stable coins
By Jean-Luc Maracon
1 / 15
What happened. An attacker hit Term Finance hard. About $8.5 million gone — drained through a governance exploit…
2 / 15
The historical context. Governance exploits aren't new to DeFi. Not even close.
3 / 15
Why it matters. Term Finance had already been through it once. Back in April 2025, an oracle error triggered…
4 / 15
What to watch. A few things worth tracking closely as this plays out.
5 / 15
An attacker hit Term Finance hard. About $8.5 million gone — drained through a governance exploit that gave the attacker control over the protocol's strategy vaults.
6 / 15
The breach wiped out close to 68% of the assets sitting in Term's vaults. That's not a minor ding.
7 / 15
What made this attack possible wasn't a bug in the base code. Term's vaults run on Yearn V3 infrastructure, which held up fine.
8 / 15
The attacker apparently acquired a majority of Term's governance tokens — cheaply, it seems — and used that voting power to pass proposals that funneled the funds out.
9 / 15
Back in 2022, Beanstalk Farms got hit by an attacker who used a flash loan to grab majority voting power almost instantly, then pushed through a proposal that moved $182 million…
10 / 15
Term Finance's situation fits that same ugly pattern. DeFi protocols keep innovating, keep building, keep adding complexity.
11 / 15
More context: SharpLink Stakes $91 Million in ETH, Becomes Second Largest Institutional Holder
12 / 15
What's different here is the custom wrapper angle. Most post-mortems on governance exploits focus on flash loans or token concentration.
13 / 15
No clear answer yet. Unclear whether the remediation efforts after the oracle incident touched the governance wrapper at all. Maybe they didn't.
14 / 15
The broader DeFi community takes a hit every time something like this happens. Trust in decentralized systems is fragile.
15 / 15
Related: Coldcard Users Urged to Replace Seed Phrases After $112 Million Bitcoin Loss
The Currency Analytics
Want the full story?