Term Finance shuts down Meta Vaults after $8.5 million exploit
Term Finance halts Meta Vaults after security breach
Term Finance, a decentralized finance (DeFi) platform, has permanently shut down its Meta Vaults after a governance exploit led to the loss of an estimated $8.5 million in crypto assets. The company announced the shutdown on August 23, stating that the decision is irreversible and prevents further deposits into the vaults.
Withdrawals from the vaults remain open, but Term Finance has not disclosed how much money is left in the vaults or how it plans to address any shortfall. The company said it is exploring ways to recover lost funds but did not provide a timeline or guarantee for reimbursement.
Estimated losses and on-chain evidence
Blockchain security firm PeckShield estimated that the attacker drained about 2,843 ETH (worth approximately $6.87 million at the time) and 1.68 million USDC, which was later swapped into roughly 1.68 million DAI. PeckShield put the total loss at around $8.5 million. Term Finance did not confirm this estimate in its official statement.
On-chain records show two transactions linked to the exploit. One transaction sent 2,841.74 WETH (a version of Ethereum that can be traded more easily) to an address labeled "Term Finance Exploiter 1." Another transaction sent 1.68 million USDC to an address labeled "Term Finance Exploiter 2."
How the exploit happened
Term Finance uses vault contracts based on Yearn Finance’s V3 architecture, but the exploit occurred through Term’s custom governance wrapper—a tool that manages how decisions are made and executed in the system. Yearn Finance confirmed that the attack did not affect its standard vaults.
According to Term Finance’s governance documentation, proposals go through a seven-day delay before being executed by a Governor Safe, which oversees risk settings and emergency controls. The company said it revoked DAO (decentralized autonomous organization) governance roles after the incident but did not specify which roles were removed or provide transaction details.
What is confirmed and what remains unclear
Confirmed:
- Term Finance has permanently shut down its Meta Vaults and revoked DAO governance roles.
- Withdrawals from the vaults are still allowed.
- The exploit involved the loss of approximately 2,843 ETH and 1.68 million USDC, totaling around $8.5 million, according to PeckShield.
- The exploit targeted Term’s custom governance wrapper, not Yearn Finance’s standard vaults.
- Term Finance’s direct borrowing and lending markets were not affected.
Unclear:
- How much money remains in the vaults and how much depositors may recover.
- Which specific DAO governance roles were revoked and whether the exploited permissions were fully removed.
- Whether Term Finance will reimburse affected users and, if so, when and how.
Why this matters for DeFi users
This incident highlights risks in DeFi platforms, particularly those using custom governance tools. While Term Finance acted quickly to shut down the affected vaults, the lack of clarity on recovery plans may concern users who lost funds. The exploit also shows how vulnerabilities in governance systems can lead to significant financial losses, even when the underlying protocol remains secure.