- PeckShield put the loss at about US$8.5 million, covering roughly 2,843 ETH worth US$6.87 million and 1.68 million USDC swapped straight into DAI.
- Term Labs shut down every Term Meta Vault and revoked their DAO governance roles, an irreversible step that permanently blocks deposits while withdrawals stay open.
- Yearn said the attack ran through a custom governance wrapper and that deposits in standard Yearn vaults are safe and unaffected.
Term Finance, an Ethereum-based fixed-rate lending protocol, lost about US$8.5 million (AU$11.9 million) on 23 August after an attacker took over the governance system controlling its vaults, and Term Labs has since shut those vaults down for good.
PeckShield put the drain at roughly 2,843 ETH, which it valued at US$6.87 million (AU$9.62 million), alongside 1.68 million USDC worth US$1.68 million (AU$2.35 million) that had already been swapped for about 1.68 million DAI by the time the firm published its alert at 10:07 UTC. PeckShield traced the operation’s starting capital to 2 ETH withdrawn from Tornado Cash.
Proceeds landed at a single externally owned address, 0xD5183d8BfC65a50863C62aF2538198A8288FFc13, an ordinary wallet with no contract code behind it. At block 25,822,718 on 24 August, that wallet held 2,843.2021 ETH and 1,679,642.45 DAI.
Read more: Metaplanet Takes Bitcoin Treasury Strategy to the US With US$132 Million Nasdaq Deal
Vaults Shut Down For Good
“We are aware of a governance exploit impacting Term vaults. We will share more details once it has been further investigated”, Term Labs stated on 23 August.
An update posted at 00:22 UTC on 24 August closed the product outright. “All Term Meta Vaults were shut down and dao governance roles have been revoked. This shutdown is irreversible and permanently prevents further deposits. Withdrawals remain open”, the team confirmed.
“Today’s incident involved Term Vault governance”, the team added. “Based on our investigation so far, the underlying Term protocol and its direct borrowing and lending markets have not been affected”, Term Labs noted, adding that it was still verifying scope. The team said it is coordinating with external security teams on remediation and recovery, and will explore paths to address any shortfall that remains.
Yearn Distances Its Own Vaults
Yearn confirmed at 19:54 UTC on 23 August that Term’s vault contracts are built on its V3 architecture, a layer sitting apart from the direct borrowing and lending markets Term Labs says were untouched.
“The exploit occurred via a custom governance wrapper around the vaults and this attack vector is not applicable to standard Yearn vault setups”, Yearn stated, adding that deposits in standard Yearn vaults “are safe and those vaults are unaffected”.
Neither team has alleged a flaw in the vault contracts themselves, and both confined the incident to the governance layer above them.
PeckShield counted 15 confirmed attacks in February for US$26.5 million (AU$37.1 million), its lowest monthly total since March 2025. A US$15 million (AU$21 million) drain in April forced the Kyrgyzstan-registered exchange Grinex to halt withdrawals and trading.
Term’s own site advertises a DeFiSafety score of 93% and audits by Sigma Prime, Runtime Verification, Dedaub and Certora.
Read more: South Korea Orders Polymarket Blocked Over Illegal Gambling Concerns
Cryptocurrency,Ethereum#Term #Finance #Loses #8.5M #Governance #Exploit1787565314
