Term Labs says it has now recovered every fixed-rate loan position linked to vaults affected by its August governance exploit, completing the final move at 14:52 UTC on Aug. 25.

According to the protocol, the incident was contained to liquid balances held inside Term vault strategies. It said its V1 and V2 contracts were not compromised and that its direct borrowing and lending markets continued operating during the attack and recovery process.

Recovery of affected positions

The company said the last remaining fixed-rate position tied to the impacted vaults was transferred on Aug. 25, closing out a key part of its response to the exploit. Term Labs had been moving those positions before they reached maturity in order to stop redemptions from occurring through compromised vault structures.

That recovery effort applied to fixed-rate loan positions held in the affected vaults, not to the broader protocol. Term Labs has maintained that the underlying fixed-rate lending system itself was not breached in the incident.

How the exploit was carried out

Term Labs said the attackers used malicious governance proposals to strip away execution delays and then drain liquid ETH and USDC from vault strategies. The exploit, as described by the protocol, relied on changing governance controls rather than breaking the core lending engine.

It also said the attackers introduced a counterfeit repo token that was priced against each strategy’s exact liquid USDC balance. That setup allegedly allowed the attacker to sweep the available funds held in those strategies.

What remained operational

Throughout the incident, Term Labs said its direct borrowing and lending markets stayed live. Supply, repayment, and liquidation functions in those fixed-rate lending markets continued to work, which the protocol cited as evidence that the lending system itself remained outside the attacker’s reach.

The protocol separately said its V1 and V2 contracts were not compromised. Its description of the breach draws a line between the affected vault strategies, where liquid balances were drained, and the main lending contracts, which it says continued to function normally.

Status of vaults and next steps

Meta Vaults and the affected strategies remain shut down. Term Labs has permanently disabled new deposits into those components, while keeping withdrawals available.

The protocol said it upgraded the affected contracts as part of its response. It is also working with law enforcement and cybersecurity firms to investigate the exploit and identify those responsible. For now, the confirmed status is that the fixed-rate positions have been recovered, while the impacted vault infrastructure remains offline.

Source: crypto.news