Term Labs recovered all fixed-rate loan positions held in vaults affected by its Aug. 23 governance exploit, completing the final recovery at 14:52 UTC on Aug. 25. The company said the attack was limited to liquid balances in Term Vault strategies, while its V1 and V2 contracts and direct borrowing and lending markets remained operational. Attackers used two operator wallets funded through Tornado Cash, submitted governance proposals that reduced execution delays to zero, and removed intervention windows that could have allowed liquidity providers to block the changes. The first campaign redirected WETH from four ETH strategies through a newly added fixed-recipient strategy, while the second drained five USDC strategies by selling counterfeit repo tokens whose spoofed pricing mechanism valued each token at the strategy’s full liquid balance. Security firms traced roughly 2,843 ETH and 1.68 million USDC, later swapped into DAI, to a single address, putting the loss at about $8.5 million. Term Labs shut down its Meta Vaults and affected strategies, disabled new deposits, kept withdrawals available and said it was cooperating with law enforcement and cybersecurity firms.