According to WooFunai, the crypto industry experienced a series of security shocks in just a few days. Maher wrote in ForesightNews that the KeetaNetwork main network was forced to be read-only on August 20, theSandbox was attacked by cross-chain counterfeit money on August 22, and TermFinance treasury funds were transferred by malicious governance on August 23. Three separate incidents occurred centrally, pointing directly to the core risks of authority management and governance monitoring.
As a public payment chain, KeetaNetwork's co-founder and CEO (account X @schenkty) revealed on August 20 that the root cause of the security incident has been locked down, the problem was limited to a single component, did not affect the anchoring system and external connections, and the KTA tokens deployed on Base were unaffected. In order to stop the spread of risk, the main network was urgently switched to a read-only state. Operation can only be resumed after patch testing is completed and additional guarantees have been added. The team promised to evaluate the full compensation plan and indicated that the strategic reserves were sufficient to cover potential losses.
Although the total amount stolen after the audit was not officially disclosed, on-chain monitoring showed that a new address received about 9.3 million KTA (worth about 685,000 US dollars at the time) and 2 billion GALA through a cross-chain bridge, then exchanged these assets for about 1,902 ETH (worth about 3.64 million US dollars). The market reacted violently. The KTA price plummeted from a high of $0.09 to a minimum of $0.05 on August 19, a drop of 37%. Although it has now rebounded to $0.077, confidence has been clearly damaged.
On August 22, Ty once again stated that the investigation had made substantial progress. It had collected evidence including the attack on the IP, VPN and VPS used, user agents, technical environment, associated email and infrastructure service providers, and submitted the relevant parties. The government issued an ultimatum requiring the attackers to return all proceeds to the designated base address in the form of KTA, ETH, or USDC within 72 hours. If the full amount is returned, the bug bounty can also be discussed and exempted from legal liability; if overdue, the right to legal prosecution is reserved. As of August 24, the main network is still read-only, no compensation rules have been issued, and it is unclear whether payment will be made within the 72-hour window.
This case shows that when the permission settings of the application chain are relaxed by default or can be bypassed in combination, the shutdown is often faster than patching, and although the practice of disclosing off-chain leads and setting a return period is rare, its effectiveness ultimately depends on the degree to which the return of funds matches the on-chain data.
TheSandbox's attack focused on flaws in the cross-chain minting mechanism. On August 22, the SAND cross-chain contract deployed on Base was attacked. The attackers used the approveAndCall function to take away LayerZero's representative authority, continue to mint SAND without collateral to the Ethereum main network, and affected BNBChain.
It is worth noting that the core layer of the LayerZero protocol has not been broken, and the vulnerability stems from a failure in the project party's contract to manage delegation rights. The project party quickly cut off the two-way bridge with Base and BNBChain to curb the expansion of losses. Nominally, the attackers added about 14.9 billion SAND, and the nominal spot exposure reached hundreds of millions of dollars, but on-chain reviews showed that only about 14.75 million SAND and about 80 ETH were actually withdrawn and monetized from Ethereum reserves, equivalent to 670,000 US dollars. SAND, user wallets, and mainnet collateral on Ethereum and Polygon have not been affected.
The SAND cross-chain uses LayerZero's OFT standard. The peer foundry should cope with the main network lockdown. Node representatives decide who can mint the target chain, but ApproveAndCall was misused to cause the fake cross-chain minting to take effect. Officials say the vulnerability is under control, affecting less than 0.01% of total supply, and investors are warned to avoid trading SAND on Base and BSC. Exchanges Upbit and Bithumb have suspended deposit/withdrawal services. As of press time, the price of SAND dropped from $0.05 to $0.045.
According to data compiled by WooFunai, despite the impressive nominal increase in sales, the actual reserves were only about 670,000 US dollars, and the focus of controversy will shift to how LP Snapshot compensates for damaged liquidity providers.
The TermFinance case revealed the fatal weakness of the governance mechanism. As a fixed-rate loan agreement on Ethereum, TermFinance implemented a governance proposal that had been publicized on the chain for about six days on August 23. The proposal received zero votes on the voting page. The proposal includes closing the original 7-day transaction cooldown (timelock) and then transferring about 2,842 WETH from ETHMetaVault. After about 20 minutes, the second transaction transferred about 1.68 million USDC coins from the five USDC vaults and exchanged them for DAI. According to PeckShield statistics, the attackers took a total of about 2,843 ETH (worth about 6.9 million US dollars at the time) and 1.68 million USDC, with a total loss of about 8.5 million US dollars.
The attack was not a smart contract re-entry or oracle manipulation, but rather strictly followed the “submit — wait — no one veto — execute” governance process. External analysis indicates that in a situation where the circulation of governance tokens is scarce, the attackers obtained almost all voting rights in some USDC strategic vaults and control of about 90% of EthMetaVault, thus transferring the funds out of the package for effective governance. TermLabs said that all TermMetaVaults have been shut down, the DAO governance role has been revoked, this shutdown is irreversible, and further deposits are permanently prohibited, but withdrawals can still be made. Officials say the underlying Term agreement and its direct lending market have not been affected, and remedies are being coordinated with external security teams.
This incident is the same as the case where the BonkDAO treasury was attacked by a malicious governance proposal in July of this year, and BONK tokens worth about 20 million US dollars were stolen. The attackers all purchased tokens through CEX wallets to control voting and “publicly” transferred huge amounts of money according to the governance process, highlighting the governance risk of low voter concentration and voting participation.
Although the attack path of the three incidents varied, they had remarkable commonalities: Keeta stopped the entire main network, with component permissions being shut down first, followed by compensation and 72 hours of recourse; theSandbox broke the bridge. Although the increase in paper volume was ridiculous, only about $600,000 in reserves that could be disbursed, the controversy fell on LP snapshot compensation; Termance Finance's proposal was dried for six days, and the veto vote was zero. The cooldown period was closed by the same proposal, and about $8.5 million was transferred according to the governance process. Together, these cases point to a central issue: in the on-chain world, the popularity of narratives is far less important than the rigor of authority and governance. Who can mint coins, who can change parameters, and whether there is enough attention when the proposal is on the chain are the keys to determining asset safety. As hacker methods become more specialized, from permission breaches to governance manipulation, attackers are using blind spots in protocol design to carry out precise attacks. In the future, project parties need to strengthen real-time monitoring of minting rights, parameter modification rights, and governance proposals to avoid repeating mistakes. This is not only a technical challenge, but also a comprehensive test of community governance and safety awareness.