Term Labs recovers fixed-rate positions after $8.5M governance attack

Term Labs has recovered all fixed-rate loan positions held in vaults affected by its August governance exploit, with the final position moved on Aug. 25 as Meta Vaults and affected strategies remain shut down. Summary Term Labs recovered all affected fixed-rate loan positions by Aug. 25, while its Meta Vaults and affected strategies remain shut down. Attackers used malicious governance proposals to remove execution delays before draining liquid ETH and USDC from vault strategies. A counterfeit repo token was priced against each strategy’s exact liquid USDC balance, allowing the attacker to sweep the available funds. Term Labs said its V1 and V2 contracts were not compromised, and its direct borrowing and lending markets remained operational. Term Labs said in its latest incident report that the last fixed-rate position was recovered at 14:52 UTC on Aug. 25, while its investigation found that the attack was confined to liquid balances held inside Term vaults. https://t.co/3OPJt8uIya — Term Labs (@term_labs) September 2, 2026 The protocol said its V1 and V2 contracts were not compromised and its direct borrowing and lending markets continued operating throughout the incident. Term Labs says lending contracts escaped the vault exploit The new technical account gives a more detailed picture of the Aug. 23 attack, which security firms previously estimated had drained roughly $8.5 million from Term Finance vaults. Term Labs had initially disclosed a governance exploit affecting vaults without providing the full attack sequence. Security firms CertiK and PeckShield estimated losses near $8.5 million, including roughly 2,843 ETH and 1.68 million USDC. PeckShield said the USDC was subsequently exchanged for approximately 1.68 million DAI. The protocol later shut down its Meta Vaults and revoked their DAO governance roles. New deposits were permanently disabled while withdrawals remained available. Yearn said at the time that the affected contracts used Yearn V3 infrastructure but that the attack involved a governance wrapper developed for Term rather than standard Yearn V3 vaults. Term Labs now says its underlying fixed-rate lending system remained outside the attacker’s reach. Supply, repayment and liquidation functions continued operating without interruption in its direct lending markets. You might also like: YAM Finance governance attack puts $337K in assets at risk The attack instead developed through two operator wallets funded through Tornado Cash and a series of governance proposals that altered controls around Term’s vault strategies. The first operator received funds through Tornado Cash on Aug. 17. Around 24 minutes later, the wallet submitted an ETH proposal titled “Vote YES to VETO the curator’s proposed vault parameter changes.” Among the changes included in the proposal was a reduction of the affected stack’s governance Delay to zero. Term Labs said the change removed an additional seven-day and one-hour period during which liquidity providers could have stopped the proposal before execution.
عنوان اصلی (انگلیسی): Term Labs recovers fixed-rate positions after $8.5M governance attack
مشاهدهی خبر کامل در منبع ↗ بازگشت به یرن فایننساین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.