Ethereum Lending Platform Term Finance Suffers Governance Exploit Resulting in $8.5 Million Loss

Deep News
5小时前

Term Finance, an Ethereum-based lending protocol, has fallen victim to a governance attack that drained approximately 2,843 ETH (worth around $6.9 million) and 1.68 million USDC stablecoins from its treasury. The combined value of the stolen assets is estimated at $8.5 million, representing roughly 68% of the platform's total treasury holdings. The attacker reportedly acquired majority voting power over the protocol's governance token at a low cost, subsequently submitting and passing a malicious governance proposal to seize control of the lending vaults.

On-chain monitoring service Defimon noted that the attacker purchased the platform's thinly-circulated governance tokens at a minimal price to gain operational decision-making authority. They then leveraged this voting power to approve the harmful proposal and assume control of the lending treasury. As of now, Term Finance has not confirmed the specific method by which the attacker obtained majority control, nor the exact governance functions exploited in the process.

On-chain data reveals that Term Finance's Meta Vaults product held roughly $12.45 million in assets prior to the attack, with nearly $8.8 million in Ethereum deposits almost entirely drained. According to a statement released by the Term Finance team on Monday, the protocol's other direct lending and borrowing markets remain unaffected by the incident.

In response to the breach, Term Finance has permanently shut down the affected vault product, halted new deposits, and revoked the governance permissions that allowed modifications to vault settings. The team stated that they are collaborating with external security firms to recover the stolen assets and will explore options to cover the remaining losses for affected users.

The compromised vault was built on Yearn V3 infrastructure, a technology widely used to automatically allocate deposits across various lending markets to maximize yields. Yearn responded to the incident by clarifying that the vulnerability stemmed from the custom governance layer added by Term Finance on top of their technology, and that standard Yearn vault products remain unaffected.

It is worth noting that this is not the first security incident for Term Finance. In April 2025, an oracle error triggered the unexpected liquidation of approximately 918 ETH. The protocol subsequently recovered most of the funds and compensated affected users, while pledging to enhance governance transparency and external verification for critical changes. Now, over a year later, the governance mechanism itself has once again proven to be the weak link—where the value of assets controlled through voting rights far exceeds the cost of acquiring those voting rights in the first place.

免责声明:投资有风险,本文并非投资建议,以上内容不应被视为任何金融产品的购买或出售要约、建议或邀请,作者或其他用户的任何相关讨论、评论或帖子也不应被视为此类内容。本文仅供一般参考,不考虑您的个人投资目标、财务状况或需求。TTM对信息的准确性和完整性不承担任何责任或保证,投资者应自行研究并在投资前寻求专业建议。

热议股票

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10