Term Finance has suffered an estimated $8.5 million loss after an attacker exploited the governance system controlling its Meta Vaults. The attacker gained sufficient governance control to authorize the withdrawal of approximately 2,843 ETH, worth around $6.9 million, along with roughly 1.68 million USDC, which was subsequently converted into DAI.
The incident was not caused by a conventional smart contract vulnerability. Instead, the attacker exploited weaknesses in the protocol’s governance mechanism to obtain control over vault assets. Following the attack, Term Finance permanently shut down its Meta Vaults and revoked their DAO governance permissions.
Term Finance has disabled new deposits while keeping withdrawals available for affected users. The team is continuing to investigate the incident and assess potential recovery options.
The incident highlights the risks associated with governance systems that can provide control over large pools of user funds.
❄️ @Release 💬 @Conversate
🦎 LizardSwap.com — Your #1 Crypto Exchange for NO KYC & No Frozen Funds
