Crypto Prices

Term Labs Successfully Reclaims Assets Following August Governance Breach of $8.5 Million

19 hours ago
2 mins read
5 views

Overview of the Incident

Term Labs has successfully retrieved all fixed-rate loan assets affected by a governance exploit that occurred in August, with the last of the positions shifted on August 25. Following this incident, both the Meta Vaults and the impacted strategies remain inoperative. The company provided an update detailing that the final fixed-rate position was reestablished at 14:52 UTC on August 25.

Details of the Exploit

An investigation determined that the breach was limited to liquid assets within Term vaults, while their V1 and V2 contracts were found to be intact, enabling their direct lending and borrowing markets to function uninterrupted during the incident.

Security firms previously estimated damages from the exploit at around $8.5 million, which included approximately 2,843 ETH and 1.68 million USDC. The latter amount was reportedly exchanged for about 1.68 million DAI. Initially, Term Labs had only disclosed the exploit’s occurrence without fully elaborating on the sequence of the attack.

Response and Recovery

Following the incident, Term Labs shut down its Meta Vaults, revoking the governance powers of their decentralized autonomous organization (DAO). While new deposits were permanently halted, users retained the ability to withdraw their assets.

According to Term Labs, their system for fixed-rate lending was unaffected by the exploit, enabling the supply, repayment, and liquidation processes to remain operational in their direct lending markets.

Mechanics of the Attack

The breach occurred through the manipulation of two operator wallets that were funded using Tornado Cash, in conjunction with several governance proposals that altered the controls surrounding Term’s vault strategies.

The initial operator wallet, which received funds via Tornado Cash on August 17, promptly submitted a proposal on the same day titled “Vote YES to VETO the curator’s proposed vault parameter changes“. This proposal included significant adjustments, such as lowering the governance delay to zero, ultimately removing a one-hour and seven-day period that would have allowed liquidity providers to intervene.

A second wallet, which was funded on August 18, later deployed a contract consolidating several functions, facilitating the governance takeover.

By August 23, the attackers had gained governance control with minimal expenditure, spending roughly $951 to acquire enough governance tokens for voting rights over vaults holding significant funds. The first proposal successfully executed at 06:25 UTC led to the removal of funds from several ETH strategies directed to a new strategy called frWETH-EXIT.

Consequences and Future Actions

After the ETH transfer, an attack orchestrated against five USDC strategy DAOs was initiated, where proposals executed by the malicious actors caused the sale of units of a counterfeit repo token that effectively drained the strategies’ entire liquid USDC reserves. Following these transactions, the proposals allowed proceeds from the sales to be swept into the second wallet controlled by the attacker.

Despite the successful execution of the attacks on liquidity, Term Labs assured stakeholders that the fixed-rate loans within impacted vaults were secured, as they could not be accessed directly by the attackers. However, future liquidity redemption could have posed an issue as the proceeds were set to redeploy into the compromised vaults. Consequently, Term Labs upgraded the relevant contracts and moved the fixed-rate positions prior to their maturity. By August 25, all impacted positions were successfully retrieved.

Lessons Learned

This incident highlights the critical importance of governance execution delays in protecting against similar security breaches. Just days before the Term Finance exploit, Binance averted a threatening DAO proposal that jeopardized approximately $1.2 million from another project. In Term’s scenario, the governance proposals themselves expeditiously removed safety delays against asset acquisition, allowing the attack to unfold quickly.

The Meta Vaults and associated strategies remain non-operational as Term Labs continues work to address remaining low-activity vaults. The protocol is collaborating with law enforcement and cybersecurity experts to bring those responsible for this exploit to justice, having already shared pertinent information to aid in the investigation.

Popular