Term Finance kills Meta Vaults after governance process clears path for $8.5 million drain
On-chain fixed-rate lending protocol Term Finance said it permanently shut down its Meta Vaults after a governance exploit, ending new deposits while leaving withdrawals open.
Term Labs said it also revoked the vaults' DAO governance roles.
Blockchain security firm PeckShield separately estimated that the attacker removed about 2,843 ETH worth $6.87 million and 1.68 million USDC, which was swapped for roughly 1.68 million DAI.
Term has not confirmed the roughly $8.5 million total or published its own vault-by-vault accounting.
How the exploit moved through governance
Term's governance documentation describes an opt-out system. Vault liquidity-provider token holders can veto queued parameter changes during a seven-day delay, and the change can become executable without a veto.

A DeFiPrime reconstruction of the on-chain activity said an ETH Meta Vault proposal remained open for six days without a veto. Its first actions on execution set the delay cooldown to zero, removing the second waiting period before the transaction routed 2,841.7435 WETH through a newly added strategy to an attacker-controlled address.
The Ethereum transaction occurred at 06:25 UTC on Aug. 23. A second transaction about 22 minutes later executed five proposals across five USDC vaults and removed 1,679,639.29 USDC, according to the same analysis.
Term has not published a postmortem confirming how the proposer obtained authority to queue those actions or why the veto and delay controls did not stop them.
Yearn said Term's vault contracts use Yearn V3 architecture, but the exploit occurred through Term's custom governance wrapper. It said the attack vector does not apply to standard Yearn vault setups and that standard Yearn vaults were unaffected.
Term similarly said its underlying protocol and direct borrowing and lending markets had not been affected based on its investigation so far, while adding that it was still verifying the scope. That limits the confirmed impact to the vault product rather than every Term market.
The remaining question is what Meta Vault users can recover. Because Term has not confirmed the final accounting, keeping withdrawals open does not by itself establish the liquidity or value available for every withdrawal.
Term said it was coordinating with outside security teams on remediation and recovery. If a shortfall remains, it said it would explore ways to address it. The company did not commit to reimburse depositors or provide a recovery timetable.