Term Finance Loses $8.5M in Governance Exploit; Arrakis Finance Reports Uniswap V3 Attack

1 hour ago 2 sources negative

Key takeaways:

  • Governance exploit underscores that token concentration, not code bugs, is DeFi's growing vulnerability.
  • Term vault shutdown signals investors should scrutinize custom governance layers on Yearn infrastructure.
  • Rising DeFi attack complexity likely prompts tighter token distribution audits and governance safeguards.

Decentralized finance suffered a fresh security shock on August 23, 2026, as Ethereum-based fixed-rate lending platform Term Finance disclosed a governance exploit that drained roughly $8.5 million from its vault products. Security researchers at PeckShield and CertiK estimated that the attacker extracted about 2,843 ETH—worth approximately $6.9 million at the time—and around 1.68 million USDC from Term’s strategy vaults. The stablecoins were subsequently swapped for a similar amount of DAI.

According to DefiLlama data, the withdrawn funds represented nearly 68 percent of the approximately $12.45 million total value locked in the affected vaults before the incident, leaving Ethereum-side holdings almost entirely depleted. Unlike a conventional smart-contract exploit, the Term Finance breach centered on governance manipulation: the attacker acquired a controlling position in a thinly distributed governance token linked to the vaults, then used that voting power to pass proposals redirecting funds from several USDC vaults and the ETH Meta Vault.

The affected Term products were Meta Vaults and related strategy vaults built on Yearn V3 infrastructure but incorporating a custom governance layer developed by Term Labs. Yearn clarified that the issue stemmed from Term’s governance wrapper rather than standard Yearn vault designs. The attacker’s initial capital has been linked to a small amount of ETH previously mixed through Tornado Cash.

Term Labs acknowledged the incident promptly, initially stating that it was investigating a governance exploit impacting Term vaults. In a follow-up update, the team said it had irreversibly shut down all Term Meta Vaults, revoked associated DAO governance roles to block new deposits, and left withdrawals open. The underlying Term borrowing and lending markets were reportedly unaffected. The project is coordinating with external security teams on remediation and recovery options and may explore ways to address any remaining shortfall for users.

The Term Finance incident was not the only DeFi security event to surface. Arrakis Finance reported a loss of 2.94 WETH from a smart contract exploit involving Uniswap V3’s mint/burn accounting. The details were highlighted by security influencer SlowMist_Team, pointing to an atomic liquidity sandwich attack in which the attacker manipulated prices and accrued fees by minting shares against a vulnerable pool composition. The breach added to investor caution, with Arrakis Finance showing muted trading activity in the following 24-hour period.

Together, the two cases underscore the rising complexity of DeFi risk in 2026. Even protocols with protective mechanisms such as timelocks and liquidity-provider veto rights can be compromised when governance token supply is concentrated or participation is low. The events are likely to intensify scrutiny of governance design, liquidity management, and security audits across decentralized finance.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.