Term Labs has permanently closed its Meta Vaults and revoked their DAO governance roles, three days after an attacker used purchased voting power to drain roughly $8.5 million from the product.
“All Term Meta Vaults were shut down and dao governance roles have been revoked,” the company said in a post on 23 August. “This shutdown is irreversible and permanently prevents further deposits. Withdrawals remain open.”
The decision goes further than most protocols go after a loss of this size. Term has not paused the vaults pending a fix. It has ended them, and removed the governance mechanism that made the attack possible in the first place.
What it has not done is explain how the attack worked.
The attack cost 2 ETH
The exploit itself was cheap enough to be uncomfortable.
Blockchain security firm PeckShield reported the attacker originally funded the operation with 2 ETH traced to Tornado Cash, then used it to acquire TERM governance tokens. Onchain monitoring service Defimon said the attacker cheaply acquired a majority of a sparsely held governance token and passed proposals that allowed it to seize control of the vaults.
The drain totalled approximately 2,843 ETH, worth about $6.87 million at the time, plus 1.68 million USDC, which was swapped for roughly 1.68 million DAI. CertiK put the combined figure at around $8.5 million.
That represented about 68% of the $12.45 million held in Term’s vault product beforehand, according to DefiLlama, and almost all of the roughly $8.8 million in ether deposits.
No code was broken. Every proposal was valid and every transfer executed as the contracts specified. PeckShield and CertiK both classified the incident as a governance exploit rather than a code exploit.
Two safeguards did not stop it
Term’s vaults were not undefended, which is what makes the missing explanation significant.
The vaults ran on Yearn V3 infrastructure, widely used software that automatically moves deposits between lending markets to chase the best available return. Governance separated operational control from depositor oversight, and vault liquidity providers participating as DAO members could veto queued governance transactions during a seven-day timelock.
Reports indicate the attack circumvented both the seven-day timelock and the LP veto through Term’s specialised governance architecture.
Yearn addressed the incident directly, stating the exploit occurred through Term’s custom governance wrapper rather than any vulnerability in standard Yearn vault configurations, and that standard Yearn vaults were unaffected.
Term has not confirmed how the attacker obtained majority voting control, which governance functions were used, or why the veto and delay controls did not intervene. It has not published a postmortem.
Users are still waiting on the accounting
The most consequential gap is financial rather than technical.
Term has not confirmed the roughly $8.5 million total or published its own vault-by-vault accounting, leaving Meta Vault users without a figure for what remains recoverable. The company said it is coordinating with external security teams on asset recovery and remediation, and will “explore paths to address” any remaining shortfall.
Explore paths is not a commitment to reimburse.
Withdrawals remain open, so users can retrieve whatever survived. Term has also advised depositors to temporarily revoke contract approvals as a precaution and to rely only on verified communication channels while the investigation continues.
Term Labs does not list a public press contact and its direct messages on X were closed. Cointelegraph reported it was unable to reach the company for comment.
The company has been here before
Term made specific commitments after a previous incident, which gives the current silence more weight than it would otherwise carry.
In April 2025, an oracle error triggered roughly 918 ETH in unintended liquidations. Term recovered about 556 ETH, reduced the final loss to around 362 ETH, and reimbursed affected users, according to its postmortem at the time.
Following that incident, the protocol pledged third-party validation for critical updates and greater governance transparency.
The 2025 case was an internal error with no attacker, and Term handled it with a published postmortem and full reimbursement. Whether the same standard applies when the loss is roughly twenty times larger and caused by an external party is the question users are currently waiting on.
Killing governance rather than fixing it
The shutdown is the part worth examining beyond the immediate loss, because Term chose the most drastic available option.
Revoking DAO governance roles removes the attack surface entirely. No token can be accumulated to control something that no longer has a governance layer. It also removes any capacity for the community to direct the product, which for a DeFi protocol is a meaningful concession about what decentralised governance was actually delivering.
Term is not alone in reaching that conclusion. Seamless DAO voted this month to wind down permanently and revoke all administrative control. Velora handed operations to its development company in April. Jupiter suspended DAO voting entirely, with a team member citing a breakdown in trust.
The pattern across all of them is the same underlying problem. Voter participation across major DAOs frequently sits below 5%, which collapses the cost of buying a controlling stake. The BONK DAO treasury attack in July succeeded when only seven addresses voted. Term’s attacker needed 2 ETH.
When acquiring governance control costs less than the assets that governance controls, the voting mechanism stops being a feature and becomes the cheapest way in. Term’s response was to remove it. The remaining question is what depositors get back.
FAQ
What did Term Labs shut down?
All Term Meta Vaults, permanently and irreversibly, along with their associated DAO governance roles. New deposits are blocked for good. Withdrawals remain open.
How much was taken?
Security firms estimate roughly $8.5 million, comprising about 2,843 ETH and 1.68 million USDC that was swapped for DAI. That was around 68% of the vault product’s $12.45 million in assets. Term has not confirmed the figure or published its own accounting.
Was the core protocol affected?
Term says its underlying protocol and direct borrowing and lending markets were unaffected based on its investigation so far, though it is still verifying the scope. Yearn confirmed the exploit involved Term’s custom governance wrapper, not standard Yearn vaults.
Disclaimer: This article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry significant risk. Always conduct your own research before making any investment decisions.



















