Term Finance lending protocol loses $8.5M to a governance exploit that bypassed vault proposal safeguards.
Security & Exploits ·
Term Finance, a DeFi lending protocol, suffered an estimated $8.5 million loss through a governance exploit that circumvented the protocol's vault proposal safeguards. The exploit bypassed security mechanisms designed to protect the platform, raising questions about the adequacy of existing governance controls.
Term's vault proposal system includes a seven-day delay and veto rights held by liquidity providers, intended to prevent unauthorized changes. Despite these protections in place, the attack succeeded in draining funds, indicating the exploit found a pathway around or through these defenses rather than directly circumventing them through brute force.
The precise mechanics of how the attacker bypassed the seven-day delay and liquidity provider veto authority remain unclear, as does whether the protocol has identified and patched the vulnerability or recovered any portion of the lost funds.