Decentralized lending protocol Term Finance has permanently shut down its Meta Vaults after an
attacker used the project’s own governance system to seize control and make off with an estimated
$8.5 million.
According to Cointelegraph, the exploit hinged on a governance control breach rather than a
conventional code bug. Blockchain analytics account Defimon described the mechanics bluntly: “the
attacker cheaply acquired a majority of a sparsely held governance token and passed proposals that
allowed it to seize control of Term’s vaults.” Term Labs has not confirmed the specific details of how
that voting control was obtained.
Counting the damage
The losses were concentrated in the Meta Vaults. Cointelegraph reports that roughly 2,843 ETH, worth
about $6.87 million, and 1.68 million USDC, which was exchanged for around 1.68 million DAI, were
drained. That amounts to roughly 68% of the $12.45 million held in the vaults before the attack, with
nearly all of the approximately $8.8 million in Ethereum deposits affected.
Security firms moved quickly to document the incident. PeckShield flagged and detailed the breach,
while CertiK arrived at similar loss estimates. In response, Term Labs permanently closed all Meta
Vaults and revoked their DAO governance roles to prevent any repeat.
Containment and recovery
Term Labs sought to reassure users that the blast radius was limited. The team said its underlying
protocol and direct lending markets remained unaffected by the attack. It added that it was
coordinating with external security teams on asset recovery and would “explore paths to address” any
shortfall left behind.
The episode also drew a clarification from Yearn Finance, whose infrastructure is widely used across
DeFi. Yearn noted that the attack involved a custom governance wrapper and did not affect standard
Yearn V3 vaults, drawing a line between the compromised bespoke component and the more widely deployed
standard contracts.
Governance-based attacks like this one are a recurring hazard in decentralized finance, where the
same token-voting mechanisms meant to distribute power can become an attack surface when tokens are
thinly held and cheap to accumulate. Term Finance’s decision to retire the affected product outright,
rather than patch and relaunch it, underscores how difficult it is to rebuild trust once an
attacker has demonstrated they can vote themselves the keys.
Written for Red Robot with AI assistance and human editing. Based on reporting by Cointelegraph.