Term Labs Vault Governance Exploit Results in $8.5 Million Loss
A governance exploit affected Term Labs' vaults on August 23, 2023, resulting in an estimated $8.5 million loss. The attackers drained Ethereum and USDC from the affected Term vaults. PeckShield reported that the attacker exchanged roughly 1.6 million USDC for 1.6 million DAI.
The incident was confirmed by Term Labs through its X post, which also stated that an investigation is ongoing. The team had not published a technical postmortem at the time of writing. CertiK tracked about $8.5 million in losses from the governance attack and identified the attacker's address as 0xD5183d8BfC65a50863C62aF2538198A8288FFc13.
Term Finance's documentation warned users that vault smart contracts could contain vulnerabilities that could cause fund losses. The company's legal disclosures stated that Term Vaults rely on Yearn v3 contracts and external decentralized finance protocols.