Decentralized lending protocol Term Finance lost an estimated $8.5 million after an attacker exploited governance control of its strategy vaults. PeckShield said about 2,843 Ether, valued at $6.87 million at the time, and 1.68 million USDC were drained. The USDC was exchanged for roughly the same amount of Dai. CertiK similarly estimated the total loss at about $8.5 million. Term Labs permanently closed all Meta Vaults and revoked their DAO governance roles. New deposits are no longer possible, while withdrawals remain open. The company said its initial investigation indicated that the underlying protocol and direct borrowing and lending markets were unaffected, although it was still checking the scope. Defimon reported that the attacker cheaply acquired a majority of a thinly held governance token and passed proposals that gave it control of the vaults. Term has not confirmed how voting control was obtained or which governance functions were used. The vaults use Yearn V3 infrastructure, but Yearn said the attack involved a custom governance wrapper and does not affect standard Yearn vault configurations. Term said it was working with outside security teams on recovery and ways to address any remaining shortfall. The incident follows an April 2025 oracle error that caused about 918 ETH in unintended liquidations. Term recovered about 556 ETH, recorded a final loss of 362 ETH, and reimbursed affected users. For the Somali diaspora and users in Soomaaliya who hold stablecoins or use DeFi services, the case is a practical reminder to examine who controls a platform’s governance before placing funds in automated vaults.