Term Finance Permanently Closes Meta Vaults After Governance Exploit Tied to ~$8.5M Loss
AI مارکیٹ کا خلاصہ
Term Finance permanently shut its Meta Vaults after a governance exploit enabled an estimated $8.5M drain, including ~2,843 ETH and 1.68M USDC swapped into DAI. Deposits are halted while withdrawals remain open, but final accounting and any shortfall are unconfirmed and no reimbursement commitment was made. The incident highlights governance and wrapper-risk in DeFi vault designs, potentially weighing on near-term ETH and DeFi risk appetite.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
ETH/USDT+0.45%
AI تجزیاتی سمجھ · ETH/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Term Finance has permanently shut down its Meta Vaults after a governance exploit that enabled an estimated $8.5 million to be drained. New deposits have been halted, while withdrawals remain open. Term Labs has also revoked the vaults' DAO governance roles.
Security firm PeckShield estimated the attacker removed roughly 2,843 ETH valued at $6.87 million, along with 1.68 million USDC. The USDC was swapped for about 1.68 million DAI. Term Finance has not confirmed the $8.5 million estimate and has not released its own vault-by-vault accounting.
According to Term Finance's governance documentation, the vaults use an opt-out model: liquidity provider token holders can veto queued parameter changes during a seven-day delay window, and changes become executable if no veto is filed. A DeFiPrime reconstruction said an ETH Meta Vault proposal sat for six days without a veto. The proposal's initial execution steps set the delay cooldown to zero, after which 2,841.7435 WETH was routed through a newly added strategy to an attacker-controlled address. That Ethereum transaction was executed at 06:25 UTC on Aug. 23.
A second transaction followed roughly 22 minutes later, executing five proposals across five USDC vaults. The same analysis put the USDC removed at 1,679,639.29.
Term Finance has not published a postmortem explaining how the proposer obtained authority to queue the actions, or why the veto and delay controls failed to stop the exploit.
Yearn said Term's vault contracts are built on Yearn V3 architecture, but argued the issue stemmed from Term's custom governance wrapper. Yearn added that the attack vector does not apply to standard Yearn vault deployments and said standard Yearn vaults were unaffected.
Term Finance said its underlying protocol and direct borrowing and lending markets have not been impacted based on its investigation so far, while it continues to verify the scope. On that basis, the confirmed impact remains limited to the vault product rather than all Term markets.
The company said it is coordinating with external security teams on remediation and recovery, and will explore ways to address any remaining shortfall. It did not commit to reimbursing depositors and did not provide a recovery timeline. Term added that open withdrawals do not necessarily indicate sufficient liquidity or final value for every withdrawal because the final accounting has not been confirmed.