A Daily Network publication
Explore the network
Digital Capital Daily
Independent Intelligence on Institutional Digital Assets
Tuesday, August 25, 2026The Morning Brief →Sign in
The Wrap

Term Finance shuts Meta Vaults after governance exploit

Term Labs has permanently closed its Meta Vaults after a governance exploit PeckShield estimated at $8.5 million, and depositor recovery remains unresolved.

A governance exploit estimated at $8.5 million by PeckShield, according to The Defiant, has pushed Term Labs to permanently shut down its Meta Vaults. In the Aug. 23 update announcing the irreversible shutdown, new deposits are blocked, withdrawals remain open, and the company says it revoked DAO governance roles after the incident without identifying which roles, which contract addresses, or which revocation transactions — so the public record does not establish whether the precise permissions used in the exploit have actually been removed.

PeckShield's estimate of roughly 2,843 ETH, then worth $6.87 million, plus 1.68 million USDC swapped into about 1.68 million DAI, is corroborated by two onchain transactions. One moved 2,841.74 WETH to an address labeled Term Finance Exploiter 1, and a second moved 1.68 million USDC to Term Finance Exploiter 2. Yearn, whose V3 architecture underpins the vault contracts, said the exploit ran through Term's custom governance wrapper, a path outside standard Yearn vault setups.

Term's own governance documentation describes a proposal path from a Proposer Safe through a seven-day delay and a Governor Safe to a vault, with the governor role overseeing risk parameters and emergency controls. The exploit hit that wrapper, not the vault code underneath. Term said its underlying protocol and direct borrowing-and-lending markets were unaffected, and Yearn separately confirmed its own vaults were unaffected, but the update did not quantify assets still inside the shuttered vaults and offered no reimbursement commitment or recovery timetable — only that the company would 'explore paths' if a shortfall remains.

Permanent closure is the right response to a product whose governing permissions became the attack vector and whose cleanup details remain unpublished. For the broader experiment in on-chain lending, the episode is a reminder that governance is the layer where these products are most exposed. Still unanswered is how much of the $8.5 million PeckShield estimates was taken actually returns.

Sources & further reading
The Defiant — Institutional
More from Digital Capital Daily
The Wrap

Arc’s mainnet launch tests settlement, not scale

Eleven bank validators and half a billion test transactions have not answered whether a permissioned chain can settle without central-bank money.
Elsewhere in the networkAll titles →
Every weekday · 6:30 a.m. ET

The Morning Brief

The private wealth industry in four minutes, every weekday at 6:30 a.m. ET. Free.