Term Finance permanently shuts Meta Vaults after estimated $8.5M governance exploit Term Finance has permanently shut down its Meta Vaults and stripped their DAO governance powers after an attacker drained an estimated $8.5 million in ETH and stablecoins, the team said in an Aug. 23 update. What happened - Term Labs announced it had irreversibly closed every Term Meta Vault and revoked the DAO governance roles tied to those products. The move blocks any new deposits forever, but users can still submit withdrawals. - The team has not published a vault-by-vault accounting, a full technical postmortem, or a compensation plan. Term Labs said it would “explore pathways” to cover any shortfalls but gave no figures, timelines or guarantees for reimbursement. Scope and estimated losses - Blockchain security firm PeckShield traced roughly 2,843 ETH (about $6.87M at the time) and 1.68 million USDC (~$1.68M) out of the affected vaults, estimating the total theft at roughly $8.5M. PeckShield reported the USDC was swapped for ~1.68M DAI after withdrawal. - Etherscan-labelled addresses show transfers of 2,841.74 wrapped ETH to an address tagged “Term Finance Exploiter 1” and 1.68M USDC to “Term Finance Exploiter 2.” Those labels help track flows but do not identify the person or group behind them. - PeckShield also traced the attacker’s initial wallet funding to 2 ETH sent through Tornado Cash; that on-chain link does not reveal the wallet controller. How the attacker acted - Initial analyses suggest this was not a classic smart-contract bug. Instead, the attacker gained governance control by acquiring voting power, then used the protocol’s authorized governance processes to move funds out of the vaults. - One report found the exploiter spent roughly $951 to obtain enough voting tokens to control four USDC strategy vaults and about 91% of the Ethereum Meta Vault. Prior to the incident, Term’s vault product reportedly held around $12.45M in depositor funds, making the estimated loss nearly 68% of those deposits. Term Labs has not confirmed the $951 figure, the voting percentages, or the precise share of assets lost. Relationship to Yearn and protocol impact - Yearn said Term’s contracts were built on Yearn V3 architecture but that the exploit occurred via a custom governance wrapper developed by Term for its vault products. Yearn emphasizes that standard Yearn vaults were not affected. - Term Labs said its core protocol and lending markets show no impact; the Meta Vaults were a separate product layer allocating assets through managed strategies. Response and what’s next - Term Labs has not announced whether it has contacted the attacker, law enforcement, centralized exchanges, or stablecoin issuers to seek asset freezes or recovery. - External security firms have been engaged to assist with remediation and recovery, but Term did not name the firms, detail remediation steps, or provide a timetable for a post-incident report. Broader context - Governance-token attacks are an emerging risk in 2026. In July, an attacker used purchased voting power to transfer roughly $20M in BONK from BonkDAO’s treasury. Other incidents — including a stopped proposal threatening $1.2M identified by Binance — illustrate how voting-power acquisition can be weaponized. - Regulators remain alert: in its 2017 DAO report the SEC said some DAO tokens can meet the definition of securities depending on structure and facts. Separately, Tornado Cash’s co-founder was convicted in Aug. 2025 in a high-profile U.S. case, a reminder of regulatory scrutiny around mixing services. Bottom line Term Finance has cut off its Meta Vault product after a governance takeover that drained millions. Key questions remain unanswered: a full asset reconciliation, a technical postmortem, whether any funds can be recovered, and whether affected users will be compensated. External investigators are involved, but the roadmap to recovery is still unclear. Read more AI-generated news on: undefined/news
