Ethereum lending protocol Term Finance loses $8.5M in governance attack
Attacker bought voting power to drain $8.5 million from Term Finance, highlighting governance risks.

Term Finance, an Ethereum-based lending protocol, has lost $8.5 million after an attacker acquired sufficient voting power to manipulate the platform's governance, according to a report from CoinDesk.
The exploit illustrates how lightly held voting tokens can become a vector for attack when the cost of gaining control of a protocol is lower than the value of the assets it manages. In this case, the attacker used voting power to push through a malicious action that drained funds.
Governance as an attack surface
Security experts have long warned that decentralized governance systems can be vulnerable when token distribution is concentrated or when voting participation is low. This incident adds to a growing list of attacks targeting protocol governance rather than code bugs.
No further details about the specific governance proposal exploited were immediately available. The incident underscores the need for robust safeguard mechanisms in DeFi governance design.