Term Finance kills Meta Vaults after governance process clears path for $8.5 million drain
On-chain fixed-rate lending protocol Term Finance said it permanently shut down its Meta Vaults after a governance exploit, ending new deposits while leaving withdrawals open. Term Labs said it also revoked the vaults' D...
Watchlist
Published in the last two hours. Multiple named entities are involved.
On-chain fixed-rate lending protocol Term Finance said it permanently shut down its Meta Vaults after a governance exploit, ending new deposits while leaving withdrawals open.
Term Labs said it also revoked the vaults' DAO governance roles.
Blockchain security firm PeckShield separately estimated that the attacker removed about 2,843 ETH worth $6.87 million and 1.68 million USDC, which was swapped for roughly 1.68 million DAI.
Term has not confirmed the roughly $8.5 million total or published its own vault-by-vault accounting.
How the exploit moved through governanceTerm's governance documentation describes an opt-out system. Vault liquidity-provider token holders can veto queued parameter changes during a seven-day delay, and the change can become executable without a veto.
Timeline showing how the Term Meta Vault drain unfolded, from governance changes to WETH and USDC transfers and the vault’s shutdown.A DeFiPrime reconstruction of the on-chain activity said an ETH Meta Vault proposal remained open for six days without a veto. Its first actions on execution set the delay cooldown to zero, removing the second waiting period before the transaction routed 2,841.7435 WETH through a newly added strategy to an attacker-controlled address.
The Ethereum transaction occurred at 06:25 UTC on Aug. 23. A second transaction about 22 minutes later executed five proposals across five USDC vaults and removed 1,679,639.29 USDC, according to the same analysis.
Term has not published a postmortem confirming how the proposer obtained authority to queue those actions or why the veto and delay controls did not stop them.
Related Reading BonkDAO’s treasury raided for $20M due to lack of governance interestYearn said Term's vault contracts use Yearn V3 architecture, but the exploit occurred through Term's custom governance wrapper. It said the attack vector does not apply to standard Yearn vault setups and that standard Yearn vaults were unaffected.
Term similarly said its underlying protocol and direct borrowing and lending markets had not been affected based on its investigation so far, while adding that it was still verifying the scope. That limits the confirmed impact to the vault product rather than every Term market.
The remaining question is what Meta Vault users can recover. Because Term has not confirmed the final accounting, keeping withdrawals open does not by itself establish the liquidity or value available for every withdrawal.
Term said it was coordinating with outside security teams on remediation and recovery. If a shortfall remains, it said it would explore ways to address it. The company did not commit to reimburse depositors or provide a recovery timetable.
The post Term Finance kills Meta Vaults after governance process clears path for $8.5 million drain appeared first on CryptoSlate.
Why this matters
USD Coin is showing up inside the Stablecoins theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on CryptoSlateRelated market context
Ceffu Pulls $263 Million in Bitcoin and Ethereum off Binance in 30 Minutes
Ceffu, Binance’s institutional custody partner, deposited 136.54 million USDC onto Binance and then withdrew 1,524 BTC and 59,484...
Bitcoin And Ethereum ETFs Add $492M As Inflow Streak Continues
US spot Bitcoin and Ethereum ETFs recorded a combined $492 million in net inflows for the August 21 session, extending a positive...
Saylor sat out Bitcoin’s 20% rally while Tom Lee bought Ethereum after a 30% surge
Bitcoin and Ethereum surged last week as falling Treasury yields, renewed US crypto optimism, and a wave of short liquidations sen...
Ledger CTO breaks down NIST’s post-quantum signatures and what they mean for Bitcoin and Ethereum
The adoption of post-quantum cryptography could reshape blockchain security, impacting transaction costs and requiring user adapta...
Ethereum proposes post-quantum deposit contract to enhance staking security
Ethereum's move towards post-quantum security could bolster its resilience, potentially influencing market confidence and future v...
Ankr joins sBTC signer set to enhance Bitcoin security on Stacks
Ankr's inclusion in the sBTC signer set could bolster Bitcoin's DeFi ecosystem, enhancing security and paving the way for broader...