$8.5M Gone Overnight: Term Finance Just Shut Down Its Vaults for Good
An attacker just exploited a governance vulnerability in Term Finance and walked away with an estimated $8.5 million in Ethereum, forcing the protocol to permanently shut down its Meta Vaults.
Not paused. Not patched. Permanently closed.
That detail matters. Most protocols hit by exploits promise a fix, a relaunch, a post-mortem with a recovery plan. Term Finance drew a hard line and killed the product entirely. That tells you everything about how bad the damage actually was.
What Happened
The attacker targeted Term's Meta Vaults through a governance-level exploit, not a typical smart contract bug. Governance exploits are particularly brutal because they operate through the system's own rules, making them harder to detect in real time and almost impossible to reverse cleanly once executed. By the time the dust settled, nearly all Ethereum deposits held in the vaults had been removed.
Term Finance confirmed the attack and announced the permanent closure shortly after. No timeline for recovery. No relaunch roadmap. Just a shutdown.
Why This Hits Different
DeFi governance exploits have been climbing in frequency, and this one follows a familiar and painful pattern. A protocol builds a yield product on top of a governance structure, that structure becomes the attack surface, and users pay the price.
What makes this case particularly sharp is the scale relative to the product. Meta Vaults were positioned as a relatively straightforward yield vehicle for ETH holders. The kind of product designed to feel safe. $8.5 million drained from something marketed as low-complexity is a red flag for the entire category of governance-adjacent DeFi products.
It also raises an uncomfortable question: how many other protocols are running governance mechanisms with similar exposure and just haven't been targeted yet?
The Bigger Picture
This is not an isolated incident. Governance-layer vulnerabilities are becoming one of the most exploited surfaces in DeFi, precisely because they sit above the smart contract layer where most security audits focus. Auditors check the code. Attackers are increasingly going after the rules that govern the code.
For ETH deposited in any governance-adjacent vault right now, the risk calculus just shifted.
What to Watch
If you hold funds in any DeFi protocol with a Meta Vault structure or governance-controlled treasury, review the withdrawal conditions today, not tomorrow. Watch for Term Finance's official post-mortem, which should reveal the specific governance mechanism that was exploited. That detail will likely expose similar vulnerabilities in comparable protocols across the ecosystem.
The yield is never worth it when the vault itself becomes the weapon.