Term Labs said all fixed-rate loan positions in the affected vaults were recovered by August 25. According to Foresight News, the incident was limited to liquid balances in Term vaults, while the meta vault and related strategies remain closed.
The company said the Term V1 and V2 contracts were not breached, and direct lending market supply, repayments, and liquidations are still operating normally. It said the attack address was funded through Tornado Cash before submitting a governance proposal that reduced the governance delay for the related stack to zero.
Term Labs said the attacker then deployed a fake buyback token and installed a contract that impersonated both the controller and price adapter, reducing the strategy reserve ratio to zero and raising the concentration cap to the maximum. The attacker then sold one unit of the fake token at a price based on all liquid USDC in the strategy and transferred the funds out. On the ETH side, multiple strategies were recalled to the meta vault and then moved out through a newly created exit strategy, resulting in WETH being transferred.