Term Finance closes Meta Vaults after estimated $8.5M attack
Term Finance has permanently closed its Meta Vaults and removed their DAO governance powers after an attacker drained an estimated $8.5 million in ETH and stablecoins.
- Term Finance has permanently blocked new deposits while keeping withdrawals available.
- PeckShield estimated that the attacker removed 2,843 ETH and 1.68 million USDC.
- Yearn said the exploit targeted Term’s custom governance wrapper, not standard Yearn V3 vaults.
- Term Labs has not confirmed depositor repayments, recovery amounts, or a compensation timeline.
Term Finance permanently blocks Meta Vault deposits
Term Labs said in an Aug. 23 update that it had shut down every Term Meta Vault and revoked the DAO governance roles connected to the products. The action cannot be reversed and prevents users from making new deposits, although existing depositors can continue submitting withdrawals.
“All Term Meta Vaults were shut down and DAO governance roles have been revoked,” the development team said.
Term Labs did not disclose how much remained inside the vaults or how much each depositor could withdraw. Instead, the team said it would “explore pathways” to cover any gaps, leaving the final recovery amount and the treatment of any shortfall undecided.
No compensation plan, reimbursement commitment, or payment schedule accompanied the update. The protocol also has not announced whether it has contacted the attacker, law enforcement agencies, centralized exchanges, or stablecoin issuers in an attempt to freeze or recover any assets.
The closure followed Term Labs’ initial confirmation that a governance exploit had affected its vaults. As crypto.news reported on Aug. 23, the first statement did not identify the compromised contracts, pause status, or estimated loss because the investigation was still underway.
At the time, Term Labs said:
“We are aware of a governance exploit impacting Term vaults. We will share more details once it has been further investigated.”
The latest notice settles the operational status of the Meta Vaults but leaves the financial accounting incomplete. Term Labs has not published a vault-by-vault breakdown, a final technical report, or a confirmed figure for missing customer assets.
PeckShield traces ETH and stablecoin transfers
Blockchain security firm PeckShield estimated the loss at approximately $8.5 million after tracing around 2,843 ETH and 1.68 million USDC from the affected vaults. The ETH was worth about $6.87 million when the transactions occurred.
According to the security firm, the attacker exchanged the 1.68 million USDC for approximately the same amount of DAI after removing it from the protocol. PeckShield also traced the attacking wallet’s initial funding to 2 ETH received through Tornado Cash, although the transfer does not reveal who controlled the wallet.
Etherscan records cited in reports on the attack show that one transaction sent 2,841.74 wrapped ETH to an address labeled “Term Finance Exploiter 1.” A separate transfer moved 1.68 million USDC to an address identified by the explorer as “Term Finance Exploiter 2.”
Etherscan labels help users follow addresses connected with reported incidents, but they do not identify the individual or organization behind an account. Term Labs has not publicly named a suspect or said whether investigators have linked the wallets to an exchange account with verified customer information.
A subsequent attack analysis found that the attacker spent about $951 to obtain enough governance tokens to control four USDC strategy vaults and roughly 91% of the Ethereum Meta Vault. According to the report, Term’s vault product held about $12.45 million in depositor funds before the attack, putting the estimated loss at nearly 68% of the deposited value.
The report said the transactions did not depend on a conventional smart contract coding error. The attacker instead used the protocol’s authorized governance process after gaining enough voting power to submit and approve proposals that directed the vaults to move funds.
Term Labs has not yet confirmed the $951 purchase, the reported voting percentages or the estimated share of vault assets lost. A complete account remains dependent on the team’s technical investigation and reconciliation of each affected contract.
Yearn says its standard V3 vaults were not exposed
Yearn said in its response that Term’s affected contracts were based on the Yearn V3 architecture, but the attacker used a governance wrapper developed specifically for Term’s vault products.
“While their contracts are built on Yearn’s V3 architecture, the exploit occurred via a custom governance wrapper around the vaults,” Yearn said, adding that the same attack route did not apply to standard Yearn vault configurations.
According to Yearn, funds held in its regular vaults were not affected. The statement separated Term’s added governance system from Yearn V3’s main vault contracts, which allow outside developers to build customized products around the underlying architecture.
Term Labs likewise said its current investigation had found no impact on the underlying Term protocol or its direct lending markets. Its Meta Vaults operated as a separate product layer that allocated deposited assets through managed strategies, while the main protocol offered fixed-rate borrowing and lending through on-chain auctions.
External security specialists are assisting with remediation and asset recovery, according to the development team. Term Labs has not named the firms, described the steps being taken, or set a date for a post-incident report.
Governance attacks have prompted tighter DAO controls
Term Finance is not the first protocol in 2026 to lose control of assets through an approved governance action. In July, an attacker used purchased voting power to pass a proposal that transferred about $20 million in BONK from BonkDAO’s treasury.
Following that attack, ENS DAO activated a security council with eight members and limited authority to cancel malicious proposals. Five signatures are required to veto a queued transaction, while the council cannot transfer treasury assets or rewrite proposals.
Another attempted governance attack was stopped before funds moved. Binance said on Aug. 18 that its security team detected a malicious proposal threatening about $1.2 million held by an unnamed DAO. The exchange contacted the project with less than 48 hours left before execution, and the proposal was rejected without a reported loss.
For U.S. users, the Securities and Exchange Commission’s position on decentralized organizations depends on the facts and economic structure of each arrangement. In its 2017 DAO report, the SEC concluded that the DAO tokens examined in that case were securities and said organizations using distributed ledgers for capital raising must comply with applicable federal securities laws.
The SEC report did not address Term Finance, and no U.S. regulator has publicly announced an investigation into the Meta Vault attack. PeckShield’s reported Tornado Cash funding trail also does not establish that the stolen assets entered the United States or passed through a U.S.-controlled service.
In August 2025, a federal jury convicted Tornado Cash co-founder Roman Storm of conspiring to operate an unlicensed money-transmitting business. The U.S. Attorney’s Office for the Southern District of New York said the service had transmitted more than $1 billion in criminal proceeds.