Term Labs, a fixed-rate lending protocol, announced that all fixed-rate loan positions in the affected vaults have been fully recovered as of August 25. The incident was confined to the floating balance within Term vaults, while meta-vaults and related strategies remain closed.
Term V1 and V2 contracts were not breached, and the direct lending market – including supply, repayments, and liquidations – continues to operate normally. The official statement detailed the attack: the attacker's address was first funded through Tornado Cash, then submitted a governance proposal that reduced the governance delay of the relevant stack to zero. Subsequently, the attacker deployed a fake repurchase token and installed a contract disguised as both a controller and a price adapter, which drove the strategy's reserve ratio to zero and maximized the concentration limit. The attacker then swapped a single unit of the fake token for all of the strategy's floating USDC and transferred the funds out. On the ETH side, the attacker recalled multiple strategies to the meta-vault and then transferred WETH via a newly created "exit strategy."

