Withdrawals remain open, but Term’s Aug. 23 update did not quantify remaining vault assets and only said it would explore ways to address any shortfall.
Term Labs said all Term Meta Vaults have been shut down and DAO governance roles revoked after a governance exploit hit the vault product, while withdrawals remain open.
In an Aug. 23 update, Term said the shutdown is irreversible and permanently prevents further deposits. The update did not quantify assets remaining in the vaults. It said the company would “explore paths” to address any shortfall, leaving the amount depositors can recover unresolved.
Blockchain security firm PeckShield estimated that the attacker drained about 2,843 ETH, then worth $6.87 million, and 1.68 million USDC that was swapped into roughly 1.68 million DAI. PeckShield put the total at about $8.5 million; Term’s update did not give its own loss estimate.
Onchain records corroborate the transferred amounts. One successful Ethereum transaction sent 2,841.74 WETH to an address Etherscan labels “Term Finance Exploiter 1.” A second transaction sent 1.68 million USDC to an address labeled “Term Finance Exploiter 2.”
Custom Governance Wrapper
Yearn said Term’s vault contracts use its V3 architecture, but that the exploit occurred through Term’s custom governance wrapper. Yearn said the attack vector did not apply to standard Yearn vault setups.
Term’s governance documentation describes a proposal path from a Proposer Safe through a seven-day delay and Governor Safe to a vault. It says the governor role oversees governance actions, risk parameters and emergency controls.
Term said it revoked DAO governance roles following an incident involving Term Vault governance. However, the Aug. 23 update did not identify the revoked roles, affected contract addresses or revocation transactions. Without those details or a postmortem, the statement does not establish whether the precise permissions used in the exploit were removed. The separately confirmed shutdown prevents new deposits, while withdrawals remain available.
Term said its underlying protocol and direct borrowing and lending markets had not been affected based on its investigation so far, while it continued to verify the scope. Yearn separately said standard Yearn vaults were unaffected.
Term said it is coordinating with external security teams on remediation and recovery. “If a shortfall remains, we will explore paths to address it,” the company said. The update did not include a reimbursement commitment or recovery timetable.
