Decentralized lending protocol Term Finance suffered an estimated loss of $8.5 million on August 23, 2026, following an exploit targeting the administrative governance framework of its strategy vaults.
#PeckShieldAlert @term_labs was exploited for ~$8.5M due to a governance exploit impacting Term vaults.
The exploiter has drained ~2,843 $ETH ($6.87M) & 1.68M USDC ($1.68M) – which has already been swapped for ~1.68M $DAI
The exploiter originally funded with 2 ETH from… pic.twitter.com/6ZRoDD9QK7
— PeckShieldAlert (@PeckShieldAlert) August 23, 2026
According to alerts from blockchain security firm PeckShield, the exploiter executed a drain of 2,843 ETH, valued at roughly $6.87 million, alongside extracting 1.68 million USDC from affected smart contracts.
#CertiKInsight 🚨@term_labs was targeted in a governance attack resulting in the loss of ~$8.5M.
2,843 ETH and ~$1.6M DAI are currently at address 0xD5183d8BfC65a50863C62aF2538198A8288FFc13
Stay vigilant!https://t.co/xWJl6gi9ao
— CertiK Alert (@CertiKAlert) August 23, 2026
A parallel assessment by cybersecurity firm CertiK identified a loss of 8.5 million dollars, confirming that the drained capital represented the vast majority of liquid assets committed to the specific vault pool.
Data published by DefiLlama indicated that the stolen funds accounted for approximately 68% of the $12.45 million locked across Term’s vault products, depleting almost all of the protocol’s $8.8 million in Ethereum deposits.
On-chain transaction records show the attacker promptly swapped the 1.68 million USDC for DAI stablecoins, an established tactic aimed at avoiding potential asset freezes by centralized stablecoin issuers.
The breach highlights how ongoing vulnerabilities in decentralized finance continue to challenge protocol developers, particularly when secondary smart contract wrappers introduce unforeseen administrative exposure across otherwise established infrastructure.
Governance manipulation and vault smart contracts
On-chain analytics platform Defimon reported that the attacker acquired a majority of governance tokens characterized by low liquidity, enabling them to vote through malicious proposals that yielded administrative control over the vaults.
Term Labs has not confirmed how the attacker obtained the requisite voting power or which specific administrative functions were executed to redirect capital from the strategy contracts.
Although Term’s vaults rely on Yearn V3 infrastructure, Yearn representatives stated that the breach occurred within Term’s custom governance wrapper, ensuring that standard Yearn V3 vault deployments remain unaffected.
In response to the incident, Term Labs initiated an irreversible shutdown of Meta Vaults and revoked associated DAO administrative roles, permanently blocking future deposits while keeping withdrawal mechanisms operational for users.
The development team emphasized that the underlying Term protocol and its primary fixed-rate borrowing and lending markets were not impacted by the governance exploit on the vault contracts.
Protocol security history and asset remediation
This marks the second significant operational setback for the protocol. In April 2025, a pricing oracle failure caused 918 ETH in unintended liquidations across collateralized borrower positions.
According to the technical postmortem from Term, developers recovered 556 ETH and limited the final shortfall to 362 ETH, eventually reimbursing all impacted depositors through dedicated treasury reserves and protocol revenue.
Following that 2025 incident, Term pledged to require rigorous third-party audits for critical contract upgrades and promised greater decentralization across its internal governance decision-making processes.
Following the August 23, 2026 exploit, Term Labs confirmed it is coordinating with external forensic teams to trace the movement of funds and evaluate potential remediation paths for affected depositors.
This article is for informational purposes only and does not constitute financial advice.

