Term Finance has permanently shut down its Meta Vaults after a governance exploit drained an estimated $8.5 million in ETH and stablecoins, according to PeckShield and Term Labs’ Aug. 23 update. The core lending protocol appears to have stayed intact, but the vault layer took a real hit, the kind DeFi loves to pretend can’t happen until, well, it does.
- Meta Vaults permanently closed
- Withdrawals remain open; new deposits are blocked
- Exploit hit Term’s custom governance wrapper, not standard Yearn V3
- Recovery, reimbursement, and full accounting are still unresolved
Term Labs said it had shut down every Term Meta Vault and revoked the DAO governance roles tied to the products. The company described the shutdown as permanent and said it cannot be reversed.
That matters because Meta Vaults were not Term’s entire protocol. They were a separate product layer that allocated user deposits into managed strategies. Term’s main service, fixed-rate borrowing and lending through on-chain auctions, was reportedly not affected.
Existing depositors can still submit withdrawals, but new deposits are blocked. Term did not say how much value remains inside the vaults or how much each depositor will be able to take out. So yes, the exit door is open, but the balance sheet is still under a tarp.
Term Labs said it would “explore pathways” to cover any gaps, but that is not the same thing as a compensation plan. There is no reimbursement commitment, no payment schedule, and no clear timetable for a full post-incident report. External security specialists are helping with remediation and asset recovery, though Term has not named them publicly.
PeckShield estimated the loss at approximately $8.5 million, tracing 2, 843 ETH and 1.68 million USDC. The ETH was worth about $6.87 million when the transactions happened. PeckShield also said the attacker swapped the 1.68 million USDC for roughly the same amount of DAI.
The firm traced the attacker’s initial funding to 2 ETH received through Tornado Cash. That does not identify the attacker, but it does make attribution messier, which is kind of the point of a mixer. Privacy tools are useful, necessary in many cases, and also regularly abused by criminals. Both things can be true at once, no matter how much everyone would prefer a neat morality play.
Reports citing Etherscan showed 2, 841.74 wrapped ETH sent to an address labeled “Term Finance Exploiter 1” and 1.68 million USDC sent to “Term Finance Exploiter 2.” Those labels are useful breadcrumbs, not proof of identity. Explorers can map the trail; they cannot tell you who was sitting at the keyboard.
The most important technical detail is that this appears to have been a governance exploit, not a conventional bug in the underlying Yearn V3 architecture. Yearn said the affected contracts were built on its V3 framework, but the exploit ran through a custom governance wrapper around the vaults.
“While their contracts are built on Yearn’s V3 architecture, the exploit occurred via a custom governance wrapper around the vaults, ”
Yearn also said the same attack route does not apply to standard Yearn vault configurations. That distinction is important. It means the weak point was Term’s custom control layer, the machinery that determines who can vote, who can move assets, and under what rules, rather than a flaw in Yearn’s default vault design.
In plain English, a governance wrapper is the extra permission layer wrapped around a product’s voting and control system. It sounds harmless. It is not. In DeFi, that extra layer is often where the “creative” engineering lives, and also where the rake is hiding in the grass.
A separate attack analysis claimed the attacker spent about $951 to obtain enough governance tokens to control four USDC strategy vaults and roughly 91% of the Ethereum Meta Vault. That same analysis said the vault product held about $12.45 million in depositor funds before the attack, implying a loss of nearly 68% of the deposited value.
Those figures are striking, but they should be read as third-party analysis, not as Term’s final accounting. PeckShield’s estimate and the vault-balance analysis do not line up neatly because they are measuring different things: one focuses on traced stolen assets, the other on control over vault governance and the amount of funds exposed before the attack. The bottom line is still ugly either way.
Term Labs said its investigation found no impact on the underlying Term protocol or its direct lending markets. That is a meaningful clarification. It does not make the exploit small, but it does narrow the blast radius. The Meta Vaults were hit; the broader protocol was not reported as drained.
That distinction is more than semantics. It is the difference between a product-layer failure and a protocol-wide collapse. One is bad. The other is catastrophic.
The bigger lesson is that governance itself has become a live attack surface in DeFi. Once a system lets voting power move money, attackers start looking for ways to buy, borrow, manipulate, or outright steal that control.
Recent incidents show the pattern clearly. In July, an attacker used purchased voting power to transfer about $20 million in BONK from BonkDAO’s treasury. On Aug. 18, Binance said it detected a malicious proposal threatening about $1.2 million held by an unnamed DAO and helped stop it before execution. ENS DAO, meanwhile, activated a security council with eight members and required five signatures to veto queued transactions.
That is the real trend here: DAOs are learning, sometimes the hard way, that decentralized governance is not automatically secure governance. If the token vote can move assets, then the token vote can be attacked. Fancy democracy with a treasury attached is still a target-rich environment.
The Tornado Cash trail adds another layer of controversy, but it should not be overread. The fact that PeckShield traced the attacker’s initial 2 ETH through a mixer suggests an attempt to obscure funding sources, not a confirmed identity. Tornado Cash remains politically radioactive because it serves both privacy-seeking users and criminals, a dual-use reality regulators hate and cypherpunks understand all too well.
That backdrop also matters because the legal climate around mixers has only gotten harsher. In August 2025, a federal jury convicted Roman Storm of conspiring to operate an unlicensed money-transmitting business, and the U.S. Attorney’s Office for the Southern District of New York said Tornado Cash had transmitted more than $1 billion in criminal proceeds. Those are separate legal developments, but they show why any funding trail touching a mixer draws attention fast.
Still, none of that proves who attacked Term. It does, however, explain why governance exploits, mixers, and custom DeFi wrappers make such a nasty combination: hard to trace, easy to execute, and expensive to unwind.
Key questions and takeaways
-
Did Term Finance shut down the Meta Vaults for good?
Yes. Term Labs said all Term Meta Vaults were shut down permanently, the decision cannot be reversed, new deposits are blocked, and withdrawals remain open. -
Was Yearn V3 itself hacked?
No evidence points to a flaw in standard Yearn V3 vaults. Yearn said the exploit used Term’s custom governance wrapper, not the default Yearn vault setup. -
How much was lost?
PeckShield estimated about $8.5 million in losses, based on 2, 843 ETH and 1.68 million USDC. A separate analysis suggested the vault product held about $12.45 million before the attack, but that is not Term’s final accounting. -
Can users still withdraw funds?
Yes, withdrawals are still open. But Term has not disclosed how much value remains in the vaults or how much each depositor can actually withdraw. -
Will users be reimbursed?
Maybe, but nothing is guaranteed yet. Term said it would “explore pathways” to cover any gaps, which is not the same thing as a compensation plan. -
Why does this matter beyond Term?
Because governance is now an attack surface across DeFi. If voting power can move funds, attackers will keep trying to acquire that power cheaply, temporarily, or by stealth.
The clean read is simple: Term’s Meta Vault design failed under pressure, and the failure appears to have lived in the custom governance layer rather than the underlying Yearn framework. That does not excuse the loss, and it certainly does not make users whole. It does, however, sharpen the lesson for every protocol still pretending governance risk is a side issue.
DeFi does not just need better code. It needs harder governance design, tighter permissions, and fewer hand-rolled shortcuts dressed up as innovation until somebody drains the treasury.
For more context on the incident and its aftermath, see Term Finance Shuts Meta Vaults After $8.5M Governance, Term Labs Loses $8.5M After Governance Takeover Costing, and the Term Finance Closes Meta Vaults After $8.5M Attack update.