The attacker who drained roughly $8.5 million from Term vaults did not only acquire votes. According to the protocol’s own account, the proposals removed the windows in which liquidity providers could have stopped them.
Term Labs says one proposal was titled as an LP veto, phrased as a vote to block a curator’s parameter changes, while among its effects was setting the governance delay to zero. A second campaign did the same across five further strategies.
Term Labs published a technical account of the August 23 exploit on September 2, stating that all fixed-rate loan positions held in the affected vaults have been recovered, the last of them on August 25 at 14:52 UTC.
The Setup Ran Over Six Days
According to the account, operator wallets were funded through Tornado Cash. The first was funded on August 17, and an ETH proposal was submitted the same morning roughly twenty-four minutes later.
That proposal carried a title framing it as a vote to veto a curator’s proposed vault parameter changes. Among its effects was setting the governance delay for that stack to zero, which Term Labs says removed an additional seven-day, one-hour window in which liquidity providers could have intervened.
A second operator was funded through Tornado Cash on August 18. That afternoon it deployed a contract combining a controller, a price adapter, and a counterfeit repo token, together with a helper initialized with it. On August 21 the helper submitted seven proposals and cast the only votes. Two sat on ETH strategy DAOs and were never executed. The remaining five each set their stack’s governance delay to zero, removing a further three-day, one-hour window.
Execution Took 22 Minutes
The first proposal was executed on August 23 at 06:25 UTC. Four live ETH strategies—Shorewoods, August Digital, Parity Prime, and Parity Core—were recalled into the meta vault and routed into a newly added strategy named frWETH-EXIT, described as a Fixed Recipient WETH Exit Strategy.
That strategy pulled the WETH from the vault and forwarded the entire amount to the operator within the same call, leaving the meta vault holding 2,841.74 shares of an empty strategy.
The second campaign was executed at 06:47 UTC against five USDC strategy DAOs: Parity Prime, Parity Core, Parity HY, Parity HY v2, and RockawayX Tori. In each, the DAO sold a single unit of a counterfeit repo token into its strategy at a price that absorbed the strategy’s entire liquid USDC, then approved and swept the proceeds to the second operator’s wallet.
The Counterfeit Token Priced Itself
Term Labs says the sale was possible because the same proposals first installed a contract that spoofed two checks at once—the controller, which determines whether a token is a genuine Term instrument, and the price adapter, which determines what it is worth.
The proposals also set each strategy’s reserve ratio to zero and its concentration limit to maximum, so neither cap constrained the sale. The counterfeit token’s redemption value was dynamic, returning each strategy’s precise liquid balance at the moment of execution, which meant every one-unit sale priced to what that strategy could pay.
What Was Not Reached
Term Labs says it does not believe its V1 and V2 contracts were compromised at any point. Direct borrowing and lending markets were unaffected and remain open, with supply, repayment, and liquidation continuing without interruption.
The company says the incident was confined to liquid balances held within Term vaults. The vaults’ fixed-rate loans were never reachable by the attack but at maturity would have redeemed into the same captured vaults. To prevent that, the affected contracts were upgraded and moved out ahead of maturity.
Meta vaults and affected strategies are now shut down, with remaining low-activity vaults in progress. Term Labs says it is working with law enforcement agencies and cybersecurity firms to identify those responsible.
The Account Refines the Early Reporting
Security firms PeckShield and CertiK traced roughly 2,843 ETH, whose worth they pegged around $6.87 million, and 1.68 million USDC, later swapped into DAI, to a single address. The Crypto Times reported the exploit on August 23, when the available account came from Decurity’s monitoring bot Defimon and described an attacker cheaply acquiring a majority of a sparsely held governance token before passing malicious proposals.
Term Labs’ technical account is consistent with that outline but adds the mechanism and specifies that the delay-zeroing removed windows that would otherwise have given LPs days rather than hours to react. The company describes the account as based on its current understanding.
The loss made Term the largest single incident in a week that drained roughly $15.4 million across five protocols and contributed to August losses that CertiK put at $215 million.
