Ethereum-based lending protocol Term Finance suffered a governance-based attack that drained roughly $8.5 million from its vault products, according to blockchain security firms tracking the incident. In response, Term Labs moved quickly to permanently shut down all Term Meta Vaults, cutting off new deposits while still allowing existing users to withdraw their funds.PeckShield’s analysis of the attack found the hacker made off with approximately 2,843 ETH, worth about $6.87 million at the time, along with 1.68 million USDC that was subsequently converted into roughly the same amount in Dai. CertiK’s independent estimate landed at a similar figure, pegging total losses around $8.5 million. Meanwhile, DefiLlama data shows the vault product carried about $12.45 million total prior to the exploit, meaning the attacker walked away with close to 68% of everything deposited, nearly wiping out the roughly $8.8 million in Ethereum holdings almost entirely.Term’s preliminary investigation points to a narrow scope for the breach. According to the company, the exploit stayed contained to the vault governance mechanism specifically and didn’t touch the underlying Term protocol or its core lending and borrowing markets, which continued functioning normally throughout the incident. The team cautioned that its review remains ongoing.Onchain monitoring service Defimon offered insight into how the attack likely unfolded. Governance tokens tied to the vaults were held by a fairly small group of holders, making them relatively cheap to acquire in bulk, as per the analysis.Defimon’s analysis suggests the attacker exploited that concentration, buying up a majority stake in the token and then using that voting power to push through governance proposals that ultimately handed control of the vaults over to the attacker. Term Labs hasn’t yet pinned down the precise mechanics behind how voting control was obtained or which specific governance functions got exploited in the process.Technical details from Term’s own documentation shed light on how the vaults were structured. Built as ERC-4626 tokenized vaults on top of Yearn’s V3 infrastructure, the vaults were designed to split capital between Term’s fixed-rate lending markets and other variable-rate lending protocols elsewhere in DeFi. Yearn addressed the incident directly on X, clarifying that the vulnerability traced back to a custom governance wrapper Term built around the vaults rather than anything inherent to standard Yearn architecture. “Funds deposited to standard Yearn vaults are safe and those vaults are unaffected,” the company wrote.However, this isn’t Term Finance’s first security incident. In April last year, an oracle malfunction triggered a wave of unintended liquidations totaling around 918 ETH. The project managed to recover roughly 556 ETH of that amount afterward, bringing the net loss down to 362 ETH, and reimbursed the users affected by that earlier episode.Binance seeks To Connect Crypto Funds With Institutional Capital6 Best Prop Trading Firms With the Fastest WithdrawalsProcess and Benefits of Depositing in Bitcoin CasinoSmithBot Review: Earn UPTO 104% APY