Term Finance Loses $8.5M in Vault Exploit Amid Rising DeFi Security Risks

An attacker cheaply acquired majority governance voting power and drained roughly $8.5 million from Term Finance vaults on August 23, 2026. The stolen

Share
Term Finance Loses $8.5M in Vault Exploit Amid Rising DeFi Security Risks

Editorial illustration for Term Finance Loses $8.5M in Vault Exploit Amid Rising DeFi Security Risks

Summary

  • An attacker cheaply acquired majority governance voting power and drained roughly $8.5 million from Term Finance vaults on August 23, 2026.
  • The stolen assets included 2,843 ETH valued at about $6.9 million plus 1.68 million USDC.
  • The incident exposed governance control risks in DeFi rather than a code vulnerability.

An attacker bought enough governance tokens on August 23, 2026. They seized control of Term Finance and drained the vaults. The move pulled out 2,843 ETH plus 1.68 million USDC in one swift action.

The attacker struck fast once voting power flipped. No code broke.

Context

DeFi protocols lean on token votes for treasury moves. Cheap tokens let one buyer grab the reins.

Term Finance tied vault access to those votes. This left the system wide open. Similar attacks hit others before, yet teams still chase liquidity first.

Details

The attacker scooped up votes at low cost. They then drained the funds. Losses hit roughly 8.5 million dollars total. ETH alone made up about 6.9 million at the time.

No contract flaw showed up. Governance alone opened the door.

"This governance attack reignited concerns over control risk in DeFi."

, OneKey (https://onekey.so/blog/ecosystem/term-finance-suffers-governance-attack-roughly-85-million-lost-20260824112645/)

Outlets tracked the same steps. The buyer grabbed power. A proposal released the assets. Money flowed out fast. The event stayed limited to Term Finance.

Outlook

Teams now push to fix vote thresholds. They also eye token spreads. Other protocols may copy the fixes ahead of their next votes.