Three crypto protocols were hit by separate attacks within the same week, with each case taking a different route onchain.
On Aug. 20, payments blockchain Keeta Network switched its mainnet to read-only mode after a security issue in what it said was a single component, then later gave the attacker 72 hours to return the funds. On Aug. 22, metaverse project The Sandbox suffered a cross-chain minting exploit that led to large amounts of SAND being minted on Base and BNB Chain. On Aug. 23, fixed-rate lending protocol Term Finance saw treasury assets moved out after a governance proposal was executed, draining about 2,843 ETH and 1.68 million USDC, for losses estimated at roughly $8.5 million.
The three incidents were unrelated, and the attack paths were not the same. Keeta dealt with a component-level security problem, The Sandbox was hit through cross-chain minting permissions, and Term Finance was affected through governance execution.
Keeta switches mainnet to read-only and seeks fund return
Keeta is a payments-focused blockchain. In an Aug. 20 update, co-founder and CEO Ty, whose X account is @schenkty, said the root cause of the security incident had been identified. He said the issue was limited to the affected component and did not involve the anchoring system or external connectivity systems. KTA deployed on Base was not affected, according to the statement.
As a precaution, the team placed the mainnet in read-only mode and said full operations would resume only after a patch had been tested and extra safeguards added. Keeta also said it was evaluating how to fully compensate affected users and added that its strategic reserves could cover damaged funds if needed.
The project has not published an audited total for stolen funds. Lookonchain tracked a new address that received about 9.3 million KTA, worth around $685,000 at the time, and about 2 billion GALA through a cross-chain bridge. The address then sold the assets into about 1,902 ETH, worth roughly $3.64 million.
On Aug. 19, KTA fell from a high of $0.09 to a low of $0.05, a drop of about 37%, and later recovered to $0.077.
Ty issued another statement on Aug. 22 saying the investigation had made substantial progress. He said the team had gathered evidence pointing to the attacker, including attack-related IP addresses, the VPN and VPS used, the user agent and technical environment behind unauthorized requests, related email accounts, and software and infrastructure service providers. The evidence had been preserved and submitted to the relevant parties.
The statement demanded that the attacker return all proceeds within 72 hours. Keeta said repayment could be made in KTA, ETH, or USDC to a Base address. If the full amount was returned, the team said it was willing to discuss a bug bounty and settle the matter without pursuing legal liability. If the deadline passed without repayment, Keeta said it reserved the right to seek legal action and asset recovery.
Keeta said a full technical report would be released after the investigation and verification were complete. As of Aug. 24, the mainnet remained in read-only mode, no compensation details had been released, and it was still unclear whether the 72-hour window had resulted in repayment.
The Sandbox attack mints huge amounts of SAND on paper, but reserve losses were lower
On Aug. 22, The Sandbox said its SAND cross-chain contract on Base had been attacked. According to the account described in the report, the attacker used approveAndCall to seize LayerZero delegate authority, allowing repeated minting of SAND without Ethereum mainnet collateral and spreading the impact to BNB Chain. The project said LayerZero’s core protocol layer was not compromised.
The Sandbox then cut off two-way bridging with Base and BNB Chain. The notional over-issuance was reported at about 14.9 billion SAND, creating a spot exposure in the hundreds of millions of dollars on paper. But onchain review put the amount actually drained from Ethereum reserves and monetized at about 14.75 million SAND and around 80 ETH, worth about $670,000.
The project said SAND on Ethereum and Polygon, user wallets, and mainnet collateral were not affected.
SAND cross-chain transfers use LayerZero’s OFT model, where minting on the destination chain is supposed to match assets locked on the mainnet, and delegate nodes determine who can mint on the target chain. In this case, the issue was in the project’s approveAndCall function, which was used to alter delegated permissions and make the forged cross-chain minting valid.
The Sandbox said the vulnerability had been contained and affected less than 0.01% of total supply. It also warned investors not to trade SAND on Base or BSC. Exchanges Upbit and Bithumb suspended deposits and withdrawals.
At the time of writing, SAND had fallen from $0.05 to $0.045.
Term Finance governance proposal executed after roughly six days onchain
Term Finance is a fixed-rate lending protocol on Ethereum. On Aug. 23, an Ethereum transaction executed a governance proposal that had been publicly posted onchain for about six days. The voting page showed zero votes against.
The proposal included disabling what had been roughly a seven-day trading timelock, then transferring about 2,842 WETH out of the ETH Meta Vault. About 20 minutes later, a second transaction moved roughly 1.68 million USDC out of five USDC treasuries and swapped the funds into DAI.
PeckShield said the attacker took about 2,843 ETH, worth around $6.9 million at the time, along with 1.68 million USDC.
This was not a reentrancy exploit and not a manipulated oracle. The governance flow ran as designed: proposal submission, waiting period, no veto, then execution. External analysis said that with governance tokens relatively thin in circulation, the attacker gained nearly all voting power in some USDC strategy vaults and about 90% control of the ETH Meta Vault, then encoded the fund transfer into a valid governance action.
Term Labs said all Term Meta Vaults had been shut down, DAO governance roles had been removed, the shutdown was irreversible, and further deposits had been permanently disabled. Withdrawals remain available. The team also said that based on the investigation so far, the underlying Term protocol and its direct lending markets were not affected, and it was coordinating with outside security teams on remediation and recovery work.
The report notes that governance attacks are not rare. It pointed to a July incident in which the BonkDAO treasury was hit by a malicious governance proposal and about $20 million worth of BONK was stolen. Addresses tied to that attack reportedly bought BONK through a centralized exchange wallet before the proposal was filed, then manipulated voting and moved funds out through the governance process.
Different attacks, same question about protocol control
Keeta halted its entire mainnet, closing component permissions first and addressing compensation and a 72-hour recovery demand later. The Sandbox cut off bridges; while the paper supply inflation figure was huge, reserves actually cashed out were a little over $600,000. Term Finance left a proposal onchain for about six days with no opposing votes, and the same proposal could turn off the timelock before moving roughly $8.5 million through the governance process.
The incidents landed during a broader market rise, but they exposed different weak spots. The immediate questions are who can mint, who can change parameters, and whether anyone is actually watching proposals while they sit onchain waiting to be executed.


