{
  "version": 1,
  "event_id": "evt_8e3439db94125c2a",
  "url": "https://xiyu.news/events/evt_8e3439db94125c2a/",
  "json": "https://xiyu.news/api/events/evt_8e3439db94125c2a.json",
  "type": "security_incident",
  "status": "resolved",
  "category": "crypto",
  "title": {
    "zh": "Term Finance 治理攻击与 Meta Vaults 关闭",
    "en": "Term Finance governance exploit and Meta Vaults shutdown"
  },
  "current_state": {
    "zh": "受影响的 Meta Vaults 已永久关闭。",
    "en": "The affected Meta Vaults are permanently closed."
  },
  "first_seen_at": "2026-08-24T08:00:00+08:00",
  "last_updated_at": "2026-08-26T08:00:00+08:00",
  "last_material_change_at": "2026-08-26T08:00:00+08:00",
  "confidence": 1.0,
  "updates_count": 2,
  "sources_count": 4,
  "entities": [
    "after",
    "app",
    "draining",
    "exploit",
    "governance",
    "hit",
    "lending",
    "loses",
    "meta",
    "millions",
    "permanently",
    "shuts",
    "term",
    "term-finance",
    "vaults"
  ],
  "identifiers": [],
  "topics": [
    "peckshield",
    "term-finance",
    "vaults"
  ],
  "updates": [
    {
      "update_id": "upd_266f9b9888ba8f99",
      "event_id": "evt_8e3439db94125c2a",
      "occurred_at": "2026-08-24T08:00:00+08:00",
      "published_at": "2026-08-24T08:00:00+08:00",
      "first_seen_at": "2026-08-24T08:00:00+08:00",
      "time_precision": "edition",
      "update_type": "initial",
      "material_change": true,
      "title_zh": "Term Finance 遭治理攻击，损失约 850 万美元。",
      "title_en": "Term Finance suffered a governance exploit with about $8.5M in losses.",
      "what_changed_zh": "Term Finance 遭治理攻击，损失约 850 万美元。",
      "what_changed_en": "Term Finance suffered a governance exploit with about $8.5M in losses.",
      "current_state_zh": "攻击和损失得到多来源确认。",
      "current_state_en": "The exploit and loss estimate were confirmed by multiple sources.",
      "detailed_summary_zh": "Term Finance（又称 Term Labs）是一个基于以太坊的非托管固定利率借贷协议，2026 年 8 月 23 日，攻击者控制其治理系统并盗走多个金库中的资金，估计损失约 850 万美元。尽管协议设有七天的提案延迟和流动性提供者否决机制，攻击仍然得逞。 这一事件表明，在 DeFi 中，治理控制（而不仅仅是代码漏洞）是关键的受攻击面。它还引发人们的担忧：当治理系统被攻破时，延迟和否决等保护措施是否足以保障用户资金安全。 报道称，本次攻击并未破坏协议代码，攻击者是通过获取治理控制权来盗取金库中的以太坊和稳定币。该协议原有的安全机制——包括金库提案的七天延迟和流动性提供者否决权——都未能阻止这次攻击。",
      "detailed_summary_en": "Term Finance (also known as Term Labs), a noncustodial fixed-rate lending protocol on Ethereum, lost an estimated $8.5 million on August 23, 2026, after an attacker took control of its governance system and drained multiple vaults. The exploit occurred despite the protocol's seven-day proposal delay and liquidity provider veto mechanism. This incident highlights that governance controls—not just code vulnerabilities—are a critical attack surface in DeFi. It raises concerns about whether delay and veto safeguards are sufficient to protect user funds when governance systems are compromised. Reports indicate the attack did not break the protocol's code; the attacker instead gained governance control and drained vaults holding Ethereum and stablecoins. The protocol's safeguards, including a seven-day delay on vault proposals and a liquidity provider veto, failed to stop the exploit.",
      "background_zh": "",
      "background_en": "",
      "community_discussion_zh": "",
      "community_discussion_en": "",
      "market_impact_zh": "",
      "market_impact_en": "",
      "importance_score": 8.0,
      "references": [],
      "confidence": 1.0,
      "story_ids": [
        "rss:www.theblock.co_rss.xml:ba61284223833910",
        "gdelt:article:20260824T154500Z::https://www.crowdfundinsider.com/2026/08/300909-ethereum-based-defi-lending-protocol-term-finance-suffers-setback-as-governance-exploit-drains-millions-from-vaults/",
        "rss:www.coindesk.com_arc_outboundfeeds_rss_:1b1f3dddd1f53072"
      ],
      "sources": [
        {
          "url": "https://www.theblock.co/news/defi/2026-08-23-defi-lending-protocol-term-finance-loses-an-estimated-8-5-million-to-governance-exploit-412543",
          "label": "The Block",
          "source_type": "rss",
          "official": false
        },
        {
          "url": "https://www.crowdfundinsider.com/2026/08/300909-ethereum-based-defi-lending-protocol-term-finance-suffers-setback-as-governance-exploit-drains-millions-from-vaults/",
          "label": "crowdfundinsider.com",
          "source_type": "gdelt",
          "official": false
        },
        {
          "url": "https://www.coindesk.com/markets/2026/08/24/ethereum-lending-app-term-finance-loses-usd8-5-million-after-attacker-buys-voting-power",
          "label": "CoinDesk",
          "source_type": "rss",
          "official": false
        }
      ]
    },
    {
      "update_id": "upd_f49d0e677cbab1ec",
      "event_id": "evt_8e3439db94125c2a",
      "occurred_at": "2026-08-26T08:00:00+08:00",
      "published_at": "2026-08-26T08:00:00+08:00",
      "first_seen_at": "2026-08-26T08:00:00+08:00",
      "time_precision": "edition",
      "update_type": "remediation",
      "material_change": true,
      "title_zh": "Term Finance 在攻击后永久关闭 Meta Vaults。",
      "title_en": "Term Finance permanently shut Meta Vaults after the exploit.",
      "what_changed_zh": "Term Finance 在攻击后永久关闭 Meta Vaults。",
      "what_changed_en": "Term Finance permanently shut Meta Vaults after the exploit.",
      "current_state_zh": "受影响的 Meta Vaults 已永久关闭。",
      "current_state_en": "The affected Meta Vaults are permanently closed.",
      "detailed_summary_zh": "Term Finance 在遭遇 PeckShield 估计为 850 万美元的攻击后，永久关闭了其 Meta Vaults 产品。该协议表示提款仍然开放，但其 8 月 23 日的更新并未量化剩余金库资产或缺口。\n\n这是一起值得关注的 DeFi 安全事件，因为基于治理的攻击迫使一个产品线永久关闭，使存款人面临尚未量化的资金缺口。它凸显了自定义治理包装器的风险，并可能促使用户重新评估类似的收益金库产品。\n\nPeckShield 追踪到约 2,843 枚 ETH 和 168 万枚 USDC 被抽走，攻击者还将 USDC 换成了 DAI。Yearn 确认该攻击针对的是 Term 的自定义治理包装器，而非标准 Yearn V3 金库；DeFiPrime 指出存在六天的提案开放空窗期，可能促成了此次接管。",
      "detailed_summary_en": "Term Finance has permanently shut down its Meta Vaults product following an exploit estimated at $8.5 million by PeckShield. The protocol says withdrawals remain open, but its Aug. 23 update did not quantify remaining vault assets or the shortfall.\n\nThis is a notable DeFi security incident because a governance-based attack forced a permanent product shutdown, leaving depositors with an unquantified shortfall. It highlights the risks of custom governance wrappers and may prompt users to reassess similar vault products.\n\nPeckShield tracked roughly 2,843 ETH and 1.68 million USDC drained, with the attacker swapping USDC for DAI. Yearn confirmed that the exploit targeted Term's custom governance wrapper, not standard Yearn V3 vaults, and DeFiPrime noted a six-day open proposal gap that likely enabled the takeover.",
      "background_zh": "",
      "background_en": "",
      "community_discussion_zh": "",
      "community_discussion_en": "",
      "market_impact_zh": "",
      "market_impact_en": "",
      "importance_score": 7.5,
      "references": [],
      "confidence": 1.0,
      "story_ids": [
        "rss:thedefiant.io_api_feed:dcd5bb541c6b961f"
      ],
      "sources": [
        {
          "url": "https://thedefiant.io/news/hacks/term-finance-permanently-shuts-meta-vaults-after-exploit-peckshield-estimated-at-8-5-million",
          "label": "The Defiant",
          "source_type": "rss",
          "official": false
        }
      ]
    }
  ]
}
