Term Finance Loses $8.5M In Governance Exploit
Ethereum lending platform Term Finance has lost an estimated $8.5 million after an attacker seemingly acquired enough governance voting power to take control of some of its lending vaults, CoinDesk reported. How the exploit unfolded The attacker removed roughly 2,843 ether, worth about $6.9 million at the time, and 1.68 million USDC, draining around 68% of the assets held in Term‘s Meta Vaults. The vaults held about $12.45 million before the attack, according to DefiLlama data, and nearly all of the ether deposited in the product was taken. The Meta Vaults sat on top of Term’s broader lending platform, which the company said was not affected by the incident. A governance weak point The unusual element is how access was gained. Onchain monitoring service Defimon said the attacker cheaply acquired a majority of the project‘s sparsely held governance token, then allegedly used that voting power to pass proposals giving it control of the vaults. Term has not confirmed how majority control was obtained or exactly which governance functions were used. The incident sits in a grey area: while the transactions were valid under the protocol’s code, authorities could still treat the conduct as an exploit or misappropriation rather than ordinary governance. Discover more Merchant Services &