Three protocol attacks hit Keeta, The Sandbox and Term Finance within days

Three protocol attacks hit Keeta, The Sandbox and Term Finance within days

N
News Editor
2026-08-24 02:14:52
Three separate crypto protocols were hit by attacks in less than a week, each exposing a different failure point in onchain security. On Aug. 20, payments-focused blockchain Keeta Network switched its mainnet to read-only mode after what it described as a security issue in a single component. The team later demanded that the attacker return the funds within 72 hours and said it had gathered evidence including IP data, VPN and VPS details, user-agent information, related email accounts, and service providers. On Aug. 22, The Sandbox suffered a cross-chain minting attack tied to its SAND bridge contract on Base. The attacker allegedly abused approveAndCall to seize LayerZero delegate authority, minting large amounts of SAND on Base and BNB Chain without Ethereum mainnet backing. While the notional over-minting figure reached about 14.9 billion SAND, the project and security reviews said the actual value drained from reserves and monetized was about $670,000. A day later, fixed-rate lending protocol Term Finance saw a governance proposal executed after sitting onchain for roughly six days with zero opposing votes. Assets moved out of the protocol included about 2,843 ETH and 1.68 million USDC, with reported losses around $8.5 million. Taken together, the three incidents point to a recurring question in crypto infrastructure: who can mint, who can change parameters, and who is watching governance before execution.

Three crypto protocols were hit by separate attacks within the same week, with each case taking a different route onchain.

Three protocol attacks hit Keeta, The Sandbox and Term Finance within days 2

On Aug. 20, payments blockchain Keeta Network switched its mainnet to read-only mode after a security issue in what it said was a single component, then later gave the attacker 72 hours to return the funds. On Aug. 22, metaverse project The Sandbox suffered a cross-chain minting exploit that led to large amounts of SAND being minted on Base and BNB Chain. On Aug. 23, fixed-rate lending protocol Term Finance saw treasury assets moved out after a governance proposal was executed, draining about 2,843 ETH and 1.68 million USDC, for losses estimated at roughly $8.5 million.

The three incidents were unrelated, and the attack paths were not the same. Keeta dealt with a component-level security problem, The Sandbox was hit through cross-chain minting permissions, and Term Finance was affected through governance execution.

Keeta switches mainnet to read-only and seeks fund return

Keeta is a payments-focused blockchain. In an Aug. 20 update, co-founder and CEO Ty, whose X account is @schenkty, said the root cause of the security incident had been identified. He said the issue was limited to the affected component and did not involve the anchoring system or external connectivity systems. KTA deployed on Base was not affected, according to the statement.

Three protocol attacks hit Keeta, The Sandbox and Term Finance within days 3

As a precaution, the team placed the mainnet in read-only mode and said full operations would resume only after a patch had been tested and extra safeguards added. Keeta also said it was evaluating how to fully compensate affected users and added that its strategic reserves could cover damaged funds if needed.

The project has not published an audited total for stolen funds. Lookonchain tracked a new address that received about 9.3 million KTA, worth around $685,000 at the time, and about 2 billion GALA through a cross-chain bridge. The address then sold the assets into about 1,902 ETH, worth roughly $3.64 million.

On Aug. 19, KTA fell from a high of $0.09 to a low of $0.05, a drop of about 37%, and later recovered to $0.077.

Three protocol attacks hit Keeta, The Sandbox and Term Finance within days 4

Ty issued another statement on Aug. 22 saying the investigation had made substantial progress. He said the team had gathered evidence pointing to the attacker, including attack-related IP addresses, the VPN and VPS used, the user agent and technical environment behind unauthorized requests, related email accounts, and software and infrastructure service providers. The evidence had been preserved and submitted to the relevant parties.

The statement demanded that the attacker return all proceeds within 72 hours. Keeta said repayment could be made in KTA, ETH, or USDC to a Base address. If the full amount was returned, the team said it was willing to discuss a bug bounty and settle the matter without pursuing legal liability. If the deadline passed without repayment, Keeta said it reserved the right to seek legal action and asset recovery.

Keeta said a full technical report would be released after the investigation and verification were complete. As of Aug. 24, the mainnet remained in read-only mode, no compensation details had been released, and it was still unclear whether the 72-hour window had resulted in repayment.

The Sandbox attack mints huge amounts of SAND on paper, but reserve losses were lower

On Aug. 22, The Sandbox said its SAND cross-chain contract on Base had been attacked. According to the account described in the report, the attacker used approveAndCall to seize LayerZero delegate authority, allowing repeated minting of SAND without Ethereum mainnet collateral and spreading the impact to BNB Chain. The project said LayerZero’s core protocol layer was not compromised.

Three protocol attacks hit Keeta, The Sandbox and Term Finance within days 5

The Sandbox then cut off two-way bridging with Base and BNB Chain. The notional over-issuance was reported at about 14.9 billion SAND, creating a spot exposure in the hundreds of millions of dollars on paper. But onchain review put the amount actually drained from Ethereum reserves and monetized at about 14.75 million SAND and around 80 ETH, worth about $670,000.

The project said SAND on Ethereum and Polygon, user wallets, and mainnet collateral were not affected.

SAND cross-chain transfers use LayerZero’s OFT model, where minting on the destination chain is supposed to match assets locked on the mainnet, and delegate nodes determine who can mint on the target chain. In this case, the issue was in the project’s approveAndCall function, which was used to alter delegated permissions and make the forged cross-chain minting valid.

Three protocol attacks hit Keeta, The Sandbox and Term Finance within days 6

The Sandbox said the vulnerability had been contained and affected less than 0.01% of total supply. It also warned investors not to trade SAND on Base or BSC. Exchanges Upbit and Bithumb suspended deposits and withdrawals.

At the time of writing, SAND had fallen from $0.05 to $0.045.

Term Finance governance proposal executed after roughly six days onchain

Term Finance is a fixed-rate lending protocol on Ethereum. On Aug. 23, an Ethereum transaction executed a governance proposal that had been publicly posted onchain for about six days. The voting page showed zero votes against.

The proposal included disabling what had been roughly a seven-day trading timelock, then transferring about 2,842 WETH out of the ETH Meta Vault. About 20 minutes later, a second transaction moved roughly 1.68 million USDC out of five USDC treasuries and swapped the funds into DAI.

Three protocol attacks hit Keeta, The Sandbox and Term Finance within days 7

PeckShield said the attacker took about 2,843 ETH, worth around $6.9 million at the time, along with 1.68 million USDC.

This was not a reentrancy exploit and not a manipulated oracle. The governance flow ran as designed: proposal submission, waiting period, no veto, then execution. External analysis said that with governance tokens relatively thin in circulation, the attacker gained nearly all voting power in some USDC strategy vaults and about 90% control of the ETH Meta Vault, then encoded the fund transfer into a valid governance action.

Term Labs said all Term Meta Vaults had been shut down, DAO governance roles had been removed, the shutdown was irreversible, and further deposits had been permanently disabled. Withdrawals remain available. The team also said that based on the investigation so far, the underlying Term protocol and its direct lending markets were not affected, and it was coordinating with outside security teams on remediation and recovery work.

Three protocol attacks hit Keeta, The Sandbox and Term Finance within days 8

The report notes that governance attacks are not rare. It pointed to a July incident in which the BonkDAO treasury was hit by a malicious governance proposal and about $20 million worth of BONK was stolen. Addresses tied to that attack reportedly bought BONK through a centralized exchange wallet before the proposal was filed, then manipulated voting and moved funds out through the governance process.

Different attacks, same question about protocol control

Keeta halted its entire mainnet, closing component permissions first and addressing compensation and a 72-hour recovery demand later. The Sandbox cut off bridges; while the paper supply inflation figure was huge, reserves actually cashed out were a little over $600,000. Term Finance left a proposal onchain for about six days with no opposing votes, and the same proposal could turn off the timelock before moving roughly $8.5 million through the governance process.

The incidents landed during a broader market rise, but they exposed different weak spots. The immediate questions are who can mint, who can change parameters, and whether anyone is actually watching proposals while they sit onchain waiting to be executed.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.