$8.5M Governance Attack on Term Labs Successfully Exploited, Positions Recovered
Term Labs has recovered all fixed-rate loan positions affected by its August governance exploit, which drained around $8.5 million from Term Finance vaults. The final position was moved on Aug. 25, after the protocol's V1 and V2 contracts were found to be unaffected.
The attack involved two operator wallets funded through Tornado Cash, with the first receiving funds on Aug. 17 and submitting a governance proposal titled 'Vote YES to VETO the curator’s proposed vault parameter changes.' The change removed an additional seven-day delay before the proposal's execution.
The attacker then deployed a singleton contract combining three functions in one deployment: a controller, a price adapter, and a counterfeit repo token. A helper contract was initialized using the singleton, which submitted seven governance proposals on Aug. 21. The proposals reduced the relevant governance Delay to zero, allowing the attacker to execute the sale of fake tokens for virtually the strategy's entire available balance.
Term Labs responded by upgrading affected contracts and moving fixed-rate positions before maturity. All affected fixed-rate loan positions have since been recovered.