-
An attacker exploited a security flaw in Term Labs’ Vault governance to steal about 2,843 ETH and 1.68 million USDC, causing millions of dollars in losses.
-
According to blockchain security firm PeckShield, the attacker swapped the stolen USDC for DAI. The attack wallet’s initial funding of 2 ETH came from the crypto mixer Tornado Cash.
-
Term Labs shut down all Term Meta Vaults and revoked their DAO governance roles while it investigates the attack.

Term Labs is investigating a governance exploit that drained an estimated $8.5 million from its Term Finance vaults. The breach happened on August 23 and hit vaults connected to the Ethereum-based lending protocol.
Both PeckShield and CertiK tracked where the stolen funds went. PeckShield found that about 2,843 ETH, worth nearly $6.87 million then was drained, along with 1.68 million USDC. The stablecoins were later swapped for roughly 1.68 million DAI. Term Labs confirmed the incident but has not yet published a full technical explanation.
Attacker Drains More than Two-Thirds of Vault Assets
The size of the attack makes it especially serious for Term vault users. DefiLlama data cited by The Block showed about $12.45 million in total value locked across Term’s vaults before the attack. About $8.8 million was held on Ethereum.
The estimated $8.5 million loss equals roughly 68% of the vault product’s total value. It also represents nearly all of the assets held in its Ethereum vaults. Term Finance’s wider platform was larger than the affected vault product. The protocol had about $25.8 million in total value locked before the attack.
That distinction matters because Term says its direct lending and borrowing markets were not affected. The company said the incident was limited to Term Vault governance. It is still checking the full scope of the attack.
The Attack Focused on Governance
The incident stands out because it appears to involve governance controls rather than a common coding flaw. Governance systems decide who has the authority to alter important aspects of operations or give permission for certain actions. Gaining control of this system means an attacker may be able to move funds without manipulating the underlying smart contract code.
Term vaults use governance roles to manage critical aspects of their operation. According to Term’s documentation, a governor can manage risk settings, protocol configuration and emergency actions. Liquidity providers also have a role in overseeing proposed governance actions.
The system includes a seven-day delay for governance proposals. Liquidity providers can vote to cancel a queued action during that period.
Term has not explained how the attacker overcame those protections. It also has not confirmed which governance role or function the attacker used. That leaves a major question for the company’s investigation: why did the existing controls allow the attacker to move millions of dollars?
The Stolen Assets Moved Quickly
PeckShield traced the stolen assets to a single wallet. The security firm said the wallet received 2 ETH from Tornado Cash before the attack. That transfer does not identify the attacker or prove who controlled the wallet. It only mentions the source from which the wallet received its initial funding.
Following the hack attack, the stolen funds were shifted on the blockchain. Afterward, the 1.68 million USDC was converted to the equivalent amount of DAI. The ETH remained in the attacker’s wallet, according to blockchain tracking cited by security researchers. They haven’t confirmed if there’s been any recovery of the stolen funds.
Term Shuts Down Its Meta Vaults
Term Labs moved quickly after confirming the attack. They advised users to temporarily revoke all approvals for their contract until they can further investigate the incident. On August 24, the company said it had revoked their DAO governance roles and shut down all Term Meta Vaults.
The shutdown is permanent. Term vaults will not accept any further deposits; however, withdrawals remain open. Term said the move prevents further deposits while its investigation continues. It is also working with outside security teams on recovery and remediation efforts.
The company said it will also explore ways to address any remaining shortfall if the stolen assets cannot be recovered. That decision gives affected users a way to withdraw remaining assets. It also prevents fresh funds from entering the affected vault system.
Standard Vaults Remain Secure
Term’s vaults use Yearn V3 infrastructure. That connection raised questions about whether the incident could affect other Yearn vaults.
Yearn’s security documentation says its V3 vaults have undergone several independent audits. It also warns that governance remains a major security assumption for the protocol.
Yearn’s own risk guidance also notes that a problem in an external protocol or strategy can create losses for users, even when the core vault code works as designed.
Current reporting indicates that the Term attack used a custom governance wrapper around its vaults. However, the incident didn’t affect standard Yearn vault setups. This distinction is important. The incident does not mean every Yearn V3 vault is vulnerable to the same attack.
Governance Security is Now Under Scrutiny
Governance attacks have become a recurring problem across decentralized finance. They can take different forms. An attacker may buy enough voting power, exploit weak voting rules, or abuse a flawed permission system. The goal is often the same: gain control over a system that can move valuable assets.
Stolen data remains valuable beyond cryptocurrency. A dark web listing claims to offer 7 TB of data from two Chinese automakers, including KYC documents and records of about 700,000 customers, along with source code, financial data, and contracts.
Term’s incident shows why protecting smart contracts alone may not be enough. A protocol can have audited code and still face major risks if its governance controls are weak. The same concern appears in Yearn’s own security documentation. Yearn states that compromised or malicious governance could cause serious damage across its vaults and strategies.
The incident is another reminder that smart contract security extends beyond the code itself. Some security experts believe governance mechanisms deserve the same scrutiny as core protocol logic. That lesson could matter well beyond Term Labs. When governance controls large pools of user funds, they become part of the security boundary too.
What Happens Next
The next step is Term Labs’ full postmortem. Users and the wider DeFi sector need clear answers about how the attacker gained control and why existing protections failed. It also needs to confirm the final loss, identify affected vaults, and report recoveries.
For now, Term has stopped new deposits and kept withdrawals open. It is also working with external security firms on recovery efforts.
The attack is a reminder that decentralization does not remove the need for strong controls. A governance system can protect user funds, but it can also become a target when its voting power is easier to capture than the assets it controls.