LIVE
Loading prices…

Accepted as Authorised

Across blockchains, governance systems and regulated gateways, this week exposed the same fault line: systems accepted authority they could recognise without always proving the permission behind it.

Accepted as Authorised

The Week in 60 Seconds

  • BounceBit permanently retired its standalone Layer 1 after an authorisation flaw let a caller nominate another account as the source of funds without proving that account had consented. No key, signature, wallet or exchange was compromised. About 286.5 million BB moved anyway.
  • Harmony completed its rollback. After both shards reached quorum and entered Phase Two, Harmony said the recovered network remained stable for more than 24 hours, produced roughly 100,000 blocks and advanced from epoch 3002 to 3004 with near-full signing participation.
  • The US Treasury proposed turning stablecoin compliance claims into a due-diligence problem. Its GENIUS Act proposal would condition US access for qualifying foreign-issued stablecoins on the issuer's technological capability to comply with lawful orders, while requiring intermediaries to perform reasonable due diligence before relying on that representation.
  • South Korea's tightened VASP registration regime took effect, with its transfer-control provisions, including mandatory reporting for large overseas transfers, still on a later timetable.
  • EU restrictions against eleven listed crypto and payment entities entered force, while NoOnes provided a live illustration of sanctions-driven de-risking: partners withdrew and the platform moved to withdrawal-only, even as NoOnes separately disputed that the EU-listed NoOneCrypto Inc. is its current operator.
  • Term Finance reportedly lost roughly $8.5 million from its vaults in what Term Labs confirmed was a governance exploit. Security researchers say the attacker acquired governance control itself, but the exact takeover mechanism remains unconfirmed by a first-party account.
  • The Sandbox confirmed a real cross-chain bridge vulnerability, while a nominal $49 billion minting figure continues to circulate as though it were a loss. It is not.

The Central Pattern

Several systems this week accepted actions because the rules they enforced treated those actions as authorised. That is not the same as saying the systems were functioning correctly. BounceBit contained an actual authorisation flaw. Harmony was recovering from one. Elsewhere, the authority layer sat outside the protocol entirely: validators coordinated around replacement history, regulators defined what issuers must establish, and counterparties decided which flows they would continue to service.

The common thread is narrower and stronger: execution can only enforce the authority model it is given. When that model omits a check, is captured, or changes at a governance or gateway layer, an action can be accepted without the legitimacy behind it ever being established. The fault line this week was between what a system was prepared to recognise and what had actually been verified.


BounceBit: The System That Never Asked

Between 21:02 UTC on 19 August and 01:54 UTC on 20 August, BounceBit said an attacker exploited an authorisation flaw in one of the chain's built-in protocol features, arising from a flaw inherent to its Evmos-derived stack, to move BB out of nine mainnet accounts without the owners' authorisation. A smart contract caller could designate another account as the source of a transfer without the underlying protocol ever confirming that account had consented. Roughly 286.5 million BB moved across fourteen transactions over just under five hours, and block production halted at height 20,702,857. BounceBit said its CeDeFi Strategy, Promo Vaults, Prime and RWA products were not affected.

The chain accepted and executed the transactions without any forged signature or stolen key. The missing check sat elsewhere: whether the nominated source account had actually authorised the debit.

The governance response is the more consequential half of the story. BounceBit did not patch the flaw and resume operating the same chain. It chose to abandon the Layer 1 entirely, reissuing BB as a BEP-20 token from a pre-attack snapshot and migrating to BNB Chain, citing Evmos's own discontinuation as a further reason not to rebuild. That decision is itself an exercise of a different kind of authority than the one the exploit abused: not the authority to move funds, but the authority to decide which chain, and which history, gets to continue existing at all.


Authority After Failure: Harmony's Rollback Completes

Harmony's recovery from its cross-shard receipt exploit reached a new stage on 20 August. Both Shard 0 and Shard 1 reportedly reached the validator quorum required to activate Phase Two of the rollback, moving the recovery from a proposed history to one with apparent coordinated support behind it. Shard 0 retains block 92,730,034 and regenerates from 92,730,035; Shard 1 retains block 94,978,278 and regenerates from 94,978,279.

That uncertainty has now narrowed. Harmony says the rollback is complete. After both shards reached quorum and Phase Two went live, the project reported more than 24 hours of stable operation, roughly 100,000 blocks produced, movement from epoch 3002 to 3004 and near-full signing participation. Those are Harmony's own recovery metrics rather than an independent audit, but they move the episode beyond a proposed replacement history into an operating replacement chain.

The pairing with Bitcoin's BIP-110 remains instructive. BIP-110 had an enforceable rule but failed to gather enough coordination to make it authoritative. Harmony gathered enough validator coordination around a recovery procedure to replace history and sustain the recovered network. Rules and coordination are different sources of authority. One failed without the other. The other succeeded because enough participants agreed on which history would count.


External Authority: Who Gets Serviced

The US Treasury's proposal turns representation into a due-diligence problem. Beginning 18 January 2027, digital asset service providers generally could not make a foreign-issued payment stablecoin available unless the issuer has the technological capability to comply with lawful orders and will comply with them. Treasury's proposal then asks what reasonable due diligence a provider must perform before relying on an issuer's representation that this capability exists, including whether providers should examine smart contracts and verify seize, freeze and burn functions. A broader licensed-issuer restriction follows from 18 July 2028. Critically, an intermediary's safe harbour disappears if it knew, had reason to know, or should have known that an issuer's representation was false.

South Korea tightened the gate it already controls. The Financial Services Commission's strengthened VASP registration requirements, including expanded scrutiny of major shareholders and executives and a 200 percent debt-ratio ceiling, took effect on 20 August. A separate layer of the same package, expanding the domestic Travel Rule to all transfer sizes and requiring mandatory reporting for transfers of 10 million won or more to overseas VASPs or digital wallets, has already been adopted but does not take effect until six months after promulgation. The entry gate tightened this week. The transfer-control layer has not yet arrived.

Ghana renewed a mandate it already held. The Bank of Ghana issued a fresh notice on 21 August requiring Virtual Asset Service Providers operating in Ghana to register, following a service-provider registration form that appeared the day before. This is not a new concept, Ghana ran compulsory VASP registration in 2025 and reiterated it again in April. What is current is the operational reassertion of that gateway control, exactly the kind of quiet, unglamorous regulatory development that is easy to miss and consequential anyway.

The EU listing became visible through NoOnes. Council Regulation 2026/1848 brought restrictions against eleven crypto and payment platforms into force on 23 August, among them a listed entity called NoOneCrypto Inc. NoOnes, the operating platform, tells two stories about what that means. One notice states that the EU-listed entity is a separate legal entity with no connection to the current platform's management or operations. A second says NoOnes is winding down because it could not resolve the sanctions affecting it, that partners withdrew support, and that blockchain-monitoring providers began classifying NoOnes-related wallets and transactions as high risk. The platform closed its peer-to-peer marketplace on 21 August and is now withdrawal-only, urging users to move their balances out.

Those two statements sit uncomfortably next to each other, and that discomfort is the point rather than something to resolve on NoOnes's behalf. No asset held by a NoOnes user became invalid. Nothing about the underlying cryptography changed. What changed was whether the surrounding financial network was willing to keep servicing it, and in NoOnes's own account, that willingness collapsed fast enough to end the platform.


Security Intelligence

Term Finance. A breaking incident on 23 August reportedly cost Term's vault infrastructure roughly $8.5 million, including about 2,843 ETH and 1.68 million USDC, with the USDC subsequently swapped into DAI. Security researchers allege that the attacker had acquired full governance control of four USDC strategy vaults and close to 91 percent control of its Ethereum Meta Vault, then used that authority to approve the transfers. Term Labs confirmed a governance exploit and responded by permanently shutting down all Term Meta Vaults and revoking DAO governance roles, a step it describes as irreversible; withdrawals remain open, and Term says its core borrowing and lending markets were not affected. If the reported takeover mechanism holds up, it would be one of the cleanest examples available anywhere of an attacker not defeating a system's authorisation controls but becoming the authority those controls were built to obey. It has not yet cleared that bar. Term has confirmed the exploit and its own remediation; the exact takeover percentages and causal mechanism still rest on security-firm monitoring and secondary reporting, not a first-party technical post-mortem. This stays a Security Intelligence item, not a major case, until that changes.

The Sandbox. The Sandbox has confirmed a real cross-chain bridge vulnerability affecting SAND on Base and BNB Smart Chain, while SAND on Ethereum and Polygon, along with user wallets, remained unaffected. The project disabled the affected bridging paths and characterised the impact as below 0.01 percent of total supply. Three separate numbers are circulating around this incident and none of them should be substituted for another. Security researchers estimate roughly 14.9 billion SAND was nominally minted. Blockaid put the face value of that minting at approximately $49 billion, a figure that reflects nominal quantity at quoted prices, not an actual loss. Independent on-chain reconstruction currently puts realised extraction at roughly 14.75 million SAND, around $675,000. The Sandbox has confirmed the vulnerability and its containment but has not yet published a matching final loss reconciliation.

MAYAChain. Maya Protocol halted its network on 18 August after an attacker chained six separate software weaknesses into one attack path, manufacturing a fictitious CACAO balance before draining real assets. Direct extraction is estimated at roughly $1.7 million, around 20 BTC plus about $300,000 in other assets. That figure should not be confused with the wider decline in liquidity-pool value, estimated at $10.9 to 11 million, which reflects arbitrage and CACAO's collapse rather than funds an attacker actually took. No single one of the six flaws was necessarily sufficient on its own. The exploit depended on their combination.

Triple-A. A first-party post-mortem published 21 August, covering a 25 July incident, showed multi-channel social engineering escalating from a compromised engineering credential into production access, malware deployment, abused API credentials and unauthorised withdrawals from Triple-A's own operational wallets across four chains. Client funds were never reachable. They sat in segregated trust accounts at institutions including DBS and Standard Chartered, structurally outside the compromised environment. This is a genuine constructive case: compromise occurred, and the architecture around it correctly limited what that compromise could reach.

The identity perimeter. A pattern kept recurring this month across otherwise unrelated companies. Trezor disclosed a shipping-partner breach exposing thousands of customers' names and home addresses. SafePal disclosed a separate authorisation flaw exposing nearly 40,000 customers' order data. Bits of Gold disclosed roughly 200,000 customers' personal and banking details. None of these involved a compromised seed phrase, private key or wallet. Operation ASTERIX showed what that kind of exposure eventually becomes: an industrial-scale operation matching leaked phone numbers against verified exchange accounts, then using counterfeit Trezor, Ledger and Exodus applications to collect recovery phrases directly, at one point switching AI coding assistants after one model refused to help obfuscate the malware. Separately, Socket documented 40 confirmed malicious Firefox extensions targeting Web3 wallets, nine of which had previously shipped as ordinary sports-score extensions before flipping to credential theft under the same signed identity, meaning a user's original trust decision did not protect them from what that extension later became. Across the disclosure cases, the cryptographic perimeter held. The identity and trust infrastructure built around it did not. ASTERIX showed what happens when that exposed information is subsequently weaponised against the keys themselves.


Stablecoin Freeze Digest

17 freezes • $14.97M frozen

Seven daily Cipher Index reporting windows covering 17–23 August 2026, using the standing ≥$200,000 threshold across Ethereum, Tron and XRPL.

Date Freezes Frozen
17 Aug 1 $427.5K
18 Aug 2 $511.0K
19 Aug 1 $270.4K
20 Aug 5 $1.86M
21 Aug 6 $10.09M
22 Aug 1 $584.1K
23 Aug 1 $1.23M
Weekly total 17 $14.97M

The week was dominated by 21 August, when six qualifying freezes accounted for $10.09 million, roughly two-thirds of the seven-day total. Activity fell back immediately afterward, with one qualifying freeze on each of the following two days. On the available data, the 21 August concentration reads as a single-day spike rather than the beginning of a sustained increase.

Source: The Cipher Index Stablecoin Freeze Tracker.


What to Watch

Term Finance's governance mechanism is the single highest-value confirmation still outstanding; if a first-party post-mortem establishes the reported takeover percentages, this becomes one of the week's strongest cases rather than a Security Intelligence entry. The Sandbox has not yet published a final reconciliation matching its own confirmed containment. The legal relationship between NoOneCrypto Inc. and the current NoOnes operator remains explicitly unresolved between NoOnes's own two statements. South Korea's transfer-control provisions, still months from taking effect, are worth tracking toward their eventual date. Compute derivatives, with the CFTC now working alongside the Department of Commerce toward a formal market structure for compute capacity, remain a watch item rather than a current story.


Corrections and Continuing Investigations

Continuing investigations. BounceBit's exact smart-contract mechanism, beyond the account-nomination flaw already confirmed, is not yet fully documented in a technical post-mortem. Term Finance's governance-takeover mechanism remains unconfirmed by any first-party account. The Sandbox's final extraction figure remains independently reconstructed rather than project-confirmed.


Published by the Zero Trust Network. Research supported by CipherBot and CipherIndex.

Discussion