Term Finance Governance Takeover: Incident Report

Less than $30 was enough to take control of a handful of Term Finance strategy vaults. The attacker leveraged a governance design flaw to update the vault strategy and drain $8.47 million.

How the Attack Unfolded

Every Term Finance Meta Vault is an ERC-4626 contract governed by its own Aragon DAO. Curators queue parameter changes into a Zodiac Delay modifier with a seven-day cooldown, and holders can veto them inside that window. However, the voting tokens are opt-in, so a liquidity provider had to wrap their shares before they could vote.

Almost nobody did. Five veto proposals between August 2025 and June 2026 received zero votes, the entire ETH Meta Vault electorate was just one account holding 0.05 wrapped shares, and the five USDC strategy vaults had no activity at all. Minimum participation was measured against wrapped supply rather than LP supply, so a single share cleared quorum.

On August 17th, two wallets were funded from Tornado Cash. The first wallet spent 0.5 ETH on tmvETH shares, wrapped them, and took 90.66% of the ETH Meta Vault's votes. The second put $5 into each of the five USDC vaults on August 21st and owned all of those electorates outright. The attacker then put up twelve proposals, all self-approved and disguised as something else: titled "Veto strategy vault parameter change," the body text urged holders to "Vote YES to VETO the curator's proposed vault parameter changes."

At 06:25:47 UTC on August 23rd, the first transaction set the Delay cooldown from 608,400 seconds to zero, recalled assets from four ETH strategies, and installed a contract whose bytecode names it "Fixed Recipient WETH Exit Strategy" with the attacker’s wallet hardcoded as the recipient. 2,841.74 WETH went in and straight back out in the same transaction.

Twenty-two minutes later a second transaction executed five proposals against the USDC strategies. It swapped the term controller and discount-rate adapter for the attacker’s malicious contract, set the required reserve ratio to zero to allow a full balance withdrawal, and forced each strategy to buy the attacker’s malicious contract repo token at prices the attacker set. The vaults reported healthy holdings while they emptied, and 1,679,639 USDC was drained and was swapped to DAI.

Term built their Meta Vaults on Yearn V3 vault infrastructure, and the failure sat in the governance wrapper Term implemented on top of their Meta Vaults. Yearn confirmed publicly that the vector doesn't apply to standard vault setups.

Depositors did fight back, but too late. The largest ETH Meta Vault depositor wrapped 2,837 tmvETH at 07:59 UTC, more than an hour after the money had gone, though counter-wrapping did push the attacker below 50% in two USDC DAOs and saved two ETH strategy vaults from being drained. The proceeds, 2,843.2 ETH and roughly 1.68 million DAI, haven't moved. 

How Term Labs Responded

Term Labs acknowledged "a governance exploit impacting Term vaults" at 10:32 UTC, and revoked DAO roles on all six vaults, writing the malicious positions off as losses, and shut the Meta Vaults down. Deposits are permanently blocked, withdrawals stay open for what's recoverable, and the ETH Meta Vault share price was marked from 1.0308 to 0.0298, a 97.1% write-down. The Term Finance lending markets weren't affected by this exploit, and the team said it will "explore paths to address" any shortfall that remains for the Meta Vaults.

Does Nexus Mutual Cover This?

Governance takeover is a covered event under Nexus Mutual Protocol Cover. Clause 2.2.4 covers “...a sudden and widespread economic event that is clearly outside the normal or intended operation” of a covered protocol, and the terms define a governance takeover as "...an event where a malicious actor forces through a malicious upgrade to a Designated Protocol smart contract."

That is exactly what happened in the Term Meta Vaults governance exploit. An attacker acquired enough voting power to push through malicious upgrades, which neutralized a timelock, installed several contracts that redirected funds to the attacker, and upgraded the pricing adapter to their malicious code. As a result, liquidity providers in the six affected Meta Vaults suffered a loss.

At the time of the Term Meta Vault governance attack, the Term Finance Multi Protocol Cover listing had no active cover. As a result, the Mutual does not expect any claims from this event.

If there were active cover for this listing, the Claims Committee would have voted in favor of paying claims, as the committee members agreed this loss event met the conditions for a Governance Takeover.

Turning $30 into $8.47 million

Autonomy is a sword that cuts both ways. Whenever code upgrades can be approved by a DAO vote, it’s critical to pay attention to what majority control costs on a given day and monitor for malicious proposals. 

This is the sort of event that traditional insurers are still reluctant to touch. Regulated carriers have not caught up with the unique risks in DeFi. A term like “governance takeover” hasn’t even been defined and could be open to wide legal interpretation. Nexus Mutual is the only underwriter with the hands-on experience to properly evaluate and price risks like these, where our cover terms clearly define what constitutes a governance takeover and outline the exposure and triggers for a valid claim.

If you are building or deploying capital into DeFi and want to be protected against governance takeovers and more, our team is ready to walk you through your cover options.

You’re Covered with Nexus Mutual

Subscribe to our newsletter

Be the first to know about our latest news, announcements and events!

Subscribe to our newsletter

Be the first to know about our latest news, announcements and events!

Subscribe to our newsletter

Be the first to know about our latest news, announcements and events!

The First Crypto Insurance Alternative: Covering Crypto since 2019

This website is operated by Collective Risk Services CIC, with its registered office at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ, on behalf of Terrapin International Foundation

© 2026 Nexus Mutual

The First Crypto Insurance Alternative: Covering Crypto since 2019

This website is operated by Collective Risk Services CIC, with its registered office at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ, on behalf of Terrapin International Foundation

© 2026 Nexus Mutual