329T SAND minted, $675K stolen

BTCC
Paxful



A bridge configuration flaw on Base and BNB Smart Chain let attackers hijack LayerZero delegate permissions, mint trillions of phantom SAND tokens, and drain roughly $675,000 from the Ethereum vault before the team shut everything down. The $49 billion face value headline masked the real story: structural constraints meant the attacker could never have cashed out more than a fraction of what was created.

Summary

  • An attacker exploited the `approveAndCall` function on The Sandbox’s SAND omnichain fungible token contract on Base, hijacking LayerZero delegate permissions and minting 329.24 trillion unbacked SAND across 703 events over five hours on Aug. 21 and 22, 2026.
  • The face value of minted tokens reached approximately $49 billion according to security firm Blockaid, but the actual extraction totaled roughly 14.75 million SAND (about 80 ETH, or $675,000) drained from the Ethereum OFT Adapter in under 60 seconds.
  • The Sandbox disabled bridging on Base and BNB Smart Chain, removed LayerZero peer settings via multisig governance, and confirmed that SAND on Ethereum and Polygon remained untouched throughout the incident.
  • The project announced a 1:1 reimbursement plan from its treasury for eligible holders, with no new SAND tokens to be minted and a claims portal expected within two weeks of the Aug. 27 post-mortem.
  • The exploit marked the third major LayerZero-related bridge failure in five months, accelerating a $15 billion migration wave from LayerZero to Chainlink CCIP led by BitGo, Mantle, and Lombard.

On the night of Aug. 21, 2026, an address that had been dormant for 313 days routed a crafted payload through The Sandbox’s SAND token contract on Base. Within five hours, blockchain explorers showed trillions of freshly minted SAND tokens spreading across 173 wallets. Security firm PeckShield flagged the activity first, and by the time The Sandbox team responded, the attacker had already extracted what they could and moved on. The headline numbers were staggering, but the actual financial damage told a very different story.

okex

The gap between the face value of minted tokens and the real amount stolen reveals something important about how bridge exploits actually work. It also exposes a recurring pattern in cross-chain infrastructure: the same design choices that make bridges useful also make them fragile, and a single misconfiguration can open a door that costs millions to close.

How the approveAndCall exploit worked

The technical root of the attack sat inside a function called `approveAndCall` on The Sandbox’s SAND omnichain fungible token contract deployed on Base. In a standard OFT setup built on LayerZero, a delegate address on the destination chain holds administrative rights over the endpoint configuration. Those rights include the ability to set trusted peers, update security stacks, and authorize privileged calls into the token contract.

The attacker discovered that the `approveAndCall` function could be weaponized to hijack those delegate permissions. By routing a crafted payload through the SAND token contract, the attacker manipulated the delegation mechanism and assumed control over the minting process on Base. Once the delegate was compromised, the OFT no longer required a legitimate burn on the source chain to authorize a mint on the destination chain. The attacker essentially became the sole verifier for incoming bridge messages, gaining the ability to approve fraudulent messages without the authorization normally required by the bridge.

The Sandbox’s post-mortem stressed that no private keys were compromised and no unauthorized access to wallets took place. The vulnerability stemmed entirely from design flaws in the operational contract structure itself. That distinction matters because it means the flaw was not a case of stolen credentials or social engineering. It was a configuration problem baked into the bridge architecture from deployment.

The attacker minted 329.24 trillion SAND across 703 separate events over approximately five hours on Aug. 21 and 22. The minting happened on Base first, with secondary exposure on BNB Smart Chain. Ethereum and Polygon, where the vast majority of SAND’s legitimate supply resides, were never affected.

The $49 billion illusion versus $675,000 reality

The most misleading number in the entire incident was the $49 billion face value that Blockaid attached to the minted tokens. That figure came from multiplying the number of minted tokens by SAND’s market price at the time, a calculation that ignored every practical constraint on actually selling those tokens.

The reality was far smaller. The attacker drained approximately 14.75 million SAND from the Ethereum OFT Adapter in under 60 seconds. That extraction generated about 80 ETH, worth roughly $675,000 at the time of the transactions. The attacker sold tokens across 26 separate transactions, each sized to extract approximately 90 percent of available ether from the liquidity pool before it could recover.

One detail from the EGamers post-mortem stood out: the attacker minted exactly 14,743,364.21 SAND, which was precisely 100 tokens below the vault’s holdings at that moment. The precision suggested careful reconnaissance of the vault balance before execution. However, an unforeseen arbitrage bot disrupted the plan, leaving the attacker with 14,095,483.66 SAND instead of the intended amount.

The trillions of additional tokens minted on Base were essentially worthless. They could not be redeemed through the official bridge because The Sandbox disabled bridging before any meaningful redemption could occur. They could not be sold on decentralized exchanges because liquidity pools on Base did not hold anywhere near enough paired assets to absorb even a tiny fraction of the supply. The tokens existed on chain but had no path to value extraction.

This dynamic is important for understanding bridge exploits more broadly. The “total tokens minted” headline dramatically overstates the actual damage. The constraint is always liquidity, not the number on screen. An attacker can print any number of tokens on a destination chain, but the tokens are only worth what someone will pay for them, and in a bridge exploit scenario, the available liquidity evaporates almost instantly.

The Sandbox response and bridge shutdown

The Sandbox team moved relatively quickly once the exploit was identified. Hours after PeckShield’s initial alert, the team disabled all bridging to and from Base and BNB Smart Chain. The shutdown was executed at the contract level on both chains, and the team removed LayerZero peer settings via multisig governance to prevent any further cross-chain messages from being processed.

The project issued a statement confirming that SAND tokens on Ethereum and Polygon were not affected. No user wallets were compromised. The SAND locked on Ethereum, which backs all legitimately bridged SAND, remained fully intact throughout the incident. The team estimated the impact at less than 0.01 percent of the total SAND token supply when measured against the 3 billion maximum supply.

Korean exchanges Upbit and Bithumb suspended SAND deposits and withdrawals on Aug. 22, citing a suspected security incident and South Korea’s Virtual Asset User Protection Act. Upbit went further and froze SAND transfers on Ethereum, the chain The Sandbox said was not affected, suggesting the exchange was taking a cautious approach regardless of the project’s assurances. Coinbase separately delisted SAND perpetual futures contracts.

SAND’s price saw a near 10 percent intraday plunge after the incident was disclosed but recovered most of the loss within 24 hours, trading down just 0.8 percent over the full day. The muted price impact reflected the market’s relatively quick understanding that the actual financial damage was small and that the inflated token count could not be converted to real value.

Bridge security remains the weakest link

The Sandbox exploit did not happen in isolation. It was the third major LayerZero-related bridge failure in five months, following the $292 million Kelp DAO attack in April and the Stake DAO breach in May. Each exploit targeted different aspects of LayerZero’s architecture, but all three shared a common thread: insufficient verification redundancy.

The Kelp DAO attack was the most damaging. On April 18, 2026, attackers linked to North Korea’s Lazarus Group drained 116,500 rsETH, worth approximately $292 million, from KelpDAO’s LayerZero-powered bridge. The attack began six weeks earlier when an attacker socially engineered a LayerZero Labs developer, harvesting session keys and pivoting into LayerZero’s internal RPC environment. The attackers then poisoned internal RPC nodes and launched a DDoS attack against external providers, feeding false data to a single verifier that was the only checkpoint standing between the attacker and $292 million.

The KelpDAO hack wiped $13 billion from DeFi within 48 hours as users rushed to exit protocols they perceived as vulnerable. Curve Finance halted LayerZero infrastructure as a precaution after the attack, affecting CRV bridging on multiple chains.

LayerZero’s Decentralized Verifier Network allows applications to select as few as one verifier to validate cross-chain messages. Chainlink CCIP, by contrast, requires a minimum of 16 independent node operators per lane plus a separate Risk Management Network. That architectural difference explains why the industry response to these exploits has been a massive migration away from LayerZero.

By August 2026, publicly announced migrations from LayerZero to Chainlink CCIP totaled approximately $15 billion in secured value. BitGo led the wave by moving $7.4 billion in WBTC. Mantle shifted its $2.5 billion Super Portal. Lombard transferred over $1 billion in bitcoin-backed assets. Solv Protocol moved $700 million in tokenized bitcoin reserves. Kraken replaced LayerZero with Chainlink CCIP for its kBTC wrapped asset. Even Wyoming’s Stable Token Commission selected Chainlink CCIP for its Frontier Stable Token.

LayerZero’s ZRO token fell to approximately $302 million in market capitalization from an all-time high near $7.47. Nethermind, a former LayerZero verifier operator, exited to join Chainlink as a node operator.

The reimbursement plan

The Sandbox announced on Aug. 27 that it would reimburse affected SAND holders at a 1:1 ratio from its treasury. The total loss stood at 14.7 million SAND tokens, worth approximately $700,000. No new tokens would be minted for the compensation, meaning the reimbursement would not increase SAND’s circulating or maximum supply.

Eligible users were those who legitimately held bridged SAND on Base or BNB Smart Chain before the Aug. 21 attack. The project planned a snapshot-based compensation system using pre-attack balances. The two largest centralized exchanges holding over 72 percent of affected balances agreed to distribute replacement tokens directly to their customers without requiring individual claims. Other holders would need to submit claims through a dedicated portal expected to open within two weeks of the post-mortem.

The treasury-funded approach was a relatively clean resolution. Unlike some exploit responses that involve emergency token mints, governance votes on inflation, or protracted recovery processes, The Sandbox had sufficient reserves to absorb the loss directly. The $700,000 price tag, while not trivial, was manageable for a project with a treasury of its size.

The history of bridge exploits in numbers

Cross-chain bridges have consistently been the most attacked category of smart contracts since the technology emerged. The cumulative damage tells a sobering story about the structural risks of moving assets between blockchains.

Bridges have leaked more than $4 billion to hackers since 2021, according to data compiled across Chainalysis, DeFiLlama, and independent security researchers. The list of individual disasters includes the $624 million Ronin exploit in March 2022, the $326 million Wormhole theft in February 2022, the $190 million Nomad hack in August 2022, and the $292 million Kelp DAO breach in April 2026.

In 2024, bridges and cross-chain messaging protocols accounted for $1.19 billion of total crypto losses despite representing fewer than 5 percent of monitored protocols by count. That disproportionate figure reflects the concentrated risk that bridges carry: they hold or control large pools of assets across chains, and a small flaw can drain a fortune in minutes.

The year 2025 was worse. Over $3 billion was stolen across 119 hacks in just the first half of the year, a 50 percent jump over all of 2024’s losses. More than $1.5 billion of that total funneled through cross-chain bridges. The $1.5 billion Bybit compromise drove much of the annual total.

In 2026, bridge exploits have already accounted for $329 million from eight separate attacks through August. April 2026 was identified as the single worst month in DeFi’s history by number of attacks, with more than 30 separate incidents netting attackers almost $635 million in total. Q2 2026 saw 99 exploits draining $746 million, with cumulative DeFi losses for the year exceeding $840 million by the end of May.

The pattern is clear: despite years of audits, bug bounties, and architectural improvements, bridges remain the soft underbelly of cross-chain infrastructure. Each year brings new attack vectors and new headlines, but the fundamental vulnerability persists because bridges must hold concentrated pools of value and rely on verification mechanisms that can be compromised.

The OFT architecture problem

The Sandbox exploit raised uncomfortable questions about the omnichain fungible token standard itself. OFTs are designed to allow tokens to move freely across multiple blockchains by burning on one chain and minting on another, with a locked pool on the home chain serving as the ultimate backing. The architecture is elegant in theory, but each destination chain introduces a new attack surface.

In The Sandbox’s case, the SAND contract on Base inherited the `approveAndCall` function from earlier ERC-20 implementations. That function was designed for a different era of token standards, one where tokens lived on a single chain and delegate permissions carried less weight. When combined with LayerZero’s OFT framework, the function became a vector for hijacking cross-chain minting authority. The interaction between legacy token functions and modern cross-chain messaging created a vulnerability that neither system would have had in isolation.

The problem extends beyond The Sandbox. Any OFT deployment that includes `approveAndCall` or similar callback functions on destination chains could be vulnerable to the same class of attack. The Sandbox’s post-mortem did not disclose how many other OFT deployments share this pattern, but security researchers have noted that the function is common in older token contracts that were later wrapped in OFT adapters.

The broader lesson is that cross-chain token standards must account for the full surface area of the underlying token contracts they wrap. An audit that examines only the bridge logic without scrutinizing legacy functions on the token itself can miss exactly the kind of flaw that enabled the SAND exploit. Projects that deployed OFT bridges on top of existing token contracts face a particular risk because the original contracts were designed without cross-chain minting authority in mind.

This architectural concern is separate from the LayerZero verifier discussion. Even with multiple verifiers, a delegate hijack through `approveAndCall` could bypass the verification layer entirely because the attacker would already hold the keys to the minting function. The fix requires changes at the token contract level, not just the messaging protocol level.

Lessons from the phantom mint

The Sandbox incident crystallized several lessons that apply far beyond a single gaming token.

First, face-value calculations are misleading and potentially dangerous for market participants. When Blockaid reported $49 billion in minted tokens, that number traveled through headlines and social media without context. Traders who sold SAND based on a $49 billion figure were reacting to a phantom number. The actual extraction was $675,000. The gap between those two numbers is the difference between a catastrophic failure and a manageable incident. Media outlets that reported the $49 billion number without qualifying it as a notional figure contributed to unnecessary panic selling and distorted the market’s initial reaction to the incident.

Second, the approveAndCall vulnerability was a configuration flaw, not a novel zero-day exploit. The function existed in the deployed contract from the beginning. The delegate permissions structure was part of the standard OFT architecture. The attacker did not need to discover a previously unknown cryptographic weakness or break any encryption. They needed to understand how the pieces fit together and find the point where a crafted payload could hijack existing permissions. That kind of composability risk, where two individually safe systems become dangerous when combined, is one of the hardest categories of vulnerability to catch in standard security audits.

Third, the dormant wallet pattern is worth watching. The attacker’s address had been inactive for 313 days before the exploit. That kind of operational patience suggests either a sophisticated actor who prepared the exploit well in advance or someone who acquired access to a previously funded wallet specifically for this purpose. Either way, the long dormancy period meant the address would not have triggered activity-based monitoring until it was too late. On-chain surveillance systems that rely on recent activity patterns would have classified the wallet as inactive and deprioritized it from alerting systems.

Fourth, the arbitrage bot interference highlighted an underappreciated dynamic in DeFi exploits. The attacker planned their extraction with precision, minting exactly 100 tokens below the vault’s holdings. An automated trading bot disrupted that plan, reducing the attacker’s take by roughly 650,000 SAND. The interaction between exploit execution and automated market activity is a growing factor in how these incidents play out. In some cases, bots can accelerate an exploit by front-running the attacker’s swaps. In this case, the bot accidentally served as an unintentional defense mechanism by consuming liquidity the attacker needed.

Fifth, the speed of the actual extraction deserves attention. The attacker drained 14.75 million SAND from the Ethereum OFT Adapter in under 60 seconds. The five-hour minting spree on Base was essentially noise. The real damage happened in a single minute on Ethereum. That timeline underscores why bridge monitoring systems need to focus on vault drain velocity rather than destination-chain minting volume. A system that alerted on unusual minting activity on Base would have fired hours before the actual theft, but the theft itself was over before any human could have intervened.

What to watch

Bridge audit disclosures: Whether The Sandbox publishes a full technical post-mortem with contract-level details, or limits disclosure to high-level summaries, will signal how transparent the project intends to be about the root cause

LayerZero configuration changes: LayerZero said it will stop signing messages for applications using single-DVN configurations; watch whether existing integrators upgrade or migrate to alternatives

Reimbursement portal launch: The claims portal for non-exchange holders is expected within two weeks of the Aug. 27 post-mortem; delays or complications could erode holder confidence

Korean exchange relisting: Upbit and Bithumb suspended SAND trading; their timeline for restoring deposits and withdrawals will indicate how regulators view the incident severity

CCIP migration pace: The $15 billion migration from LayerZero to Chainlink CCIP is accelerating; further bridge incidents could push total migration volume past $20 billion by year-end

How many SAND tokens were actually minted in the exploit?

The attacker minted 329.24 trillion unbacked SAND tokens across 703 separate events over approximately five hours on Aug. 21 and 22, 2026. Security firm PeckShield initially flagged roughly 14.9 billion SAND created across two wallet addresses, while Blockaid put the face value near $49 billion across more than 400 transactions.

How much money was actually stolen from The Sandbox?

The actual financial extraction was approximately 14.75 million SAND drained from the Ethereum OFT Adapter in under 60 seconds. The attacker converted those tokens into roughly 80 ETH, worth about $675,000 at the time. The EGamers post-mortem estimated total economic damage at approximately $1.5 million when including broader market impact and slippage losses across affected liquidity pools.

What was the approveAndCall vulnerability?

The `approveAndCall` function on The Sandbox’s SAND omnichain fungible token contract on Base allowed the attacker to route a crafted payload that hijacked LayerZero delegate permissions. Once the attacker controlled the delegate, they could authorize minting on the destination chain without a corresponding burn or deposit on the source chain. No private keys were compromised; the vulnerability was a design flaw in the contract structure.

Will The Sandbox reimburse affected holders?

Yes. The Sandbox announced a 1:1 reimbursement plan funded from its treasury. No new SAND tokens will be minted. The two largest exchanges holding over 72 percent of affected balances will distribute replacement tokens directly to customers. Other holders must submit claims through a portal expected within two weeks of the Aug. 27 post-mortem.

Were SAND tokens on Ethereum and Polygon affected?

No. The exploit targeted only the bridge contracts on Base and BNB Smart Chain. SAND on Ethereum and Polygon was not affected. The SAND locked on Ethereum that backs all legitimately bridged SAND remained fully secure throughout the incident. No user wallets on any chain were compromised.

Why did Korean exchanges suspend SAND trading?

Upbit and Bithumb suspended SAND deposits and withdrawals on Aug. 22 under South Korea’s Virtual Asset User Protection Act after detecting abnormal on-chain activity. Upbit froze SAND transfers on Ethereum despite The Sandbox confirming that chain was unaffected, suggesting the exchange adopted a cautious approach. Coinbase also delisted SAND perpetual futures contracts.

What is the connection between this exploit and the Kelp DAO hack?

Both exploits targeted LayerZero-powered bridge infrastructure. The Kelp DAO hack in April 2026 drained $292 million through a compromised single-verifier configuration. The Sandbox exploit in August used a different attack vector (approveAndCall function hijacking) but exploited a similar weakness: insufficient verification redundancy in LayerZero’s architecture. Together with the Stake DAO breach in May, these three incidents accelerated a $15 billion migration from LayerZero to Chainlink CCIP.

How do phantom token mints differ from real theft in bridge exploits?

A phantom mint creates tokens on a destination chain without a corresponding deposit or burn on the source chain. While the face value can reach astronomical numbers, the tokens are only worth what available liquidity allows them to be sold for. In The Sandbox case, 329 trillion tokens were minted with a notional value of $49 billion, but the attacker could only extract $675,000 because that was the extent of reachable liquidity. The distinction between minted face value and extractable value is critical for accurately assessing bridge exploit severity.

Disclaimer: This article is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency investments carry significant risk, and readers should conduct their own research and consult with qualified professionals before making any investment decisions. Published Aug. 29, 2026.





Source link

Changelly

Be the first to comment

Leave a Reply

Your email address will not be published.


*