Overview
- Security firms and on‑chain monitors say an attacker acquired majority governance control and used legitimate votes to withdraw about 2,843 ETH plus roughly 1.6–1.68 million USDC/DAI to a single wallet.
- On August 23 the exploit began after the attacker seeded their address with 2 ETH from Tornado Cash and then bought sparse governance tokens to pass malicious proposals that moved vault funds.
- Term Labs confirmed the governance breach, permanently closed Meta Vault deposits, revoked DAO governance roles, left withdrawals open, and hired outside security firms to investigate.
- Yearn clarified the vaults ran on Yearn V3 but said the issue involved a Term‑built custom governance wrapper rather than core Yearn code.
- The estimated $8.5 million loss represents a large share of Meta Vault TVL, recovery is unresolved, and the case highlights that token distribution, timelocks, multisig settings and governance wrappers can be as risky as smart‑contract bugs.