Term Finance, an Ethereum-based fixed-term lending protocol, lost approximately $8.5 million after an attacker acquired sufficient governance token voting power to pass a malicious proposal, redirecting protocol funds. The attack did not exploit a smart contract code vulnerability in the traditional sense but instead weaponized the governance mechanism itself — a vector that is difficult to audit and increasingly common in DeFi lending infrastructure.
For Armada's crypto repo desk, this incident is directly relevant to how on-chain collateral is assessed. If any collateral assets — particularly ETH or tokens like HYPE — are deposited in or interact with DeFi protocols susceptible to governance attacks, the no-rehypothecation policy does not fully insulate Armada from contagion risk. Fireblocks custody must be confirmed to segregate assets from protocol governance exposure, and the incident warrants adding governance attack risk as an explicit criterion in the crypto collateral due diligence framework.