Particle.news

Term Labs Loses $8.5M After Attacker Buys Majority Governance Votes

The company shut new Meta Vault deposits, revoked the vaults’ DAO permissions, kept withdrawals available, and called in outside security teams for a forensic review.

Overview

  • Security firms PeckShield and CertiK estimate about $8.5 million was moved out of Term’s Meta/strategy vaults after on‑chain transactions routed roughly 2,843 ETH and about 1.6–1.68 million USDC to a single attacker wallet.
  • On August 23 the attacker bought a large share of a sparsely held governance token for a nominal sum and used legitimate governance votes to approve proposals that redirected vault funds into an attacker‑controlled address.
  • On‑chain tracing shows the attacker’s initial seed came from 2 ETH routed through Tornado Cash and that the USDC was later swapped to DAI, which complicates attribution and potential freezes by centralized issuers.
  • The exploited path targeted Term’s custom governance wrapper layered over Yearn V3 vaults rather than Yearn’s standard code, and Term says its core lending and borrowing markets were not affected.
  • Term Labs has permanently closed Meta Vault deposits, revoked the vaults’ DAO roles, left withdrawals open, and is coordinating external forensic work while a full postmortem, loss reconciliation, and any recovery plan remain pending.