Governance exploit drains $8.5 million from Term Labs vaults

Term Labs, the team behind the Ethereum-based fixed-rate lending protocol Term Finance, confirmed a governance exploit that drained roughly $8.5 million from vaults built on Yearn v3 infrastructure. An attacker accumulated enough voting power to gain full control of four of five USDC strategy vaults and about 91 percent control of the Ethereum Meta Vault, then used that supermajority to direct the vaults to release their funds to a single address beginning 0xD5183.

The stolen funds included roughly 2,843 ETH, worth about $6.87 million, and 1.68 million USDC, which the attacker later swapped for around 1.6 million DAI. PeckShield traced the attacker's initial funding to just 2 ETH routed through Tornado Cash. PeckShield and CertiK both tracked the destination wallet, though Term Labs has not published a technical post-mortem or named the specific governance function that was abused.

No smart contract broke; the vaults did exactly what their governance told them to do. That distinction matters, since patching code does nothing against an attacker who can simply out-vote everyone else.