$8.5M Drained from Term Finance's Meta Vaults in Governance Exploit
Term Finance permanently shut down its Meta Vaults on August 23 after a governance exploit allowed an attacker to drain about $8.5 million from the vaults.
The exploit occurred when a proposal remained open for six days without a veto, allowing it to execute and remove the delay cooldown. This cleared the path for the attacker to route 2,841.74 WETH (~$6.87M) and 1,679,639 USDC (swapped to ~1,68M DAI) through newly added strategies to an attacker-controlled address.
Term Labs revoked the vaults' DAO governance roles and left withdrawals open, but has not published a full accounting of the drain or committed to reimburse depositors. The company is coordinating with outside security teams on remediation and recovery, and will explore ways to address any shortfall if one remains.
Yearn said that Term's vault contracts use Yearn V3 architecture, but the exploit occurred through Term's custom governance wrapper, which does not affect standard Yearn vault setups. Term also stated that its underlying protocol and direct borrowing and lending markets were unaffected by the attack.