Term Labs confirmed a governance exploit affecting Term Vaults on August 23. It has not independently confirmed the final dollar loss, while blockchain security firms PeckShield and CertiK have put the estimate at roughly $8.5 million.

PeckShield tracked about 2,843 ETH and 1.68 million USDC leaving the affected vaults. The stablecoins were subsequently exchanged for approximately 1.68 million DAI.

Yearn V3 was underneath the vaults, not the governance attack

Term Strategy Vaults use Yearn V3 infrastructure, but that does not mean the standard Yearn vault system was compromised. Yearn says the exploit involved a custom governance wrapper added around the vaults by Term and that the same attack vector does not apply to standard Yearn vault deployments.

Term's own initial investigation makes a similar boundary around the incident. Its direct fixed-rate borrowing and lending markets have not been identified as affected so far.

The documented governance model already contained a delay

Term's developer documentation describes vault liquidity providers as DAO members with the ability to veto queued governance transactions. Governance actions were also meant to sit behind a seven-day Zodiac Delay Module before execution.

That makes the unanswered technical question more specific: how did an attacker with sufficient voting control get an asset-moving proposal through a system that already advertised both delay and veto mechanisms?

Term Labs has not yet published the final postmortem or confirmed the precise execution path.

On-chain analysis points at the timelock itself

A separate transaction-level analysis argues that the malicious governance action was able to alter the Zodiac Delay configuration as part of an authorized action bundle, setting delay-related parameters to zero before enabling subsequent transactions to execute immediately.

That account is considerably more detailed than Term's public incident statements, so it should not be treated as the company's final root-cause analysis. What Term has confirmed is the governance exploit and the permanent shutdown that followed it.

Deposits are permanently closed

Term Labs has revoked the DAO governance roles attached to all Term Meta Vaults. The shutdown is irreversible and prevents new deposits, while withdrawals remain available for balances that are still present.

The company says it is working with external security teams on remediation and asset recovery. It also plans to explore ways to address any remaining shortfall, but no detailed compensation program had been announced by August 24.

DefiLlama data cited by CoinDesk put the vault product at roughly $12.45 million before the incident. An $8.5 million loss would equal about 68% of those assets and included nearly all of the ether deposited in the vault product.