On-chain fixed-rate lending protocol Term Finance has permanently discontinued its Meta Vaults product following a governance exploit that enabled unauthorized fund removal. While new deposits have been halted, withdrawals remain accessible to users.
Term Labs, the organization behind the protocol, announced that it has revoked the vaults’ decentralized autonomous organization (DAO) governance roles to prevent further unauthorized access.
Blockchain security firm PeckShield has estimated that the attacker extracted approximately 2,843 ETH, valued at roughly $6.87 million, along with 1.68 million USDC, which was subsequently swapped for approximately 1.68 million DAI.
Term Finance has not confirmed the reported $8.5 million total figure nor has it released its own comprehensive vault-by-vault accounting of the losses.
Exploit Execution Through Governance Mechanisms
According to Term’s governance documentation, the system operates on an opt-out model where vault liquidity-provider token holders can veto queued parameter changes during a mandatory seven-day delay period. Changes can become executable if no veto is submitted during this window.
A reconstruction of on-chain activity by DeFiPrime revealed that an ETH Meta Vault proposal remained open for six days without receiving a veto. Upon execution, the first actions set the delay cooldown to zero, eliminating the secondary waiting period before routing 2,841.7435 WETH through a newly added strategy to an attacker-controlled address.
The Ethereum transaction occurred at 06:25 UTC on August 23. Approximately 22 minutes later, a second transaction executed five proposals across five USDC vaults, removing 1,679,639.29 USDC, according to the same analysis.
Term Finance has not published a postmortem report confirming how the proposer obtained the authority to queue those actions or why the veto and delay controls failed to prevent the exploit.
Yearn confirmed that Term’s vault contracts utilize Yearn V3 architecture, though the exploit occurred through Term’s custom governance wrapper. The organization clarified that this attack vector does not apply to standard Yearn vault configurations and that standard Yearn vaults remained unaffected.
Term similarly stated that its underlying protocol and direct borrowing and lending markets have not been impacted based on its ongoing investigation, while acknowledging that verification efforts are still underway. This narrows the confirmed damage to the vault product specifically, rather than encompassing all Term markets.
The critical question remains what recovery options Meta Vault users can expect. Since Term has not confirmed the final accounting, maintaining withdrawal availability does not guarantee that sufficient liquidity or value exists to honor all withdrawals in full.
Term indicated it is coordinating with external security teams on remediation and recovery efforts. Should a shortfall persist, the company stated it would explore potential solutions. However, Term has not committed to reimburse depositors or provided a timeline for recovery.
Also Read
- block at absolute beginning, followed immediately by rewritten content. No intro notes, no internal thinking.
- Ledger Addresses Critical Ethereum App Vulnerability Allowing Transaction Substitution During Signing
- WTI Crude Oil Falls Below $84 as Dollar Strengthens, but Iran Tensions Cap Losses
- Euro Slides Further as Dollar Gains Momentum Ahead of PCE Data and Jackson Hole


