What happened?
DeFi lending protocol Term Finance lost an estimated $8.5 million in an attack on its so-called Meta Vaults, according to Cointelegraph and The Block. DeFi (decentralized finance) refers to financial applications that run on a blockchain without a central intermediary. A vault, in this context, is a smart contract into which users deposit funds in exchange for yield.
According to Cointelegraph, the attack drained almost all of the ether (ETH) deposits from these vaults. Term Finance subsequently closed its Meta Vaults permanently.
How were the safeguards bypassed?
This is the crux of the story, and also the part that is not yet fully clear. The Block reports that proposals for Term Finance vaults were subject to a seven-day delay and that liquidity providers could veto them. These control mechanisms were meant to do exactly this: catch a malicious change to protocol governance before it takes effect.
But according to The Block, these safeguards clearly failed to stop the attack. Exactly how they were bypassed is not yet unambiguously clear from the available sources. Whether it was a bug in the code, a governance takeover, or a combination of factors remains unconfirmed at this point.
How much exactly was lost?
Both key outlets, Cointelegraph and The Block, use the figure of roughly $8.5 million and describe it as an estimate. Cointelegraph characterizes the loss as nearly all of the ETH deposits in the affected vaults. We do not yet have the exact final amount, nor its definitive on-chain verification, confirmed from the protocol's primary source.
Broader context: this was not the only security incident
The Term Finance case fits into a busier stretch for crypto infrastructure security. These are not related events, however, just a coincidence in timing that is worth keeping separate:
| Incident | What it concerns | Source |
|---|---|---|
| Term Finance | Vault governance exploit, ~$8.5M | Cointelegraph, The Block |
| The Sandbox | Bridging halted on Base and BNB Chain after an exploit, impact under 0.01% of SAND supply | CoinDesk |
| Coldcard (Coinkite) | New firmware requiring physical entropy during seed generation after a vulnerability | CryptoSlate |
According to CoinDesk, the web3 gaming network The Sandbox paused bridging on the Base and BNB Chain networks to isolate the tokens, and warned users not to trade the SAND token on Base and BNB. The Sandbox reports an impact of under 0.01% of supply.
According to CryptoSlate, hardware wallet maker Coldcard, the company Coinkite, released new standard firmware on August 20 that requires adding physical randomness during seed generation (at least 65 key presses at irregular intervals). Owners who rely on a seed created with the affected firmware must, according to CryptoSlate, generate a new seed and move their funds unless their wallet meets the exemption for the dice-based procedure.
These three cases have no technical connection to one another. All they share is that they illustrate different layers of risk: smart contracts and governance (Term Finance), cross-chain bridges (The Sandbox), and key generation on hardware (Coldcard).
What to watch for with this type of event
Not as advice on what to do with your money, just as a tool for reading similar situations: with governance exploits, the key questions are whether the team publishes a post mortem with a precise account of how the time locks and the liquidity provider veto were bypassed, what the definitive quantified loss verified on-chain turns out to be, and whether there is a compensation plan. Until this information is confirmed, these remain estimates.
charliedesk will keep this case on its list to verify and, if Term Finance issues an official post mortem, will compare what gets confirmed against today's state of knowledge.

