Overview
- Security firms PeckShield and CertiK estimate about $8.5 million was moved out of Term’s Meta/strategy vaults after on‑chain transactions routed roughly 2,843 ETH and about 1.6–1.68 million USDC to a single attacker wallet.
- On August 23 the attacker bought a large share of a sparsely held governance token for a nominal sum and used legitimate governance votes to approve proposals that redirected vault funds into an attacker‑controlled address.
- On‑chain tracing shows the attacker’s initial seed came from 2 ETH routed through Tornado Cash and that the USDC was later swapped to DAI, which complicates attribution and potential freezes by centralized issuers.
- The exploited path targeted Term’s custom governance wrapper layered over Yearn V3 vaults rather than Yearn’s standard code, and Term says its core lending and borrowing markets were not affected.
- Term Labs has permanently closed Meta Vault deposits, revoked the vaults’ DAO roles, left withdrawals open, and is coordinating external forensic work while a full postmortem, loss reconciliation, and any recovery plan remain pending.