Login
Sign Up
Woofun AI reports that Term Finance permanently shut down its Meta Vaults following a governance exploit that drained $8.5 million in WETH, while Term Labs simultaneously revoked the vaults' DAO governance roles to secure the remaining infrastructure.
Woofun AI data shows, The technical execution of the breach, reconstructed by DeFiPrime, revealed that an ETH Meta Vault proposal remained open for six days without triggering a veto. Upon execution, the attacker set the delay cooldown to zero, effectively bypassing the second waiting period before routing 2,841.7435 WETH through a newly added strategy to an attacker-controlled address. This sequence highlights a critical failure in the veto and delay controls that were supposed to prevent such unauthorized transactions.
Structurally, the impact appears contained to the vault product rather than the broader ecosystem, as Term stated its underlying protocol and direct borrowing and lending markets had not been affected based on initial investigations.
However, the protocol has not published a postmortem confirming how the proposer obtained the authority to queue those actions or why the existing safeguards failed to stop them. Consequently, the confirmed damage is limited to the Meta Vaults, leaving the wider Term market intact but raising questions about governance security.
Recovery efforts are currently underway, with the protocol coordinating with outside security teams on remediation and recovery strategies. While withdrawals remain open, Term has not confirmed the final accounting, meaning liquidity availability for Meta Vault users is uncertain. The company did not commit to reimburse depositors or provide a recovery timetable, leaving the potential shortfall and final user implications unresolved.