The Sandbox minted 329 trillion unbacked SAND tokens in 5 hours and only $675K was stolen

1 hour ago 1



A bridge configuration flaw on Base and BNB Smart Chain let attackers hijack LayerZero delegate permissions, mint trillions of phantom SAND tokens, and drain roughly $675,000 from the Ethereum vault before the team shut everything down. The $49 billion face value headline masked the real story: structural constraints meant the attacker could never have cashed out more than a fraction of what was created. Summary An attacker exploited the `approveAndCall` function on The Sandbox’s SAND omnichain fungible token contract on Base, hijacking LayerZero delegate permissions and minting 329.24 trillion unbacked SAND across 703 events over five hours on Aug. 21 and 22, 2026. The face value of minted tokens reached approximately $49 billion according to security firm Blockaid, but the actual extraction totaled roughly 14.75 million SAND (about 80 ETH, or $675,000) drained from the Ethereum OFT Adapter in under 60 seconds. The Sandbox disabled bridging on Base and BNB Smart Chain, removed LayerZero peer settings via multisig governance, and confirmed that SAND on Ethereum and Polygon remained untouched throughout the incident. The project announced a 1:1 reimbursement plan from its treasury f...

Read Entire Article