Login
Sign Up
Woofun AI reports that a concentrated wave of security breaches targeted three distinct blockchain protocols within a four-day window, fundamentally challenging the integrity of on-chain governance and infrastructure. Written by Mah for Foresight News, the analysis highlights that Keeta Network, The Sandbox, and Term Finance were compromised on August 20, August 22, and August 23 respectively. These incidents, while unrelated in their technical vectors, collectively demonstrate a systemic vulnerability in how permissions are managed and verified across decentralized ecosystems.
The rapid succession of attacks underscores a critical shift in threat modeling, where attackers exploit not just code bugs, but also procedural gaps in governance and cross-chain communication. This pattern of exploitation suggests that current security paradigms are insufficient against coordinated, multi-vector assaults that target both technical and administrative layers of protocol operations.
Keeta Network, a payment-focused public chain, initiated its response on August 20 by switching its mainnet to read-only mode, citing a security issue confined to a single component. Ty, the co-founder and CEO with X account @schenkty, clarified that the anchoring system and external connection systems remained uncompromised, and the KTA token deployed on Base was not directly impacted by the core vulnerability. The decision to halt operations was a precautionary measure to allow for patch testing and the implementation of additional safeguards before full functionality could resume. The team emphasized that strategic reserves were available to cover potential losses, aiming to fully compensate affected users.
However, the official team has yet to release an audited figure for the total amount stolen, leaving the financial scope of the breach partially obscured. The technical scope of the incident was narrowly defined, but the operational impact was immediate and severe, forcing a complete shutdown of network activities.
Lookonchain data reveals that a new address received approximately 9.3 million KTA tokens, valued at around $685,000 at the time, along with about 2 billion GALA tokens via a bridge exploit. These assets were subsequently sold, yielding roughly 1,902 ETH, which equated to approximately $3.64 million. The market reaction was swift and volatile; on August 19, the price of KTA plummeted from a high of $0.09 to a low of $0.05, representing a drop of around 37%. Despite this sharp decline, the token has since recovered to $0.
077, indicating some resilience in market sentiment. The discrepancy between the initial token value and the final realized loss in ETH highlights the complexity of valuing cross-chain exploits. The financial impact extends beyond the immediate theft, affecting user confidence and the broader stability of the Keeta ecosystem. The ability of attackers to liquidate such large volumes of tokens without triggering immediate circuit breakers points to liquidity vulnerabilities in the secondary markets.
On August 22, Ty announced significant progress in the investigation, revealing that evidence pointing to the attackers had been collected. This evidence includes IP addresses related to the attack, VPNs and VPS used, user agents and technical environments during unauthorized requests, associated email addresses, as well as information from software and infrastructure providers. The statement demanded that the attackers return all stolen funds within 72 hours, either in the form of KTA, ETH, or USDC, to a specific Base address.
If the funds were returned in full, Keeta expressed willingness to discuss a bug bounty and resolve the matter without legal action; otherwise, legal recourse and pursuit of the funds would be pursued. A complete technical report was promised to be released after further investigation. As of August 24, the mainnet remains in read-only mode, compensation details have not been announced, and it is unclear whether the 72-hour deadline will be met. This approach of disclosing off-chain clues and setting a deadline for returns is uncommon in recent theft cases, but its effectiveness remains to be seen.
The Sandbox suffered a cross-chain minting attack on August 22, where attackers exploited the approveAndCall function to seize control rights of LayerZero. This allowed them to continuously mint SAND without any collateral on Ethereum Mainnet, with effects spreading to BNB Chain as well. The core layer of the LayerZero protocol was not compromised, but the project team immediately severed the bidirectional bridges connecting to Base and BNB Chain to contain the damage. The nominal secondary offering amounted to around 14.9 billion tokens, creating a spot exposure of several hundred million dollars.
However, the actual financial loss was significantly lower than the theoretical maximum. The attack vector relied on altering authorization settings within the project team's own approveAndCall function, enabling fraudulent cross-chain minting. This incident highlights the risks associated with complex cross-chain mechanisms and the potential for single points of failure in authorization logic.
Woofun AI data shows that on-chain analysis revealed approximately 14.75 million SAND tokens and around 80 ETH were actually withdrawn from Ethereum reserves and converted into cash, totaling about $670,000. The SAND tokens on Ethereum and Polygon, as well as user wallets and mainnet collateral, were said to remain unaffected. SAND's cross-chain functionality relies on LayerZero's OFT mechanism, where minting on one side should correspond to locking assets on the mainnet, with node representatives deciding who can mint on the target chain.
The vulnerability lay in the project team's own approveAndCall function, which was exploited to alter authorization settings. The official team claimed that the vulnerability had been contained, affecting less than 0.01% of the total supply, and advised investors not to trade SAND on Base or BSC. The discrepancy between the minted amount and the actual loss underscores the importance of reserve management and the limitations of cross-chain minting mechanisms in preventing arbitrage and theft.
Exchanges Upbit and Bithumb have paused trading of SAND in response to the attack, reflecting the market's caution and the need for clarity on the extent of the compromise. As of this report, the price of SAND dropped from $0.05 to $0.045, indicating a negative market reaction despite the containment efforts. The pause in trading serves as a protective measure for investors, preventing further volatility and potential losses due to misinformation or panic selling. The incident also raises questions about the responsibility of exchanges in monitoring and responding to security breaches in the tokens they list. The rapid response by these major exchanges highlights the interconnectedness of the crypto ecosystem and the ripple effects of security incidents on market liquidity and confidence.
Term Finance, a fixed-interest lending protocol built on Ethereum, experienced a governance exploit on August 23. A transaction executed a governance proposal that had been listed on-chain for about six days, with the voting page showing zero votes against the proposal. The proposal called for ending the existing 7-day transaction cooldown period (timelock) and then transferring around 2,842 WETH from the ETH Meta Vault. About 20 minutes later, a second transaction transferred around 1.
68 million USDC from five USDC vaults and converted it into DAI. This sequence of events demonstrates how attackers can manipulate governance processes to bypass security measures like timelocks. The execution of the proposal was technically valid, but the intent was malicious, highlighting the limitations of on-chain governance in preventing insider threats or coordinated attacks. The speed of the execution, with only a 20-minute gap between the two transactions, suggests a high level of coordination and preparation by the attackers.
PeckShield estimated that attackers stole around 2,843 ETH, worth approximately $6.9 million at the time, and 1.68 million USDC. This incident was not caused by smart contract reentrancy or manipulated oracles, but rather by the governance process following its design—submission, waiting, no rejection, and execution. External analysts suggested that, given the limited circulation of governance tokens, the attackers gained nearly all voting rights in some USDC strategy vaults and around 90% control over the ETH Meta Vault, then framed the fund transfer as a legitimate governance action.
So far, Term Labs has stated that all Term Meta Vaults have been closed, the DAO governance role has been revoked, and this closure is irreversible with permanent bans on further deposits. Withdrawals are still allowed. The official team said that, based on current investigations, the underlying Term protocol and its direct lending market remain unaffected, and they are working with external security teams to carry out remediation and recovery efforts. This case illustrates the vulnerability of governance systems to concentration of voting power and the potential for malicious actors to exploit procedural gaps.
Governance attacks have become increasingly common in recent years, especially when voting rights are concentrated and voter participation is low. In July of this year, BonkDAO's vault was targeted by a malicious governance proposal, resulting in the theft of BONK tokens worth around $20 million. The attacker's associated addresses purchased BONK through CEX wallets before the proposal was submitted, then manipulated voting, and finally "publicly" transferred huge amounts of funds according to the governance process. Keeta shut down the entire mainnet, first disabling component permissions, followed by compensation and a 72-hour deadline for recovery.
The Sandbox severed the bridges, allowing theoretically enormous amounts of fake coins to be minted, but the actual reserves that could be withdrawn were only around $670,000, with disputes focusing on how to compensate LP holders. Term's proposal remained pending for six days with zero votes against it, and the cooldown period was even canceled by the same proposal, resulting in around $8.5 million being transferred according to the governance process. What matters now is not the narrative, but rather who can mint coins, who can modify parameters, and whether anyone actually checks proposals once they're posted on-chain.