The Sandbox (SAND) Bridge Exploit: ApproveAndCall Flaw Mints 329 Trillion SAND
A bridge flaw let attackers mint 329 trillion unbacked SAND on Base and drain $675K in under a minute. The Sandbox pledged 1:1 treasury reimbursement.
AI SummaryAI
- Attackers minted 329.24 trillion unbacked SAND across 703 events on Base and BNB Smart Chain.
- The attacker drained 14.75 million SAND, about 80 ETH or $675,000, in under 60 seconds.
- The Sandbox disabled Base and BNB Smart Chain bridging and removed LayerZero peer settings via multisig.
- Upbit and Bithumb suspended SAND deposits and withdrawals on Aug. 22.
329 Trillion Phantom SAND Minted on Base
The bridge behind The Sandbox (SAND), the NFT-based metaverse platform, failed through configuration, not cryptography: a flaw in the token's omnichain contract on Base let an attacker hijack delegate permissions and mint 329.24 trillion unbacked SAND across 703 events in roughly five hours on Aug. 21 and 22, 2026. In plain terms, a cross-chain bridge is supposed to mint tokens on a destination chain only after a burn or deposit is proven on the source chain — the attacker's crafted payload, routed through the approveAndCall function, made the bridge accept their own authorization instead. Once delegate control was seized, no legitimate burn was ever required. The attacker's address had sat dormant for 313 days before the payload went out, and on-chain monitoring flagged the burst only after freshly minted tokens had already spread across 173 wallets. Security firm PeckShield raised the first alert; by the time The Sandbox team responded, the extraction was already complete. Security firm Blockaid put the face value of the minted supply at approximately $49 billion — a notional figure that simply multiplies phantom tokens against market price. The real damage was a fraction of that: roughly 14.75 million SAND drained from the Ethereum OFT Adapter in under 60 seconds, sold across 26 transactions sized to pull about 90 percent of available ether from the liquidity pool each time, netting approximately 80 ETH, or $675,000. The team later confirmed no private keys were compromised and no user wallets were touched. Secondary exposure appeared on BNB Smart Chain, while SAND on Ethereum and Polygon — where the circulating supply backing legitimate bridged tokens is anchored — was never affected. The gap between $49 billion on paper and $675,000 actually taken defines the incident: an attacker can print anything on a destination chain, but can only steal what nearby liquidity will absorb.
Shutdown, Exchange Suspensions and 1:1 Reimbursement
The Sandbox ecosystem moved within hours of the first alert, disabling all bridging to and from Base and BNB Smart Chain at the contract level and removing LayerZero peer settings through multisig governance so no further cross-chain messages could clear. SAND locked on Ethereum, which backs every legitimately bridged token, stayed intact throughout, and the team pegged realized impact at less than 0.01 percent of the 3 billion maximum token supply. Market venues reacted fast: Upbit and Bithumb suspended SAND deposits and withdrawals on Aug. 22 under South Korea's Virtual Asset User Protection Act, and Upbit froze transfers even on Ethereum, the chain the project said was untouched — a deliberately cautious read. Coinbase delisted SAND perpetual futures separately. Retail holders on venues such as these — platforms we track in our Best Crypto Exchanges guide — will receive replacement tokens without individual claims. Price action stayed contained: SAND plunged nearly 10 percent intraday on disclosure, then recovered most of the loss within 24 hours to close down just 0.8 percent on the day, as traders digested that the $49 billion headline was phantom and the FUD around it overstated the actual loss. The exploit was the third major LayerZero-related bridge failure in five months, after the $292 million Kelp DAO breach in April and the Stake DAO incident in May, and it accelerated a roughly $15 billion migration to Chainlink CCIP led by BitGo, Mantle and Lombard. Curve Finance halted its LayerZero infrastructure as a precaution during that same wave. On Aug. 27, The Sandbox published its post-mortem and committed to a 1:1 reimbursement from treasury with no new SAND minted — the plan we detailed in our earlier 1:1 SAND repayment pledge report. Snapshot-based compensation covers holders of bridged SAND on Base or BNB Smart Chain before Aug. 21; exchanges holding over 72 percent of affected balances will distribute replacements directly, while other holders use a claims portal expected within two weeks. Our earlier coverage of the SAND token exploit on Base tracked the minting burst as it unfolded.
Vault Reconnaissance and the Wider OFT Question
On-chain records sharpen the picture: the attacker minted exactly 14,743,364.21 SAND — precisely 100 tokens below the Ethereum vault's holdings at that moment — evidence of careful reconnaissance, before an arbitrage bot consumed liquidity the plan depended on and cut the final take to 14,095,483.66 SAND. The official post-mortem states the root cause plainly: the legacy approveAndCall function, inherited from an earlier era of token standards, interacted with LayerZero delegate permissions to hand over minting authority — a configuration failure, not a key theft. Remediation was contract-level: bridging disabled, peer settings removed via governance. What remains open is scope. The post-mortem did not disclose how many other OFT deployments share the approveAndCall pattern, though security researchers note the function is common in older token contracts later wrapped in OFT adapters. Until audits cover the token layer and not just bridge logic, COINOTAG's reading is that the same failure class stays reachable in similar builds — the constraint that limited this theft to $675,000 was liquidity, not design.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


