The cryptocurrency sector has weathered a wave of security breaches within just days, with three separate incidents striking at the heart of permission management and governance oversight. On August 20, the Keeta Network mainnet was forced into read-only mode; on August 22, The Sandbox suffered a cross-chain counterfeit token attack; and on August 23, Term Finance's treasury funds were drained via a malicious governance proposal.
Keeta Network, a payment-focused public chain, had its co-founder and CEO Ty (X account @schenkty) reveal on August 20 that the root cause of the security event had been identified. The issue was confined to a single component, leaving the anchoring system and external connections unaffected, while the KTA token deployed on Base remained safe. To prevent further risk, the mainnet was urgently switched to read-only mode, with operations set to resume only after patch testing is completed and additional safeguards are added. The team has promised to evaluate a full compensation plan and noted that strategic reserves are sufficient to cover potential losses.
Although the official audited amount of stolen funds has not been disclosed, on-chain monitoring shows that a new address received approximately 9.3 million KTA (worth roughly $685,000 at the time) and 2 billion GALA via a cross-chain bridge, subsequently converting these assets into about 1,902 ETH (valued at approximately $3.64 million). Market reaction was severe, with KTA's price plunging from a high of $0.09 on August 19 to a low of $0.05, a decline of 37%. While it has since recovered to $0.077, investor confidence has clearly taken a hit.
On August 22, Ty issued another statement indicating substantial progress in the investigation, having gathered evidence including attack-related IPs, VPN and VPS usage, user agents, technical environments, associated emails, and infrastructure service providers, which has been submitted to relevant authorities. An ultimatum was issued, demanding that attackers return all stolen assets in KTA, ETH, or USDC to a designated Base address within 72 hours. If the full amount is returned, discussions on bug bounties and immunity from legal action may be possible; otherwise, legal recourse will be pursued. As of August 24, the mainnet remains in read-only mode, compensation details are pending, and it is unclear whether the 72-hour window has been honored.
This case demonstrates that when an application chain's permission settings are lax by default or can be bypassed through composability, halting the chain often proves faster than patching. While publicly disclosing off-chain clues and setting a return deadline is unusual, its effectiveness ultimately hinges on matching fund returns with on-chain data.
The Sandbox attack, meanwhile, targeted flaws in its cross-chain minting mechanism. On August 22, the SAND cross-chain contract deployed on Base was compromised. The attacker exploited the approveAndCall function to seize LayerZero's representative permissions, continuously minting SAND without collateralizing the Ethereum mainnet, with spillover effects on BNB Chain. Notably, the LayerZero protocol core layer was not breached; the vulnerability stemmed from the project's contract mismanagement of delegation permissions. The project team quickly severed bidirectional bridges to Base and BNB Chain to contain the damage.
In nominal terms, the attacker minted approximately 14.9 billion SAND, with spot nominal exposure reaching hundreds of millions of dollars. However, on-chain analysis reveals that the assets actually drained from Ethereum reserves and liquidated were only about 14.75 million SAND and roughly 80 ETH, equivalent to around $670,000. SAND on Ethereum and Polygon, user wallets, and mainnet collateral were all unaffected. SAND's cross-chain mechanism uses LayerZero's OFT standard, where counterparty minting should correspond to mainnet locking, and node representatives determine who can mint on the target chain. But the abuse of approveAndCall enabled forged cross-chain minting to take effect.
The official statement says the vulnerability has been contained, affecting less than 0.01% of total supply, and warns investors to avoid trading SAND on Base and BSC. Exchanges Upbit and Bithumb have suspended deposit and withdrawal services. As of press time, SAND's price has slipped from $0.05 to $0.045. Despite the staggering nominal minting figure, the actual reserves drained were only about $670,000, and the debate will now shift to how LP snapshots compensate affected liquidity providers.
The Term Finance case exposes a fatal weakness in governance mechanisms. As a fixed-rate lending protocol on Ethereum, Term Finance executed a governance proposal on August 23 that had been publicly visible on-chain for approximately six days, receiving zero veto votes on the voting page. The proposal included closing the original 7-day trading cooldown (timelock), followed by the transfer of approximately 2,842 WETH from the ETH MetaVault. About 20 minutes later, a second transaction moved roughly 1.68 million USDC from five USDC vaults, converting it into DAI. PeckShield statistics show the attacker extracted approximately 2,843 ETH (worth about $6.9 million at the time) and 1.68 million USDC, totaling losses of around $8.5 million.
This attack was not a smart contract reentrancy or oracle manipulation; it strictly followed the "submit-wait-no-veto-execute" governance process. External analysis indicates the attacker, amid thin circulating governance tokens, acquired near-complete voting power over some USDC strategy vaults and roughly 90% control over the ETH MetaVault, thereby packaging the fund transfers as legitimate governance actions. TermLabs stated that all Term MetaVaults have been closed, DAO governance roles revoked, and this closure is irreversible, with further deposits permanently banned—though withdrawals remain available. The official statement says the underlying Term protocol and its direct lending markets are unaffected, with external security teams coordinating remediation.
This incident mirrors the July attack on the BonkDAO treasury, where approximately $20 million in BONK tokens were stolen via a malicious governance proposal. In both cases, attackers purchased tokens through CEX wallets to manipulate voting and "transparently" moved massive funds through the governance process, highlighting the risks of concentrated voting power and low participation.
While the three incidents follow different attack paths, their commonalities are striking: Keeta halted its entire mainnet, with component permissions shut down first, followed by compensation and a 72-hour recovery demand; The Sandbox severed bridges, with absurd on-paper minting but only about $600,000 in actual drainable reserves, leaving the controversy over LP snapshot compensation; Term Finance's proposal sat for six days with zero vetoes, the cooldown period was closed by the same proposal, and approximately $8.5 million was transferred out through governance procedures. These cases collectively point to a core issue: in the on-chain world, narrative hype matters far less than the rigor of permissions and governance. Who can mint, who can change parameters, and whether proposals receive adequate attention while posted on-chain are the keys to asset security. As hacker tactics grow increasingly professional—from permission vulnerabilities to governance manipulation—attackers are exploiting blind spots in protocol design with precision. Moving forward, project teams must strengthen real-time monitoring of minting rights, parameter modification permissions, and governance proposals to avoid repeating these mistakes. This is not merely a technical challenge but a comprehensive test of community governance and security awareness.
Comments