Three Attacks in Four Days: As the Market Rises, Hackers Get Busier
The focus now should not be on the narrative, but on who can mint, who can change parameters, and whether anyone is watching when proposals are posted on the chain.
Written by: Ma He, Foresight News
In less than a week, three crypto protocols have become targets for attackers.
On August 20, the payment public chain Keeta Network switched its mainnet to read-only mode, citing a security issue with a single component, and subsequently issued a 72-hour ultimatum for the return of funds; on August 22, the metaverse project The Sandbox suffered a cross-chain minting attack, with attackers minting a large amount of SAND on Base and BNB Chain, leading the project team to sever the bridge between the two chains, with security agencies estimating that approximately $670,000 was actually siphoned off; on August 23, the fixed-rate lending protocol Term Finance executed a governance proposal, resulting in approximately 2,843 ETH and 1.68 million USDC being transferred out of its treasury, with losses estimated at around $8.5 million.
The three incidents are unrelated, with different attack paths, but they all occurred within the same week.
Keeta: Mainnet Set to Read-Only Status
Keeta is a payment-oriented public chain. Its co-founder and CEO Ty (X account @schenkty) stated in an update on August 20 that the root cause of the security incident had been identified, with the issue limited to the affected component and not involving the anchoring system or external connection systems; the KTA deployed on Base was unaffected.
As a precaution, the mainnet was set to read-only status, and it will resume full operation after patch testing and additional safeguards are completed. The team also stated that they are evaluating how to fully compensate affected users and mentioned that strategic reserves could cover the lost funds if needed.
The official total amount of the theft has not yet been disclosed. Lookonchain monitored a new address that received approximately 9.3 million KTA (worth about $685,000 at the time) and about 2 billion GALA via a cross-chain bridge, which was then sold for approximately 1,902 ETH (about $3.64 million).
On August 19, the price of KTA plummeted from a high of $0.09 to a low of $0.05, a drop of about 37%, and has since rebounded to $0.077.
On August 22, Ty issued another statement, claiming that the investigation had made substantial progress and that evidence pointing to the attackers had been collected, including attack-related IPs, VPNs and VPSs used, user agents and technical environments during unauthorized requests, associated email addresses, and information about software and infrastructure service providers; the evidence has been preserved and submitted to the relevant parties. The statement demanded that the other party return all proceeds within 72 hours, which could be paid in KTA, ETH, or USDC to a Base address. If the full amount is returned, Keeta is willing to discuss a bug bounty and resolve the matter without pursuing legal liability; otherwise, they reserve the right to pursue legal accountability and fund recovery.
A complete technical report is promised to be released after the investigation and verification. As of August 24, the mainnet remains in read-only mode, and compensation details have not been released; it is also unknown whether the 72-hour window will be honored.
The lesson from this incident is not complicated: when application chains write "who can change permissions" as default loose or combinable bypass, stopping the chain often comes faster than a patch. Keeta chose to publicly disclose some off-chain clues and set a return deadline, which is rare in recent theft cases, but whether the money will flow back and whether the report can match the on-chain data will be the standard for evaluating this approach.
The Sandbox: Fake Coins Minted in Astronomical Numbers
On August 22, The Sandbox's cross-chain contract for SAND deployed on Base was attacked. The attackers seized the representative authority of LayerZero through approveAndCall, allowing them to continuously mint SAND without collateral on the Ethereum mainnet, affecting BNB Chain as well. The core LayerZero protocol layer was not breached.
The project team immediately severed the two-way bridge with Base and BNB Chain. The nominal issuance was reported to be about 14.9 billion, with a nominal exposure of several hundred million dollars, while the actual amount siphoned off and liquidated from Ethereum reserves was approximately 14.75 million SAND and about 80 ETH, totaling around $670,000. The SAND on Ethereum and Polygon, user wallets, and mainnet collateral were reported to be unaffected by the attack.
The SAND cross-chain uses LayerZero's OFT: the counterpart minting should correspond to the mainnet locking, and node representatives decide who can mint on the target chain. The vulnerability lay in the project team's contract's approveAndCall, which was used to change delegated permissions, allowing the forged cross-chain minting to take effect.
The official statement claimed that the vulnerability has been controlled, affecting less than 0.01% of the total supply, and reminded investors not to trade SAND on Base or BSC. Exchanges Upbit and Bithumb have suspended deposits and withdrawals.
As of the time of publication, the price of SAND has dropped from $0.05 to $0.045.
Term Finance: Proposal Vetoed After Six Days on Chain, Treasury Transferred According to Governance Process -----------------------------------
Term Finance is a fixed-rate lending protocol on Ethereum. On August 23, an Ethereum transaction executed a governance proposal that had been publicly posted on-chain for about six days. The voting page showed zero veto votes. The proposal included closing the original approximately 7-day trading cooldown (timelock), followed by transferring approximately 2,842 WETH from the ETH Meta Vault.
About 20 minutes later, a second transaction transferred approximately 1.68 million USDC from five USDC vaults and exchanged it for DAI. PeckShield estimated that the attacker took away approximately 2,843 ETH (worth about $6.9 million at the time) and 1.68 million USDC.
This incident was neither a smart contract reentrancy nor an oracle manipulation, but rather governance followed the protocol design through "submission---waiting---no veto---execution." External analysis indicated that the attacker gained nearly all voting rights in a USDC strategy vault with low circulation of governance tokens, as well as about 90% control over the ETH Meta Vault, and then wrote the transferred funds as an effective governance action.
As of now, Term Labs has stated that all Term Meta Vaults have been closed, the DAO governance role has been revoked, this closure is irreversible, and further deposits are permanently prohibited. Withdrawals are still allowed. The official statement claims that, based on the current investigation, the underlying Term protocol and its direct lending market have not been affected, and they are coordinating with external security teams for remediation and recovery work.
Governance attacks have become increasingly common in recent years. When voting power is concentrated and participation is low, such attacks are particularly effective.
In July of this year, the BonkDAO treasury was attacked by a malicious governance proposal, resulting in the theft of approximately $20 million worth of BONK tokens. The attacker's related address had purchased BONK through a CEX wallet before the proposal was initiated, then manipulated the vote, and finally "publicly" transferred the massive funds according to the governance process.
Keeta stopped the entire mainnet, with component permissions being closed first, followed by compensation and a 72-hour recovery. The Sandbox severed the bridge, with nominal minting reaching absurd levels, but the actual reserves that could be withdrawn were only about $600,000, and the controversy will revolve around how to compensate LP snapshots. Term's proposal was left hanging for six days, with zero veto votes, and the cooldown period could still be closed by the same proposal, with about $8.5 million being transferred according to the governance process.
The focus now should not be on the narrative, but on who can mint, who can change parameters, and whether anyone is watching when proposals are posted on the chain.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Proteomic clocks link accelerated aging to higher risk of death and disease

Peak Begins Transition of 1 Million Units... 3.3 Million Units to Use PEAQ Collateral and Burn

Kraken Withdrawal Delays, 23 Funding Services Downgraded

ETF Flows: How to Read Inflows and Outflows of Capital in Cryptocurrency Funds

Robinhood CEO Emphasizes Long-Term Bullish Outlook for Bitcoin and Security Investments

European Funds Leave the US: A Chance for France and Bitcoin?

ChatGPT, Claude, and Grok All Go Down: Why Is Everyone Suspecting Cloudflare?

Changpeng Zhao: Kyrgyzstan has made a leap to become a crypto hub in just one year, a process that usually takes up to 9 years

Cypherpunk Denies Issuance of ZEC Ticker Token

TokenPost Builds Korean Crypto Wiki: "Creating Information Needed for the Korean Crypto Industry"

VTB Prepares for Cryptocurrency Trading in Russia: Bank Awaits Regulatory Approvals

Reviews of awx pro: what the crypto exchange offers, how trading works, and where the risks arise

Middle East Tensions and U.S. Interest Rates Impact Global Markets

WEEX P2P now supports VES—Merchant Recruitment Now Open

WEEX P2P now supports NPR—Merchant Recruitment Now Open

WEEX P2P now supports GBP—Merchant Recruitment Now Open

Australia tightens crypto oversight with 45 removals

Orionx freezes withdrawals after 7 million dollars leaves custody

LayerZero Supports Multi-Chain for KRW1 Stablecoin

Changpeng Zhao Predicts Bitcoin Could Surpass Gold as a Reserve Asset

9706 Companies Included in the List of Taxpayers with High Compliance Levels

Bitcoin's Sideways Movement and Ethereum's Risk of Decline: Trader Predicts Movement of Two Cryptocurrencies

Amazon Cargo Plane Crashes on Landing in Miami, Leaving Several Injured

Wealthy Tax Avoidance: DeFi Lending Pools Take the Blame

How to Use the WEEX Telegram Mini App: No Download Needed, Plus Rewards and an iPhone 17 Pro Chance

Philippine Central Bank Plans to Suspend Registration of New Payment System Operators

What is Nockchain (NOCK)? The Mechanism of Proof of Work Calculation Tokens

Exclusive: Coin Staking Company Goes Bankrupt... Court Rules "No Separate Return, Must Follow Bankruptcy Procedures"

Rocket Punch and World Introduce Human Verification Badges to Business Ecosystem










