Four days, three attacks on the chain: the market has risen, and hackers are busier.

CN
12 hours ago
Now the focus should not be on the narrative, but rather on who can mint coins, who can change parameters, and whether anyone is actually watching when proposals are listed on the chain.

Written by: Mahe, Foresight News

In less than a week, three cryptocurrency protocols became targets for attackers.

On August 20, the payment public chain Keeta Network switched its mainnet to read-only, stating that a single component had a security issue, and subsequently issued a 72-hour ultimatum for the return of funds; on August 22, the metaverse project The Sandbox suffered a cross-chain minting attack, with attackers minting a large amount of SAND on Base and BNB Chain, prompting the project team to sever the bridge connections to the two chains, while security agencies estimated that approximately $670,000 worth of reserves were actually drained; on August 23, the fixed-rate lending protocol Term Finance executed a governance proposal, resulting in approximately 2,843 ETH and 1.68 million USDC being removed from the treasury, leading to a loss of about $8.5 million.

The three incidents were unrelated, with different attack vectors, but all occurred within the same week.

Keeta: Mainnet has been set to read-only status

Keeta is a payment-type public chain, and its co-founder and CEO Ty (X account @schenkty) stated in an update on August 20 that a sudden tweet indicated that the root cause of the security incident had been found, limiting the problem to the affected component and not involving the anchoring system or external connection system; the KTA deployed on Base was unaffected.

As a precaution, the mainnet was placed in read-only mode, awaiting the completion of patch testing and additional safeguards before resuming full operation. The team also indicated that it was evaluating how to fully compensate affected users and stated that strategic reserves could cover the damaged funds when necessary.

The official audited "total amount stolen" has not yet been disclosed. Lookonchain monitored a new address that received approximately 9.3 million KTA (about $685,000 at the time) and approximately 2 billion GALA via cross-chain bridge, and subsequently sold it for about 1,902 ETH (approximately $3.64 million).

On August 19, the price of KTA plummeted from a high of $0.09 to a low of $0.05, a drop of about 37%, and has now rebounded to $0.077.

On August 22, Ty released another statement, claiming that the investigation had made substantial progress and evidence pointing to the attackers had been collected, including attacking-related IPs, VPNs and VPSs used, user agents and technical environments at the time of unauthorized requests, associated email addresses, as well as information about software and infrastructure service providers; the evidence has been preserved and submitted to the relevant parties. The statement demanded that the counterpart return all earnings within 72 hours, transferable in KTA, ETH, or USDC to the Base address. If returned in full, Keeta is willing to discuss a bug bounty and conclude the matter without legal liability; otherwise, it reserves legal recourse and the right to recover funds.

The complete technical report is promised to be released after the investigation and verification. As of August 24, the mainnet remains read-only, compensation details are not yet available, and whether the 72-hour window will result in payment is also unknown.

The lesson from this incident is not complex: when application chains write "who can change permissions" as a default that is loosely enforced or can be circumvented, halting the chain often comes faster than applying a patch. Keeta chose to publicly disclose part of the off-chain clues and set a return deadline, which is rare in recent theft cases, but whether the money returns and whether the report can match the on-chain data are the standards for evaluating this approach.

The Sandbox: Fake coins minted in astronomical numbers

On August 22, The Sandbox's SAND cross-chain contract deployed on Base was attacked. The attackers seized representing rights from LayerZero through approveAndCall, continuously minting SAND without collateral on the Ethereum mainnet, affecting BNB Chain as well. The core layer of LayerZero protocol was not compromised.

The project team promptly severed the bidirectional bridge with Base and BNB Chain. The nominal issuance was reported to be about 14.9 billion, with a nominal spot exposure of several hundred million dollars; however, the actual amount drained and realized from Ethereum reserves was approximately 14.75 million SAND and about 80 ETH, equivalent to around $670,000. The SAND on Ethereum and Polygon, user wallets, and mainnet collateral were stated by the project team to be unaffected.

The SAND cross-chain uses LayerZero's OFT: minting on the other end should correspond to the mainnet locking, and node representatives decide who can mint on the target chain. The vulnerability lay in the project team's contract’s approveAndCall, which was used to alter delegation rights, allowing the forged cross-chain minting to take effect.

The official announcement stated that the vulnerability has been contained, affecting only 0.01% of the total supply, and reminded investors not to trade SAND on Base or BSC. Exchanges Upbit and Bithumb have suspended deposits and withdrawals.

As of the time of writing, the price of SAND dropped from $0.05 to $0.045.

Term Finance: Proposal was left on-chain for six days before vetoing, treasury was removed according to governance process

Term Finance is a fixed-rate lending protocol on Ethereum. On August 23, a transaction on Ethereum executed a governance proposal that had been public on-chain for about six days. The veto votes on the voting page were zero. The proposal's content included closing the original approximately 7-day trading cooling (timelock), from which approximately 2,842 WETH were subsequently transferred from the ETH Meta Vault.

About 20 minutes later, a second transaction transferred about 1.68 million USDC from five USDC vaults and exchanged it for DAI. PeckShield estimated that the attacker took away approximately 2,843 ETH (approximately $6.9 million at the time) and 1.68 million USDC.

This incident was neither a smart contract re-entry nor oracle manipulation, but rather governance went through the protocol design of "submit—wait—no one vetoes—execute." External analyses suggested that the attacker, under conditions of scarce circulation of governance tokens, gained near-total voting rights over a portion of the USDC strategy vault and about 90% control over the ETH Meta Vault, then used the funds transferred out to establish a valid governance execution.

As of now, Term Labs has stated that all Term Meta Vaults have been closed, DAO governance roles have been revoked, this closure is irreversible, and further deposits are permanently prohibited. Withdrawals can still be conducted. The official statement claims that, based on the current investigation, the underlying Term protocol and its direct lending market were unaffected and that remediation and recovery work is being coordinated with external security teams.

Governance attacks have not been uncommon in recent years. This form of attack is particularly effective when voting power is concentrated and participation is low.

In July this year, the BonkDAO treasury suffered a malicious governance proposal attack, resulting in the theft of BONK tokens valued at approximately $20 million. The attacker’s related address purchased BONK through a CEX wallet before the proposal was initiated, then manipulated the votes, and ultimately "publicly" transferred the massive amount of funds according to the governance process.

Keeta halted the entire mainnet, first disabling component permissions, and then addressing compensation and a 72-hour recovery. Sandbox severed the bridge, with outrageous amounts theoretically printable, but the redeemable reserves amount to only about $600,000, and the controversy will fall on how to compensate LP snapshots. Term's proposal was left hanging for six days, with zero veto votes, and the cooling period could still be terminated by the same proposal; approximately $8.5 million was transferred according to governance processes.

Now the focus should not be on the narrative, but rather on who can mint coins, who can change parameters, and whether anyone is actually watching when proposals are listed on the chain.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink