Term Finance, an Ethereum lending app, lost $8.5 million after an attacker bought voting power, according to CoinDesk. CoinDesk frames the incident around governance control. Its summary says the exploit shows how lightly held voting tokens can become a means of attack when control of a protocol is cheaper than the assets that control governs. That distinction matters in decentralized finance. If voting rights over a protocol can be acquired cheaply enough, an attacker may be able to use the protocol’s own control mechanisms against it. Who benefits: Security teams and protocol designers benefit from treating governance control as part of their threat model. The incident also gives auditors another concrete class of risk to examine in lending protocols. Who's exposed: Protocols with lightly held or cheaply accumulated voting tokens are exposed if their governance systems can affect valuable assets. Tokenholders and users of those protocols bear the direct risk when governance control can be bought below the value at stake.