Term Labs has recovered every fixed-rate loan position held in vaults affected by the governance exploit on 23 August, completing the process on 25 August while its Meta Vaults and the compromised strategies remain shut down.
The final position was moved at 14:52 UTC on 25 August, according to the protocol’s latest incident report. Term Labs said its investigation found that the attack was limited to liquid balances held within Term vaults.
Its V1 and V2 contracts were not compromised, while its direct borrowing and lending markets continued to operate throughout the incident. The underlying fixed-rate lending system also remained beyond the attacker’s reach, with supply, repayment and liquidation functions continuing without interruption.
Security firms CertiK and PeckShield had estimated that about $8.5m was taken from Term Finance vaults. Their initial assessments included approximately 2,843 ETH and 1.68 million USDC. PeckShield later said the USDC had been exchanged for about 1.68 million DAI.
Term Labs first disclosed that its vaults had been affected by a governance exploit but did not initially publish the full sequence of events. It subsequently shut down its Meta Vaults and removed their DAO governance roles. New deposits were permanently disabled, although withdrawals remained available.
Yearn said at the time that the affected contracts used Yearn V3 infrastructure, but stressed that the attack involved a governance wrapper developed for Term rather than standard Yearn V3 vaults.
How the attack unfolded
Term Labs said the attack involved two operator wallets funded through Tornado Cash, followed by a series of governance proposals that changed controls around Term’s vault strategies.
The first operator received funds through Tornado Cash on 17 August. About 24 minutes later, the wallet submitted an ETH proposal titled “Vote YES to VETO the curator’s proposed vault parameter changes.”
The proposal reduced the governance Delay for the affected stack to zero. That removed a further seven-day and one-hour period in which liquidity providers could have intervened and stopped the proposal before it was executed.
A second operator wallet received Tornado Cash funding on 18 August and deployed a singleton contract later that day. Term Labs said the contract combined a controller, a price adapter and a counterfeit repo token. A helper contract was then initialised using the singleton.
On 21 August, the helper submitted seven governance proposals and cast the only votes on them. Two proposals concerned ETH strategy DAOs but were never executed. The remaining five were used in the USDC attack.
Those five proposals also reduced the relevant governance Delay to zero, removing an additional three-day and one-hour period during which liquidity providers could otherwise have intervened.
An earlier review found that the attacker acquired enough governance tokens to control votes linked to vaults holding millions of dollars in deposits for about $951. The attack did not require access to Term’s core fixed-rate lending contracts; instead, governance contracts carried out instructions that had passed through the proposal and voting process.
A similar method was used against StrongBlock earlier in August. In that case, an attacker took control of its governance system and drained about $72,000 in STRONG and STRNGR tokens after gaining enough voting power to pass a proposal that provided administrative control over the project’s Governor contract.
ETH and USDC strategies targeted
The first successful Term proposal was executed at 06:25 UTC on 23 August.
Four active ETH strategies Shorewoods, August Digital, Parity Prime and Parity Core were recalled into the Meta Vault using `update_debt()` and redirected to a newly added strategy called frWETH-EXIT.
Term Labs said the name referred to “Fixed Recipient WETH Exit Strategy”. Once the WETH entered the new strategy, frWETH-EXIT transferred the entire amount to the first operator during the same call.
The transaction left the Meta Vault holding 2,841.74 shares in a strategy containing none of the WETH transferred into it. The figure closely matched the approximately 2,843 ETH identified by PeckShield in its initial analysis.
Twenty-two minutes later, at 06:47 UTC, the second campaign targeted five USDC strategy DAOs: Parity Prime, Parity Core, Parity HY, Parity HY v2 and RockawayX Tori.
According to Term Labs, each proposal instructed its DAO to sell one unit of a counterfeit repo token into the relevant strategy at a value equal to the strategy’s entire liquid USDC balance.
The sale was enabled after the proposals installed a contract called fmTERT. The protocol said fmTERT impersonated both the controller used to establish whether a token was a legitimate Term instrument and the price adapter used to determine its value.
The proposals also set each strategy’s reserve ratio to zero and raised its concentration limit to the maximum permitted level. Those changes prevented the normal controls from restricting the fake-token transaction.
The counterfeit token was valued through a dynamic `redemptionValue()` function. At the time of execution, the function returned the exact amount of liquid USDC held by the strategy, allowing one unit of the fake repo token to be sold for virtually the entire available balance.
The proposals then approved the USDC proceeds and swept them from each DAO to the second operator’s wallet.
Fixed-rate loans recovered
Although the fixed-rate loans held by the affected vaults could not be accessed directly through the attack, Term Labs said a separate risk would have arisen when the positions matured. Their proceeds were due to be redeemed into the same vaults that had been captured.
The protocol upgraded the affected contracts and moved the fixed-rate positions before they matured. It said all affected positions have now been recovered, with the last transferred at 14:52 UTC on 25 August.
The incident has highlighted the importance of execution delays in governance security. Days before the Term Finance attack, Binance said it had prevented a malicious DAO proposal that threatened about $1.2m belonging to an unnamed project. Fewer than 48 hours remained before the proposal could be executed when Binance contacted the project, which rejected it without reporting a loss.
In the Term attack, the malicious proposals themselves removed further delay periods before the assets were taken. The ETH proposal eliminated a seven-day and one-hour window, while the five USDC proposals removed three-day and one-hour periods from their respective governance systems.
Term Labs said its Meta Vaults and affected strategies remain shut down. Work to shut down the remaining low-activity vaults is continuing.
The protocol is also working with law enforcement agencies and cybersecurity firms to identify those responsible. It said it had supplied relevant information to support the investigations.
