The Sandbox’s $49 billion phantom mint: how a bridge exploit created unbacked SAND tokens

1 hour ago 2



An attacker weaponized a single ERC-20 function to hijack LayerZero delegate permissions and mint 329 trillion unbacked SAND on Base, yet the actual reserve drain totaled just $675,000, exposing both the fragility and the hidden safeguards of cross-chain token architecture. Summary An attacker exploited the approveAndCall function on The Sandbox\u2019s SAND omnichain fungible token contract on Base, hijacking LayerZero delegate permissions and minting 329.24 trillion unbacked SAND across 703 events over five hours on Aug. 21 and 22, 2026. Blockchain security firm Blockaid flagged $49 billion in face-value SAND minted across more than 400 transactions, while PeckShield counted 14.9 billion SAND directed to two attacker-controlled addresses. The actual financial extraction was far smaller: roughly 14.75 million SAND drained from the Ethereum OFT Adapter in under 60 seconds, yielding approximately 80 ETH (around $675,000 at the time of the transactions). The Sandbox disabled bridging on Base and BNB Smart Chain, removed LayerZero peer settings via multisig, and confirmed that SAND on Ethereum and Polygon was unaffected; Korean exchanges Upbit and Bithumb halted deposits and withdrawal...

Read Entire Article