ChainThink reports that, on September 3, according to an official announcement from Term Labs, all fixed-rate loan positions in affected vaults have been restored, with the final restoration completed on August 25 at 14:52 UTC.
The impact of the event is limited only to the liquid assets held in Term Vault; Meta Vault and related strategies remain disabled.
The team has not detected any attacks on the Term V1 and V2 contracts during the incident; the direct lending market was unaffected, and deposit, repayment, and liquidation functions continued to operate normally.
According to technical analysis, the attacker funded their operational wallet through Tornado Cash and exploited a governance proposal to set the governance delay for multiple strategies to zero, bypassing the LP additional blocking window.
Subsequently, deploy a fake controller, price adapter, and counterfeit Repo tokens to manipulate strategy parameters and pricing mechanisms, draining liquidity from the ETH and USDC strategies.
Term Labs is collaborating with law enforcement agencies and cybersecurity firms to investigate the attackers and has provided relevant information to assist the investigation. The affected Meta Vaults and strategies have been shut down, and remaining low-activity Vaults are currently being addressed.


