Term Labs recovers all fixed rate loan positions affected by governance vulnerability, Meta Vaults remains closed
As of August 25, Term Labs has fully recovered all fixed rate loan positions affected in Meta Vaults and its associated strategies. Meta Vaults and related policies are currently closed.
The attacker removes the execution delay mechanism through a malicious governance proposal, which then drains liquidity ETH and USDC from the Vault policy. Attackers used fake repo tokens tied to the actual liquidity USDC balance of each strategy to successfully empty the available funds. Term Labs confirmed that its V1 and V2 contracts have not been compromised and that the direct lending market is still operating normally.
Term Labs stated in its latest incident report that the last fixed rate position was fully recovered at 14:52 Coordinated Universal Time (UTC) on August 25. The investigation results showed that the attack was limited to liquid balances held in Term Vault and did not affect underlying assets.
Loan contracts unaffected by Vault vulnerability
New technology accounts reveal more details about the August 23 attack. Previously, security companies estimated that the incident stole approximately $8.5 million from the Term Finance Vault. Term Labs initially disclosed only governance vulnerabilities that affected Vault and did not provide a complete attack sequence. Security companies CertiK and PeckShield estimated the damage at close to $8.5 million, including approximately 2,843 ETH and 1.68 million USDC. PeckShield said those USDC were subsequently exchanged for approximately 1.68 million DAIs.
The parties subsequently closed its Meta Vaults and revoked its DAO governance authority. The new deposit feature is permanently disabled, but the withdrawal feature remains open. Yearn said at the time that the affected contracts used Yearn V3 infrastructure, but the attack involved a governance wrapper developed for Term, not the standard Yearn V3 Vault.
Term Labs now says its underlying fixed-rate lending system has not been touched by attackers. In its direct lending market, supply, repayment and clearing functions continued uninterruptedly throughout the event.
Detailed explanation of the attack path: Leveraging Tornado Cash and governance proposals
The attack was mainly carried out through two operator wallets funded by Tornado Cash and a series of governance proposals that changed control of Term Vault policies.
The first operator wallet received funds through Tornado Cash on August 17. About 24 minutes later, the wallet submitted an ETH proposal titled "Vote in favor of veto the curator's proposed changes to Vault parameters." A key change included in the proposal is to reduce governance delays for affected stacks to zero. Term Labs pointed out that the change eliminated a seven-day and one-hour window during which liquidity providers could have blocked the proposal from being implemented.
The second operator wallet received Tornado Cash funds on August 18 and deployed a single contract that afternoon. According to Term Labs, the contract combines three functions in one deployment: a controller, price adapter, and fake repurchase tokens. An auxiliary contract was then initialized.
Three days later, on August 21, the ancillary contract submitted seven governance proposals and cast its only vote on them. Two of the proposals for the ETH policy DAO were never implemented, while the other five became part of the USDC attack. The five proposals also reduced governance delays to zero, removed the original three-day and one-hour window, and prevented LP from interfering before implementation.
Early incident analysis found that attackers gained governance influence at a very low cost. A review of the governance takeover process revealed that the attacker spent approximately $951 on enough governance tokens to control voting rights associated with Vault, which held millions of dollars in deposits. The deal did not require the attacker to undermine Term's core fixed-rate lending contract, but rather implemented instructions through a governance contract that went through a proposal and voting process.
StrongBlock encountered a similar attack path earlier this year, when attackers took over its governance system and stole approximately $72,000 in STRONG and STRNGR tokens. The attacker gained enough voting power to pass a proposal that would ultimately give him control over the project's Governor contract management.
ETH Flow to Fixed Receiver Policy
The first successful Term proposal was implemented at 06:25 UTC on August 23. Four active ETH policies-Shorewoods, August Digital, Parity Prime, and Parity Core-were recalled to Meta Vault via the update_debt() function and directed to a newly added policy frWETH-EXIT.
Term Labs named this policy "Fixed Recipients WETH Exit Strategy." Once WETH enters a new policy, frWETH-EXIT forwards the entire amount to the first operator in the same call. The transaction resulted in Meta Vault holding 2,841.74 shares that did not include any of the strategies that had been transferred to WETH. This number is very consistent with the approximately 2,843 ETH tracked by PeckShield during its early analysis of the incident.
A second wave of actions against five USDC strategy DAOs followed 22 minutes after the ETH transaction occurred. Parity Prime, Parity Core, Parity HY, Parity HY v2 and RockawayX Tori were targeted at 06:47 UTC.
Term Labs stated that each proposal would result in its DAO selling one unit of fake repurchase tokens to associated strategies at a value equal to the strategy's entire liquidity USDC balance. After the proposal installed a contract called fmTERT, the attacker was able to perform the sales operation. Term Labs pointed out that fmTERT posed as a controller used to determine whether a token is a legitimate Term tool, as well as a price adapter responsible for determining how much the tool is worth.
The proposal would set the reserve ratio for each strategy to zero and increase its concentration limit to the maximum allowed, preventing these controls from restricting counterfeit token trading. The dynamic redemptionValue() function is then used to price the fake token. When executed, this function returns the exact liquidity USDC amount available in the policy, allowing a single unit of fake repurchase tokens to be sold at a price that is almost equal to the entire available balance of the policy.
After the sale was completed, the proposal approved USDC revenue and swept it from each DAO into the wallet of the second operator.
Fixed rate positions were transferred before redemption
Term Labs stated that fixed rate loans held by affected Vault could not be directly reached through the attack itself. However, another problem arises when these positions expire because their earnings are planned to be redeemed into the same Vault that has been captured in a governance attack. In response, the agreement upgraded affected contracts and moved fixed-rate positions before expiration.
Since then, all affected fixed rate loan positions have been withdrawn, and the last position was transferred at 14:52 UTC on August 25.
This incident illustrates the role of execution delays in governance security. Days before the Term Finance attack, Binance said it had blocked a malicious DAO proposal that threatened approximately $1.2 million in assets of an unnamed project. With less than 48 hours left for the proposal to be implemented, the exchange contacted the project, and the project finally rejected the proposal without causing reported losses. In Term's case, the malicious proposal itself removes an additional delay period before the assets are taken. The ETH proposal eliminates the seven-day and one-hour window, while the five USDC proposals each remove three-day and one-hour cycles from their respective governance stacks.
Term Labs stated that its Meta Vaults and related policies remain closed, and the shutdown of remaining low-activity vaults is still in progress. The agreement is working with law enforcement agencies and cybersecurity companies to identify the attackers and said it has provided relevant information to assist in the investigation.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH