The attack bypassed traditional smart contract vulnerabilities by weaponizing the protocol's own governance mechanism. According to blockchain security firm PeckShield, the perpetrator spent roughly $951 to acquire enough voting power to seize control of four USDC strategy vaults and a significant majority of the Ethereum Meta Vault. Once in control, the attacker executed authorized proposals to siphon 2,843 ETH and 1.68 million USDC. While deposits are now permanently blocked, the team has kept withdrawal functions active for existing users.
Term Labs has yet to provide a concrete plan for compensating those affected, stating only that they are exploring pathways to address the shortfall. The firm has not disclosed how much capital remains in the vaults or whether they have engaged law enforcement to trace the funds, which were routed through Tornado Cash. Yearn, whose V3 architecture provided the base for the vaults, clarified that its standard products remain secure, noting that the vulnerability was isolated to a custom governance wrapper developed specifically for Term’s now-defunct products.

Comments (0)
No comments yet. Be the first!