BNB Chain leads 2026 RWA growth with $3.62B
How I am setting up for 10–20X returns on my portfolio this cycle

In the 2020/2021 cycle I invested heavily in BTC and ETH options on the Canadian ETF’s back when BTC was just coming out of its bear market blues, and BTC was roughly $29,000. Those options paid off over 10X returns, even while having been bought 2X off the bottom. As importantly, they involved zero altcoin specific risk, minimum counterparty risk (regulated ETF’s) and no trading and constant position management .. AND could be bought in my retirement account or tax free savings account.
I bought, I held about 2 years, and I sold at 10–12X the price. Original article written in July 2023 below:
Best Bear Market Opportunity Yet
I managed those returns despite buying the BTC and ETH options after Bitcoin had doubled from its bear market Bottom in Oct of 2022. Now, we are roughly 35% off the bottom (which I think is very likely THE bottom), and the opportunity is on par with the previous cycle.
I am not ready to divulge all the specifics just yet, as my strategy is likely to evolve as we near the end of the bear market. That said, here is the gist of it:
I do believe Bitcoin will have a solid bull run, but also concede that dimishing returns are a mathematical reality.
BTC Targets:
ETH and SOL are more difficult to predict, particularly given the capital drain from AI stonks and Meme coins.
That said, I believe ETH has a shot at some redemption here as corporations and large entities gravitate towards L2 chain they can customize and control. I will refine these targets in the coming months as Robinhood chain and Solana play out their game of meme coin capture, and provide them by year-end in an update article.

To be frank, the real talent at this point is to ignore all the noise on crypto X, and make a plan and stick to it. If you are like me, this big move up caught you somewhat off guard, and perhaps more sidelined that you would like. I have had a battle with the FOMO demons for weeks now, and winning that battle is what will set the stage for huge gains.
The timeline is far too bullish, and my expectation at this point is that we take a bit of a breather and pull back into the low 70K, or high 60K range BTC, at which point I will not try to time my entries but will buy hard in expectation of a big 2027 and 2028. Then sit back, stomach the volatilty, and cash in in a couple years while 90% of crypto X is trying to predict the hourly charts and missing the 300–400% gains on spot BTC (and 1000%–1500% on call options)
Good luck out there, and see you on the next one!
Sovereign Crypto (aka RickyBobby)
I release regular altcoin and crypto updates, subscribe for more info and to keep up to date!
400% return on most recent trade 🔥…

Disclosures:
The Bull Run is Quietly Loading was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.

On August 23, 2026, an attacker used roughly half an ETH to acquire majority governance control over Term Labs Meta Vaults, then passed a routine-looking proposal that disabled the vault’s transaction delay and drained six vaults. No key was stolen and no core vault code was broken: with almost no one else voting, the attacker simply became the governance, extracting 2,841.74 WETH and 1,679,639 USDC, about $8.5 million, later swapped to DAI.
Term’s Strategy Vaults are ERC-4626 vaults built on Yearn V3 infrastructure, governed through Aragon TokenVoting. Voting power isn’t tied to vault deposits directly: to get it, a depositor has to wrap their vault shares into a separate governance token, an extra opt-in step almost nobody took. A Zodiac Delay module was meant to sit between an approved governance proposal and its execution, giving roughly a week’s cooldown before anything it authorized could actually run.
Term’s voting power came from wrapping vault shares into a separate governance token, and almost no one bothered. On the ETH Meta Vault the total wrapped supply was just 0.5352 tokens, across the USDC vaults it was similarly thin. A depositor putting in about 0.5 ETH and wrapping the resulting shares ended up holding 0.4852 of that ETH Meta Vault supply, about 90.7%, while a separate wallet held all of the active voting power across all seven USDC vault proposals it opened.

Because the minimum proposer voting power was set to zero, opening a proposal cost nothing beyond gas. The attacker filed a proposal titled Veto strategy vault parameter change, using the exact wording the curator used for routine parameter updates, so it read on the surface like an ordinary item up for a veto vote rather than an attack.

Underneath that title sat 17 actions. The first three reset the Zodiac Delay module’s roughly seven-day cooldown and expiration to zero and handed control of it to an attacker-controlled executor. The rest recalled capital from all four of the ETH Meta Vault’s real strategies, deployed a new strategy called Fixed Recipient WETH Exit Strategy, gave it a debt ceiling of uint256 max, and routed the vault's balance into it.

Six days later, with the voting window closed and almost nobody having voted against a majority the attacker already held, the proposal became executable. At about 06:25 UTC on August 23, the attacker called executeProposal(), recalling WETH from four strategies and pulling roughly 2,841.74 WETH out through the planted strategy contract.

Twenty-two minutes later, a second attacker wallet ran the identical playbook against five USDC vaults in a single transaction, where it held all of the voting power across every proposal it had opened on those vaults. That transaction drained approximately 1,679,639 USDC, which was later swapped into DAI.



This wasn’t a bug in Term’s core vault code. The root failure is that voting power depended on an opt-in wrapping step almost nobody took, so a deposit worth a few hundred dollars was enough to become the effective government of vaults holding millions, and that governance had the authority to disable its own safety delay.
The formal governance settings, a 50% support threshold, 5% minimum participation, and a roughly six-day voting window, weren’t reckless on their own, but they meant nothing once one wallet held almost all the active voting power. A zero minimum proposer-power requirement meant opening the proposal cost nothing, and the proposal’s own opening actions could reset the Zodiac Delay module’s cooldown and expiration to zero, removing the one control meant to slow exactly this kind of action before it executed.
Whether the delay module’s exposure to governance was an intentional design choice or a distinct authorization failure hasn’t been publicly explained.
Governance participation and concentration monitoring. A review should flag when a governance token’s actively-wrapped supply is thin enough that a small deposit can cross a majority threshold, and require a minimum active-participation floor before proposals gain force, not just a percentage-of-supply threshold.
Scope-limit what governance can touch. The Zodiac Delay module existed specifically to slow dangerous actions, but the same governance process could reset its own cooldown and expiration. A review would flag any proposal-executable action that can modify the safeguard meant to gate proposal-executable actions, and wall that off behind a separate, higher-friction control.
Title and content review for proposals, not just code review. A malicious proposal disguised as a routine curator veto item passed unnoticed for six days. Requiring a structured, machine-checkable diff of what a proposal actually changes, surfaced independently of its title, would have caught the delay-module reset regardless of what the proposal was called.
2,841.74 WETH and 1,679,639 USDC(swapped to DAI) drained from the vaults converged at a single address, 0xD5183d8BfC65a50863C62aF2538198A8288FFc13.

Stolen USDC was swapped into DAI and then transfer to another address 0x9210130f81c84d028DB83701fF379A79c9365135, and then swapped to ETH and deposited into tornado cash.


Since then, major ETH didn’t moved from attacher wallet, 300 of it moved out of the consolidation address to 0xC14007663A5bb9F13d4d2AEE8c6FE9075eF1d83e, and deposited to tornado cash.

Term Labs posts its first public acknowledgment, confirming a governance exploit hit its vaults, without giving a loss figure or technical explanation.
Term Labs follows up, confirming all Term Meta Vaults have been shut down and their DAO governance roles revoked, an irreversible step that blocks new deposits while leaving withdrawals open.
Attacker Wallets / EOAs
Key Transactions
No key was stolen and no line of core vault code was broken. Almost nobody wrapped their shares into Term’s governance token, so a deposit worth a few hundred dollars was enough to become the majority, and that majority had the authority to disable the one mechanism built to slow it down. The vault executed exactly what its governance authorized, the governance itself was the vulnerability. A safeguard that governance can switch off isn’t a safeguard, it’s a formality waiting for someone to notice nobody’s watching.
Originally Posted at Quillaudits
Term Labs $8.5M Governance Takeover Exploit (Explained) was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.
EigenLayer has crossed 5 million ETH in restaking deposits across operators, marking another major scale milestone for one of Ethereum’s most closely watched DeFi infrastructure protocols.
The figure includes native ETH and liquid staking token deposits, so it needs to be read carefully. Still, 5 million ETH is a huge number, and it shows how large the restaking market has become.
EigenLayer’s pitch has always been simple but ambitious: let staked ETH secure more than Ethereum alone.
That idea has pulled in capital quickly, but it also created a new set of risks that the market is still learning how to price.
For more details, visit the official Defillama platform.
Ethereum staking created a large pool of capital earning yield.
EigenLayer asks a natural next question: can that same economic security be reused to support other services? Those services, often called AVSs, can include data availability layers, oracle systems, middleware, rollup infrastructure, and other networks that need security.
For depositors, the attraction is extra yield.
For builders, the attraction is access to Ethereum-linked security without bootstrapping everything from zero.
That combination explains why restaking has grown so quickly.
Crossing 5 million ETH puts EigenLayer into a different scale category.
This is no longer a small experiment. It is a major concentration of staked assets being routed through a restaking system. That can strengthen Ethereum’s wider infrastructure economy, but it also means failures would matter.
The larger restaking gets, the more important risk controls become.
Slashing conditions, operator performance, AVS security, smart contract risk, and liquidity assumptions all need to be understood properly.
The deposit figure combines different kinds of exposure.
Native ETH restaking is not identical to restaking liquid staking tokens. LSTs already carry their own smart contract, liquidity, and staking-provider risks. Adding restaking on top can create a more layered risk profile.
That does not make the model bad.
It means users need to understand what they are depositing and what risks they are accepting.
A headline number is useful, but the composition behind it matters.
Deposits alone do not complete the story.
EigenLayer also needs Actively Validated Services that create real demand for restaked security. If AVSs grow and generate sustainable fees, the model becomes more compelling. If deposits grow faster than useful services, the market may start asking whether the yield is durable.
Protocol metrics point to 18 active security networks, which gives the milestone more context.
Restaking is not only attracting deposits. It is also building out the services that are meant to use those deposits.
Restaking has supporters and critics for good reason.
Supporters see it as a way to make Ethereum’s security more productive. Critics worry about correlated risk, complex slashing, leverage-like behavior, and contagion if restaking systems fail.
Both sides have a point.
EigenLayer’s 5 million ETH milestone shows the market wants the product. Now the harder work is making sure the risk is understood as clearly as the opportunity.
This article draws on EigenLayer restaking data from DeFiLlama and related protocol metrics.
This article was written by the News Desk and edited by Samuel Rae.
This report is based on information released by Defillama. at Defillama
