Term Labs suffered a governance attack that drained approximately $8.5 million from its vault infrastructure. The attacker acquired 0.4852 tmvETH for about 0.5 ETH, roughly $951, which represented 90.66 percent of the active governance supply because only 0.5352 gtmvETH had been staked before the attack.
The attack that cost $951
Blockchain security firm PeckShield estimated the attacker withdrew 2,843 ETH, equivalent to $6.87 million, and 1.68 million USDC, later swapped to DAI. CertiK separately confirmed the about $8.5 million loss figure.
The attacker’s initial funds came from 2 ETH routed through Tornado Cash, a privacy protocol that obscures transaction origins.
How governance became the attack vector
In this context, Term Labs’ vaults are ERC-4626-tokenized vaults built on the Yearn V3 infrastructure. The governance system was designed to give community control over strategy allocation, a feature many decentralized finance protocols include as a decentralization measure.
However, low user participation created an opportunity: vault liquidity providers received share tokens but needed an extra step to convert those positions into voting power. The attacker exploited this thin participation to dominate active governance supply without controlling equivalent economic assets.
After all of that, the attacker submitted proposals to four USDC strategy vaults and the Ethereum Meta Vault, directing them to transfer holdings to the attacker’s wallet.
Because the attacker held most of the active voting tokens, their proposals sailed right through. The vault contracts did exactly what they were programmed to do and sent the funds over.
Response and broader context
Term Labs permanently shut down all Meta Vault deposits and revoked DAO governance roles, though withdrawals remain open. The core Term protocol and direct lending markets were not affected.
Yearn Finance clarified the exploit occurred through Term’s custom governance wrapper, not standard Yearn vault setups. This whole situation feels a lot like what happened with BonkDAO back in July 2026, where someone turned a $4 million investment into a $20 million payday by taking over their governance.
The governance dilemma: A feature, not a bug
The crazy thing is that this wasn’t even a technical “hack” in the traditional sense; the code actually did exactly what it was supposed to do. As a result, the attacker held most of the votes; thus, the vault contracts just followed orders and handed over the cash.
This puts the spotlight on a deeper challenge in DeFi: the tension between decentralization and security. When only a handful of people bother to vote, it’s cheap and easy for an attacker to swoop in and hijack the whole system. Basically, the very thing meant to protect the protocol becomes its weakest link.
Going forward, protocols have to find a better middle ground. They need to keep their community in charge, but also add some basic safety rails, like requiring more votes, using timelocks, or making people stake more capital, to keep bad actors from pulling this off again.




