Three Attacks in Four Days: As the Market Rises, Hackers Get Busier
The focus now should not be on the narrative, but on who can mint, who can change parameters, and whether anyone is watching when proposals are posted on the chain.
Written by: Ma He, Foresight News
In less than a week, three crypto protocols have become targets for attackers.
On August 20, the payment public chain Keeta Network switched its mainnet to read-only mode, citing a security issue with a single component, and subsequently issued a 72-hour ultimatum for the return of funds; on August 22, the metaverse project The Sandbox suffered a cross-chain minting attack, with attackers minting a large amount of SAND on Base and BNB Chain, leading the project team to sever the bridge between the two chains, with security agencies estimating that approximately $670,000 was actually siphoned off; on August 23, the fixed-rate lending protocol Term Finance executed a governance proposal, resulting in approximately 2,843 ETH and 1.68 million USDC being transferred out of its treasury, with losses estimated at around $8.5 million.
The three incidents are unrelated, with different attack paths, but they all occurred within the same week.
Keeta: Mainnet Set to Read-Only Status
Keeta is a payment-oriented public chain. Its co-founder and CEO Ty (X account @schenkty) stated in an update on August 20 that the root cause of the security incident had been identified, with the issue limited to the affected component and not involving the anchoring system or external connection systems; the KTA deployed on Base was unaffected.
As a precaution, the mainnet was set to read-only status, and it will resume full operation after patch testing and additional safeguards are completed. The team also stated that they are evaluating how to fully compensate affected users and mentioned that strategic reserves could cover the lost funds if needed.
The official total amount of the theft has not yet been disclosed. Lookonchain monitored a new address that received approximately 9.3 million KTA (worth about $685,000 at the time) and about 2 billion GALA via a cross-chain bridge, which was then sold for approximately 1,902 ETH (about $3.64 million).
On August 19, the price of KTA plummeted from a high of $0.09 to a low of $0.05, a drop of about 37%, and has since rebounded to $0.077.
On August 22, Ty issued another statement, claiming that the investigation had made substantial progress and that evidence pointing to the attackers had been collected, including attack-related IPs, VPNs and VPSs used, user agents and technical environments during unauthorized requests, associated email addresses, and information about software and infrastructure service providers; the evidence has been preserved and submitted to the relevant parties. The statement demanded that the other party return all proceeds within 72 hours, which could be paid in KTA, ETH, or USDC to a Base address. If the full amount is returned, Keeta is willing to discuss a bug bounty and resolve the matter without pursuing legal liability; otherwise, they reserve the right to pursue legal accountability and fund recovery.
A complete technical report is promised to be released after the investigation and verification. As of August 24, the mainnet remains in read-only mode, and compensation details have not been released; it is also unknown whether the 72-hour window will be honored.
The lesson from this incident is not complicated: when application chains write "who can change permissions" as default loose or combinable bypass, stopping the chain often comes faster than a patch. Keeta chose to publicly disclose some off-chain clues and set a return deadline, which is rare in recent theft cases, but whether the money will flow back and whether the report can match the on-chain data will be the standard for evaluating this approach.
The Sandbox: Fake Coins Minted in Astronomical Numbers
On August 22, The Sandbox's cross-chain contract for SAND deployed on Base was attacked. The attackers seized the representative authority of LayerZero through approveAndCall, allowing them to continuously mint SAND without collateral on the Ethereum mainnet, affecting BNB Chain as well. The core LayerZero protocol layer was not breached.
The project team immediately severed the two-way bridge with Base and BNB Chain. The nominal issuance was reported to be about 14.9 billion, with a nominal exposure of several hundred million dollars, while the actual amount siphoned off and liquidated from Ethereum reserves was approximately 14.75 million SAND and about 80 ETH, totaling around $670,000. The SAND on Ethereum and Polygon, user wallets, and mainnet collateral were reported to be unaffected by the attack.
The SAND cross-chain uses LayerZero's OFT: the counterpart minting should correspond to the mainnet locking, and node representatives decide who can mint on the target chain. The vulnerability lay in the project team's contract's approveAndCall, which was used to change delegated permissions, allowing the forged cross-chain minting to take effect.
The official statement claimed that the vulnerability has been controlled, affecting less than 0.01% of the total supply, and reminded investors not to trade SAND on Base or BSC. Exchanges Upbit and Bithumb have suspended deposits and withdrawals.
As of the time of publication, the price of SAND has dropped from $0.05 to $0.045.
Term Finance: Proposal Vetoed After Six Days on Chain, Treasury Transferred According to Governance Process -----------------------------------
Term Finance is a fixed-rate lending protocol on Ethereum. On August 23, an Ethereum transaction executed a governance proposal that had been publicly posted on-chain for about six days. The voting page showed zero veto votes. The proposal included closing the original approximately 7-day trading cooldown (timelock), followed by transferring approximately 2,842 WETH from the ETH Meta Vault.
About 20 minutes later, a second transaction transferred approximately 1.68 million USDC from five USDC vaults and exchanged it for DAI. PeckShield estimated that the attacker took away approximately 2,843 ETH (worth about $6.9 million at the time) and 1.68 million USDC.
This incident was neither a smart contract reentrancy nor an oracle manipulation, but rather governance followed the protocol design through "submission---waiting---no veto---execution." External analysis indicated that the attacker gained nearly all voting rights in a USDC strategy vault with low circulation of governance tokens, as well as about 90% control over the ETH Meta Vault, and then wrote the transferred funds as an effective governance action.
As of now, Term Labs has stated that all Term Meta Vaults have been closed, the DAO governance role has been revoked, this closure is irreversible, and further deposits are permanently prohibited. Withdrawals are still allowed. The official statement claims that, based on the current investigation, the underlying Term protocol and its direct lending market have not been affected, and they are coordinating with external security teams for remediation and recovery work.
Governance attacks have become increasingly common in recent years. When voting power is concentrated and participation is low, such attacks are particularly effective.
In July of this year, the BonkDAO treasury was attacked by a malicious governance proposal, resulting in the theft of approximately $20 million worth of BONK tokens. The attacker's related address had purchased BONK through a CEX wallet before the proposal was initiated, then manipulated the vote, and finally "publicly" transferred the massive funds according to the governance process.
Keeta stopped the entire mainnet, with component permissions being closed first, followed by compensation and a 72-hour recovery. The Sandbox severed the bridge, with nominal minting reaching absurd levels, but the actual reserves that could be withdrawn were only about $600,000, and the controversy will revolve around how to compensate LP snapshots. Term's proposal was left hanging for six days, with zero veto votes, and the cooldown period could still be closed by the same proposal, with about $8.5 million being transferred according to the governance process.
The focus now should not be on the narrative, but on who can mint, who can change parameters, and whether anyone is watching when proposals are posted on the chain.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Bitcoin Surge Drives Corporate Accumulation of BTC and ETH

Arthur Hayes calls EUR/JPY prices crypto’s smoke alarm, but the Fed’s plumbing still shows no fire

Why GENIUS could leave digital dollars vulnerable to sudden blockchain network ‘bank runs’

Cracking 1.33 Trillion Daily Tokens: B.AI Powers the “AI Grid” with Full-Stack Infrastructure to Fuel the Agentic Era

Cybercrime, Child Gambling, and Underground Banking

Polygon Foundation Launches Cryptocurrency Donation Campaign for Nepal Disaster Relief Fund

Should You Invest in Cryptocurrency in 2026-2027: New Rules, Risks, and a Reasonable Portfolio Share

RWA Weekly: Singapore's Monetary Authority Proposes New Stablecoin Regulations; London Stock Exchange Plans to Launch Tokenized UK Stocks

Taiwan's Financial Supervisory Commission Plans Nine Regulations for Virtual Assets, Expected to Launch in Q1 2027

What Really Happened with Agents in Q2 Earnings Season of US and A-shares

Axis Robotics Open-Sources One of the Largest Franka Arm Simulation Datasets for Physical AI

El Niño Disturbs Commodities: Under the Calm of US Stocks, Markets Begin Trading Supply Risks

Why Do Robots Need Money? Understanding the Next Generation of Machine Economy Driven by DePIN

US, UK join forces to target crypto scam centers and investment fraud

The Rise of Blockchain Again, but This Time It's Clearly Different

What is arbitrage? The trading minute

Monad mainnet upgrade reduces data storage costs by 98%

Creators Speak | Is a New Round of Crypto Bull Market Coming?

USDT Recharge, Multi-Currency Exchange, Virtual Credit Cards: What Are the Criminal Boundaries of Web3 Payment Platforms?

Wyoming Adds Chainlink's Reserve Verification Feature to State-Issued Stablecoin

Betting on the Frontier: Why the Best Crypto Investments Arise in Bear Markets

Coldcard Bitcoin Theft Transferred to Ethereum Through 34 Exchanges

Uniswap Founder Says Tokenized SPY Trading Pairs Perform Well, Liquidity Expected to Grow

USD.AI Releases First Verification Report on GPU-Backed Loan Portfolio

The fintech industry debated its future, between evolution and regulation: "The ecosystem is here to stay"

Coinbase files to bring stock perpetuals to the US

OpenAI Releases GPT-6 Astra: The Closest AI Model Yet to AGI

Meta Invests $18 Billion in AI to Guess Your Age from Photos

Revolut hit by Washington crypto boom illusion, exposing massive two-tier banking system











