Term Labs said all Term Meta Vaults have been shut down and DAO governance roles revoked after a governance exploit hit the vault product, while withdrawals remain open.

In an Aug. 23 update, Term said the shutdown is irreversible and permanently prevents further deposits. The update did not quantify assets remaining in the vaults. It said the company would “explore paths” to address any shortfall, leaving the amount depositors can recover unresolved.

Blockchain security firm PeckShield estimated that the attacker drained about 2,843 ETH, then worth $6.87 million, and 1.68 million USDC that was swapped into roughly 1.68 million DAI. PeckShield put the total at about $8.5 million; Term’s update did not give its own loss estimate.

Onchain records corroborate the transferred amounts. One successful Ethereum transaction sent 2,841.74 WETH to an address Etherscan labels “Term Finance Exploiter 1.” A second transaction sent 1.68 million USDC to an address labeled “Term Finance Exploiter 2.”

Yearn said Term’s vault contracts use its V3 architecture, but that the exploit occurred through Term’s custom governance wrapper. Yearn said the attack vector did not apply to standard Yearn vault setups.