Yearn said the attack involved a custom Term governance wrapper and did not affect standard Yearn V3 vaults.