EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Term Labs resumes fixed-rate positions after $8.5 million governance attack

2026-09-04 00:30:48
Bookmark

Term Labs recovers all fixed rate loan positions affected by governance vulnerability, Meta Vaults remains closed

As of August 25, Term Labs has fully recovered all fixed rate loan positions affected in Meta Vaults and its associated strategies. Meta Vaults and related policies are currently closed.

The attacker removes the execution delay mechanism through a malicious governance proposal, which then drains liquidity ETH and USDC from the Vault policy. Attackers used fake repo tokens tied to the actual liquidity USDC balance of each strategy to successfully empty the available funds. Term Labs confirmed that its V1 and V2 contracts have not been compromised and that the direct lending market is still operating normally.

Term Labs stated in its latest incident report that the last fixed rate position was fully recovered at 14:52 Coordinated Universal Time (UTC) on August 25. The investigation results showed that the attack was limited to liquid balances held in Term Vault and did not affect underlying assets.

Loan contracts unaffected by Vault vulnerability

New technology accounts reveal more details about the August 23 attack. Previously, security companies estimated that the incident stole approximately $8.5 million from the Term Finance Vault. Term Labs initially disclosed only governance vulnerabilities that affected Vault and did not provide a complete attack sequence. Security companies CertiK and PeckShield estimated the damage at close to $8.5 million, including approximately 2,843 ETH and 1.68 million USDC. PeckShield said those USDC were subsequently exchanged for approximately 1.68 million DAIs.

The parties subsequently closed its Meta Vaults and revoked its DAO governance authority. The new deposit feature is permanently disabled, but the withdrawal feature remains open. Yearn said at the time that the affected contracts used Yearn V3 infrastructure, but the attack involved a governance wrapper developed for Term, not the standard Yearn V3 Vault.

Term Labs now says its underlying fixed-rate lending system has not been touched by attackers. In its direct lending market, supply, repayment and clearing functions continued uninterruptedly throughout the event.

Detailed explanation of the attack path: Leveraging Tornado Cash and governance proposals

The attack was mainly carried out through two operator wallets funded by Tornado Cash and a series of governance proposals that changed control of Term Vault policies.

The first operator wallet received funds through Tornado Cash on August 17. About 24 minutes later, the wallet submitted an ETH proposal titled "Vote in favor of veto the curator's proposed changes to Vault parameters." A key change included in the proposal is to reduce governance delays for affected stacks to zero. Term Labs pointed out that the change eliminated a seven-day and one-hour window during which liquidity providers could have blocked the proposal from being implemented.

The second operator wallet received Tornado Cash funds on August 18 and deployed a single contract that afternoon. According to Term Labs, the contract combines three functions in one deployment: a controller, price adapter, and fake repurchase tokens. An auxiliary contract was then initialized.

Three days later, on August 21, the ancillary contract submitted seven governance proposals and cast its only vote on them. Two of the proposals for the ETH policy DAO were never implemented, while the other five became part of the USDC attack. The five proposals also reduced governance delays to zero, removed the original three-day and one-hour window, and prevented LP from interfering before implementation.

Early incident analysis found that attackers gained governance influence at a very low cost. A review of the governance takeover process revealed that the attacker spent approximately $951 on enough governance tokens to control voting rights associated with Vault, which held millions of dollars in deposits. The deal did not require the attacker to undermine Term's core fixed-rate lending contract, but rather implemented instructions through a governance contract that went through a proposal and voting process.

StrongBlock encountered a similar attack path earlier this year, when attackers took over its governance system and stole approximately $72,000 in STRONG and STRNGR tokens. The attacker gained enough voting power to pass a proposal that would ultimately give him control over the project's Governor contract management.

ETH Flow to Fixed Receiver Policy

The first successful Term proposal was implemented at 06:25 UTC on August 23. Four active ETH policies-Shorewoods, August Digital, Parity Prime, and Parity Core-were recalled to Meta Vault via the update_debt() function and directed to a newly added policy frWETH-EXIT.

Term Labs named this policy "Fixed Recipients WETH Exit Strategy." Once WETH enters a new policy, frWETH-EXIT forwards the entire amount to the first operator in the same call. The transaction resulted in Meta Vault holding 2,841.74 shares that did not include any of the strategies that had been transferred to WETH. This number is very consistent with the approximately 2,843 ETH tracked by PeckShield during its early analysis of the incident.

A second wave of actions against five USDC strategy DAOs followed 22 minutes after the ETH transaction occurred. Parity Prime, Parity Core, Parity HY, Parity HY v2 and RockawayX Tori were targeted at 06:47 UTC.

Term Labs stated that each proposal would result in its DAO selling one unit of fake repurchase tokens to associated strategies at a value equal to the strategy's entire liquidity USDC balance. After the proposal installed a contract called fmTERT, the attacker was able to perform the sales operation. Term Labs pointed out that fmTERT posed as a controller used to determine whether a token is a legitimate Term tool, as well as a price adapter responsible for determining how much the tool is worth.

The proposal would set the reserve ratio for each strategy to zero and increase its concentration limit to the maximum allowed, preventing these controls from restricting counterfeit token trading. The dynamic redemptionValue() function is then used to price the fake token. When executed, this function returns the exact liquidity USDC amount available in the policy, allowing a single unit of fake repurchase tokens to be sold at a price that is almost equal to the entire available balance of the policy.

After the sale was completed, the proposal approved USDC revenue and swept it from each DAO into the wallet of the second operator.

Fixed rate positions were transferred before redemption

Term Labs stated that fixed rate loans held by affected Vault could not be directly reached through the attack itself. However, another problem arises when these positions expire because their earnings are planned to be redeemed into the same Vault that has been captured in a governance attack. In response, the agreement upgraded affected contracts and moved fixed-rate positions before expiration.

Since then, all affected fixed rate loan positions have been withdrawn, and the last position was transferred at 14:52 UTC on August 25.

This incident illustrates the role of execution delays in governance security. Days before the Term Finance attack, Binance said it had blocked a malicious DAO proposal that threatened approximately $1.2 million in assets of an unnamed project. With less than 48 hours left for the proposal to be implemented, the exchange contacted the project, and the project finally rejected the proposal without causing reported losses. In Term's case, the malicious proposal itself removes an additional delay period before the assets are taken. The ETH proposal eliminates the seven-day and one-hour window, while the five USDC proposals each remove three-day and one-hour cycles from their respective governance stacks.

Term Labs stated that its Meta Vaults and related policies remain closed, and the shutdown of remaining low-activity vaults is still in progress. The agreement is working with law enforcement agencies and cybersecurity companies to identify the attackers and said it has provided relevant information to assist in the investigation.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP