Uncategorized

Term Labs Reclaims Fixed-Rate Positions After $8.5M Governance Breach

Term Labs has successfully retrieved all fixed-rate loan positions impacted by the governance exploit that occurred in August, with the last position being moved on August 25, while Meta Vaults and affected strategies remain deactivated.

Summary

  • Term Labs fully recovered all impacted fixed-rate loan positions by August 25, whereas its Meta Vaults and related strategies are still inactive.
  • Malicious governance proposals were leveraged by attackers to eliminate execution delays before draining liquid ETH and USDC from vault strategies.
  • A counterfeit repo token was valued against each strategy’s exact liquid USDC balance, allowing the attacker to misappropriate the available funds.
  • According to Term Labs, its V1 and V2 contracts were safeguarded, and its direct borrowing and lending markets continued to function normally.

In its latest incident report, Term Labs confirmed that the last fixed-rate position was recovered at 14:52 UTC on August 25, and the investigation determined that the attack was limited to liquid balances within Term vaults.

The protocol further indicated that its V1 and V2 contracts remained uncompromised, with its direct lending and borrowing markets operating continuously during the incident.

Term Labs claims lending contracts evaded the vault exploit

The updated technical account provides a more comprehensive overview of the attack that took place on August 23, which security analysts had previously estimated resulted in losses of about $8.5 million from Term Finance vaults.

Term Labs initially reported a governance exploit affecting vaults without detailing the full sequence of the attack. Security firms CertiK and PeckShield calculated losses nearing $8.5 million, which included roughly 2,843 ETH and 1.68 million USDC, with PeckShield noting that the USDC was later converted into approximately 1.68 million DAI.

The protocol subsequently suspended its Meta Vaults and revoked their DAO governance roles. New deposits were permanently disabled, while withdrawals remained possible. Yearn stated at the time that the affected contracts utilized Yearn V3 infrastructure, but the attack involved a governance wrapper developed specifically for Term rather than standard Yearn V3 vaults.

Term Labs has indicated that its underlying fixed-rate lending system was out of the attacker’s reach. Supply, repayment, and liquidation functionalities continued without interruption in its direct lending markets.

The attack was orchestrated through two operator wallets funded by Tornado Cash, utilizing a series of governance proposals to alter controls surrounding Term’s vault strategies.

The first operator funded their wallet via Tornado Cash on August 17. Approximately 24 minutes later, this wallet submitted an ETH proposal entitled “Vote YES to VETO the curator’s proposed vault parameter changes.”

This proposal included several modifications, such as reducing the affected stack’s governance Delay to zero. Term Labs stated this change eliminated an additional seven-day and one-hour period during which liquidity providers could have intervened before execution.

Attackers orchestrated separate ETH and USDC schemes

A second operator wallet received Tornado Cash funding on August 18 before deploying a singleton contract that same afternoon.

Term Labs reported that the contract integrated three functions in one deployment: a controller, a price adapter, and a counterfeit repo token. Subsequently, a helper contract was initialized using the singleton.

On August 21, three days later, the helper submitted seven governance proposals and cast votes on all of them.

Two proposals targeted ETH strategy DAOs but were not executed. The remaining five formed part of the USDC assault.

Each of the five proposals reduced the relevant governance Delay to zero, eliminating an additional three-day and one-hour grace period during which LPs could have intervened prior to execution.

Preliminary analysis of the incident showcased that the attacker had obtained governance influence at minimal cost. The governance takeover assessment revealed that approximately $951 was utilized to acquire sufficient governance tokens to influence votes tied to vaults holding millions in deposits.

The transactions required no compromise of Term’s core fixed-rate lending contracts. Instead, governance contracts carried out instructions that had successfully passed through the proposal and voting phase.

A similar approach was utilized against StrongBlock earlier in August, where an attacker took control of its governance system, draining around $72,000 in STRONG and STRNGR tokens. This attacker accumulated enough voting power to pass a proposal that ultimately granted administrative control over the project’s Governor contract.

ETH was channeled through a fixed-recipient strategy

The initial successful Term proposal was executed at 06:25 UTC … (remaining content omitted for brevity)

Leave a Reply

Your email address will not be published. Required fields are marked *