A DeFi lending protocol has just been drained of $8.5 million in an attack targeting its governance system directly. Despite theoretically robust safeguards, the exploit managed to bypass every protection in place.
Term Finance now joins a growing list of protocols that have fallen victim to governance vulnerabilities — an attack category that is rapidly expanding across the DeFi ecosystem. This type of exploit raises fundamental questions about the reliability of decentralized control mechanisms.
Here is everything we know about the incident, its technical mechanics, and what it reveals about the structural vulnerabilities of DeFi in 2025.
A Governance Exploit That Bypassed Every Safeguard
Term Finance is a decentralized lending protocol that allows users to deposit assets into term vaults — fixed-duration vaults that generate yield. To modify the parameters of these vaults, the protocol normally enforces a seven-day delay before any governance proposal can be executed, alongside a veto right granted to liquidity providers.
On paper, this dual mechanism — a mandatory time lock and LP veto — forms a solid barrier against opportunistic attacks. In practice, the attacker managed to exploit a flaw in this process to drain approximately $8.5 million in user-deposited funds. The precise details of the attack vector have not yet been fully disclosed by the team, which is standard practice to prevent copycat attacks during the post-mortem investigation.
This type of exploit, commonly referred to as a governance attack, typically involves manipulating the voting or proposal execution process to force the adoption of malicious parameters — such as redirecting funds to an address controlled by the attacker. The central question remains: why did the seven-day delay fail to alert the community or the protocol’s guardians in time?
DeFi Governance: An Underestimated Attack Vector
Governance exploits represent one of the most insidious threats in the decentralized ecosystem. Unlike flash loan attacks or traditional smart contract vulnerabilities, they exploit the protocol’s own rules — which makes them legally and technically difficult to classify as straightforward hacks.
Notable precedents exist: Beanstalk Farms lost $182 million in April 2022 through a governance exploit that used a flash loan to temporarily acquire a voting majority. Compound and Tornado Cash have also faced similar attempts. In each case, the speed of execution or social engineering allowed attackers to circumvent security time locks.
For Term Finance, the incident highlights an uncomfortable reality: a seven-day delay is only effective if vigilant actors are actively monitoring live proposals. Without a robust automated alert system, without a sufficiently engaged community, or if the attack exploits a stage that precedes the delay phase entirely, this safeguard becomes purely theoretical. DeFi must rethink its governance security models — not simply by adding time locks, but by integrating real-time on-chain monitoring mechanisms and emergency response systems capable of acting before it is too late.