Term Labs, the developer behind fixed-rate lending protocol Term Finance, said all Term Meta Vaults have been permanently closed after a governance attack. DAO governance powers have also been revoked, though withdrawals remain open.
In an Aug. 23 update, Term said the shutdown cannot be reversed and that any future deposits have been permanently blocked. The team did not disclose the amount of assets left in the vaults. It said only that it would "explore paths" to address any shortfall, while the amount depositors may be able to recover is still unclear.
PeckShield put estimated losses at about $8.5 million
Blockchain security firm PeckShield estimated that the attacker stole about 2,843 ETH, worth roughly $6.87 million at the time, along with 1.68 million USDC. The USDC was later exchanged for about 1.68 million DAI. Based on that estimate, total losses came to about $8.5 million.
On-chain records show two related transfers
On-chain records appear to confirm the movements. One transaction sent 2,841.74 WETH to an address labeled by Etherscan as "Term Finance Exploiter 1." Another transferred 1.68 million USDC to an address marked "Term Finance Exploiter 2."
Yearn said the issue did not affect standard V3 vaults
Yearn said Term's vault contract used its V3 architecture, but the attack hit Term's custom governance wrapper. According to Yearn, that attack vector does not apply to standard Yearn vaults.
Term said the core protocol was not affected
Term said that, based on the current investigation, its underlying protocol and direct lending markets were not affected. The team added that it is working with external security teams on remediation and recovery efforts, but it did not provide any compensation commitment or timeline.

