Thedefiant
The Sandbox Exploit: 14.9B Unbacked SAND Tokens Minted on Base and BNB Chain
Article Content
On August 22, 2026, The Sandbox reported a security breach that allowed an attacker to mint 14.9 billion unbacked SAND tokens on the Base and BNB Smart Chain networks. The exploit involved hijacking LayerZero delegate permissions via the `approveAndCall` function, resulting in an estimated face value of $49 billion in unauthorized tokens. The Sandbox quickly disabled bridging to and from these networks, isolating the compromised tokens and preventing further transfers. The company stated that the actual impact was less than 0.01% of the total SAND supply, and no user wallets were compromised. Major South Korean exchanges, Upbit and Bithumb, suspended SAND transactions as a precaution. The Sandbox is preparing a compensation plan for affected liquidity providers and plans to release a full post-mortem report.
Key Points: • An attacker minted 14.9 billion unbacked SAND tokens using a cross-chain bridge exploit. • The exploit's face value was estimated at $49 billion, but the actual impact was less than 0.01% of total supply. • Bridging to Base and BNB Smart Chain has been suspended, and major exchanges halted SAND transactions.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.