The attacker didn’t need to find a smart contract vulnerability to drain millions from Term Finance. A small stake in the vault was enough to propose the changes they needed and wait for no one to say “no.”
The weak point wasn’t the code. It was the protocol’s governance.
The attacker swapped 0.5 ETH for a stake in the ETH Meta Vault, received governance tokens, and submitted a proposal containing 17 actions.
Those actions included removing the protective delay, pulling WETH back from four strategies, and adding an attacker-controlled exit strategy.
The proposal remained open for around six days. No one vetoed it. Once the window closed, the protocol executed the actions and transferred 2,841.74 WETH to the attacker.
A similar setup targeted five USDC vaults. Separate proposals changed key roles and risk controls, allowing another 1.68M USDC to be withdrawn.
➤ WETH was converted to ETH;
➤ USDC was swapped for DAI via KyberSwap and Maker PSM;
➤ the ETH and DAI were consolidated into a single wallet.
The attacker didn’t need to break the code. They used Term Finance’s own rules: propose the right changes, wait for no one to stop them, then let the protocol execute the rest.
Website | Telegram | BitOK bot



