Term Labs recovers fixed-rate positions after $8.5M governance attack

Paxful
fiverr



Term Labs has recovered all fixed-rate loan positions held in vaults affected by its August governance exploit, with the final position moved on Aug. 25 as Meta Vaults and affected strategies remain shut down.

Summary

  • Term Labs recovered all affected fixed-rate loan positions by Aug. 25, while its Meta Vaults and affected strategies remain shut down.
  • Attackers used malicious governance proposals to remove execution delays before draining liquid ETH and USDC from vault strategies.
  • A counterfeit repo token was priced against each strategy’s exact liquid USDC balance, allowing the attacker to sweep the available funds.
  • Term Labs said its V1 and V2 contracts were not compromised, and its direct borrowing and lending markets remained operational.

Term Labs said in its latest incident report that the last fixed-rate position was recovered at 14:52 UTC on Aug. 25, while its investigation found that the attack was confined to liquid balances held inside Term vaults. 

okex

The protocol said its V1 and V2 contracts were not compromised and its direct borrowing and lending markets continued operating throughout the incident.

Term Labs says lending contracts escaped the vault exploit

The new technical account gives a more detailed picture of the Aug. 23 attack, which security firms previously estimated had drained roughly $8.5 million from Term Finance vaults.

Term Labs had initially disclosed a governance exploit affecting vaults without providing the full attack sequence. Security firms CertiK and PeckShield estimated losses near $8.5 million, including roughly 2,843 ETH and 1.68 million USDC. PeckShield said the USDC was subsequently exchanged for approximately 1.68 million DAI.

The protocol later shut down its Meta Vaults and revoked their DAO governance roles. New deposits were permanently disabled while withdrawals remained available. Yearn said at the time that the affected contracts used Yearn V3 infrastructure but that the attack involved a governance wrapper developed for Term rather than standard Yearn V3 vaults.

Term Labs now says its underlying fixed-rate lending system remained outside the attacker’s reach. Supply, repayment and liquidation functions continued operating without interruption in its direct lending markets.

The attack instead developed through two operator wallets funded through Tornado Cash and a series of governance proposals that altered controls around Term’s vault strategies.

The first operator received funds through Tornado Cash on Aug. 17. Around 24 minutes later, the wallet submitted an ETH proposal titled “Vote YES to VETO the curator’s proposed vault parameter changes.”

Among the changes included in the proposal was a reduction of the affected stack’s governance Delay to zero. Term Labs said the change removed an additional seven-day and one-hour period during which liquidity providers could have stopped the proposal before execution.

Attackers prepared separate ETH and USDC campaigns

A second operator wallet received Tornado Cash funding on Aug. 18 before deploying a singleton contract later that afternoon.

According to Term Labs, the contract combined three functions in one deployment: a controller, a price adapter and a counterfeit repo token. A helper contract was then initialized using the singleton.

Three days later, on Aug. 21, the helper submitted seven governance proposals and cast the only votes on them.

Two proposals targeted ETH strategy DAOs but were never executed. The other five became part of the USDC attack.

Each of the five proposals reduced the relevant governance Delay to zero, removing an additional three-day and one-hour period in which LPs could otherwise have intervened before execution.

Earlier analysis of the incident found that the attacker had obtained governance influence at very little cost. A review of the governance takeover found that roughly $951 was spent acquiring enough governance tokens to control votes tied to vaults holding millions of dollars in deposits.

The transactions did not require the attacker to compromise Term’s core fixed-rate lending contracts. Governance contracts instead executed instructions that had passed through the proposal and voting process.

A similar attack path was used against StrongBlock earlier in August, when an attacker took over its governance system and drained around $72,000 in STRONG and STRNGR tokens. The attacker gained enough voting power to pass a proposal that ultimately provided administrative control over the project’s Governor contract.

ETH was routed through a fixed-recipient strategy

The first successful Term proposal executed at 06:25 UTC on Aug. 23.

Four active ETH strategies, Shorewoods, August Digital, Parity Prime and Parity Core, were recalled into the Meta Vault using update_debt() and directed into a newly added strategy named frWETH-EXIT.

Term Labs said the strategy had been named “Fixed Recipient WETH Exit Strategy.”

Once the WETH entered the new strategy, frWETH-EXIT forwarded the entire amount to the first operator during the same call.

The transaction left the Meta Vault holding 2,841.74 shares in a strategy containing none of the WETH that had been transferred into it.

That figure closely corresponds with the roughly 2,843 ETH that PeckShield traced from Term Finance during its initial analysis of the incident.

Twenty-two minutes after the ETH transaction, the second campaign executed against five USDC strategy DAOs.

Parity Prime, Parity Core, Parity HY, Parity HY v2 and RockawayX Tori were targeted at 06:47 UTC.

Term Labs said each proposal caused its DAO to sell one unit of a counterfeit repo token into the associated strategy at a value equal to the strategy’s entire liquid USDC balance.

The attacker was able to execute the sale after the proposals installed a contract called fmTERT.

Term Labs said fmTERT impersonated both the controller used to determine whether a token was a legitimate Term instrument and the price adapter responsible for determining how much the instrument was worth.

The proposals set each strategy’s reserve ratio to zero and increased its concentration limit to the maximum permitted value, preventing those controls from limiting the fake token transaction.

The counterfeit token was then priced using a dynamic redemptionValue() function.

At execution, the function returned the precise amount of liquid USDC available in the strategy, allowing a single unit of the fake repo token to be sold for virtually the strategy’s entire available balance.

After the sale, the proposals approved the USDC proceeds and swept them from each DAO into the second operator’s wallet.

Fixed-rate positions were moved before they could redeem

Term Labs said the fixed-rate loans held by affected vaults could not be reached through the attack itself.

A separate problem would have emerged when those positions matured because their proceeds were scheduled to redeem into the same vaults that had been captured during the governance attack.

The protocol responded by upgrading affected contracts and moving the fixed-rate positions before maturity.

All affected fixed-rate loan positions have since been recovered, with the final position moved at 14:52 UTC on Aug. 25.

The incident illustrates the role that execution delays can play in governance security. Days before the Term Finance attack, Binance said it had stopped a malicious DAO proposal that threatened roughly $1.2 million belonging to an unnamed project. Less than 48 hours remained before that proposal could execute when the exchange contacted the project, which ultimately rejected it without a reported loss.

In Term’s case, the malicious proposals themselves removed additional delay periods before the assets were taken. The ETH proposal eliminated a seven-day and one-hour window, while the five USDC proposals removed three-day and one-hour periods from their respective governance stacks.

Term Labs said its Meta Vaults and affected strategies remain shut down, while shutdown work involving the remaining low-activity vaults is still underway.

The protocol is working with law enforcement agencies and cybersecurity firms to identify those responsible for the attack and said it has provided relevant information to assist the investigations.



Source link

Ledger

Be the first to comment

Leave a Reply

Your email address will not be published.


*