Term Finance, an Ethereum lending protocol, lost $8.5 million this week after an attacker bought voting power and used it to take control of the app. The exploit shows that when governance is cheap enough, it becomes the attack surface. The attacker spent less to buy votes than the protocol held in assets.
How the attack worked
The attacker didn't break a smart contract or crack a private key. Instead, they accumulated voting power in the protocol's governance system. With that control, they moved $8.5 million out of the lending app. It's a clean, clinical takeover — no code exploit, just a purchase.
Term Finance's governance tokens were lightly held. That's not unusual in DeFi. Many protocols hand out tokens to users and partners, and a lot of those tokens sit unused. When a single buyer can sweep up enough of them, they get the keys to the house.
Why cheap voting power is dangerous
The math is brutal. If a protocol holds $50 million in assets, but its governance tokens cost $2 million to amass, an attacker can spend $2 million to steal $50 million. That's the logic at play here. The cost of control was lower than the cost of the assets.
This isn't a glitch in Term Finance's code. It's a structural risk that exists whenever governance tokens are lightly held and lightly valued. A lot of projects, not just Term Finance, face the same exposure. The voting power doesn't need to be a majority of all tokens — just a majority of the tokens that actually get used.
What happens to the $8.5 million
The money is gone from Term Finance's lending pool. There's no word yet on whether the attacker will return it — that's usually a coin flip in these cases. The protocol itself is still running, but the funds aren't there. For users with money still locked in, the immediate question is whether the remaining pool covers the loss.
Term Finance hasn't said how it plans to respond. Whether the team can recover the funds, or whether the attacker will just sit on them, is the open question. What's clear is that the vulnerability isn't a bug you can patch — it's a governance design that let one person buy enough weight to make a decision.
The attack is a reminder that in DeFi, governance is power. And if that power is priced at a discount, someone will buy it.




