The Sandbox said an attacker exploited its SAND omnichain token setup on Base, minting 329.24 trillion unbacked SAND over Aug. 21 and 22 after abusing the token contract’s approveAndCall function. The incident briefly produced a notional face value near $49 billion, but the amount actually extracted was far smaller.

According to the reported on-chain timeline, the attacker used the flaw to seize LayerZero delegate permissions, then minted tokens across 703 events over roughly five hours. Security firms cited different measures of the activity, while The Sandbox moved to disable bridging on the affected networks and said Ethereum and Polygon were not impacted.

How the exploit unfolded

The first reported activity began at 23:42:05 UTC on Aug. 21, when an address that had been inactive for 313 days started sending crafted transactions to the SAND OFT contract on Base. PeckShield identified one address, tagged as attacker-controlled, as central to the operation.

The attack centered on approveAndCall, an ERC-20 extension that combines token approval with a follow-on contract call. In this case, the payload was routed through the SAND contract into the LayerZero endpoint. Because the call reached the endpoint with the token contract as msg.sender, the attacker was able to inherit the contract’s delegate authority and alter endpoint permissions.

Once that access was obtained, unbacked SAND could be minted on Base without a matching lock of tokens on Ethereum. The minting continued through 04:45:21 UTC on Aug. 22. At 05:09:19 UTC, The Sandbox multisig removed trusted peer settings for Base and BNB Smart Chain, cutting the bridge path used in the exploit.

Why the $49 billion figure was mostly nominal

Blockaid flagged roughly $49 billion in face-value SAND minted across more than 400 transactions, while PeckShield counted 14.9 billion SAND sent to two attacker-controlled addresses. The much larger 329.24 trillion total reflected all minted balances across 173 wallets and 703 mint events.

That headline number came from multiplying inflated token balances by the market price, not from liquid value that could realistically be withdrawn. SAND’s legitimate maximum supply on Ethereum is 3 billion tokens, so the forged balances exceeded that cap by an enormous margin. In practical terms, markets could not absorb more than a small fraction of those tokens without collapsing the price on affected venues.

The actual reserve drain was tied to the amount of real SAND sitting in the Ethereum OFT Adapter, which backs cross-chain transfers. Reportedly, about 14.75 million SAND was pulled from that adapter in under a minute and later converted into about 79.74 ETH, or roughly $675,000 at the time.

Why losses were limited

The exploit exposed a weakness in application-level permissions, but the bridge design also imposed a hard limit on what could be redeemed. Under LayerZero’s OFT model, real SAND remains on Ethereum and is locked when bridged out, while destination-chain tokens are minted as representations. That means only the adapter’s reserves, not the phantom balances on Base, could be turned back into backed assets.

After those reserves were drained, the remaining minted tokens had no effective redemption path. The source article described them as visible on-chain but unsupported by locked collateral. Any additional damage would have depended on whether the attacker could swap fake SAND against real liquidity in decentralized exchange pools on Base or BNB Smart Chain.

The Sandbox said it took a pre-incident snapshot and plans to compensate eligible liquidity providers, suggesting there may have been losses in local pools beyond the adapter drain. As of Aug. 23, the company had not disclosed the payment timeline or funding source for that compensation.

Market and industry response

Following the incident, The Sandbox advised users not to buy, sell, or trade SAND on Base and BNB Smart Chain. It also said SAND on Ethereum and Polygon was unaffected. Korean exchanges Upbit and Bithumb halted deposits and withdrawals, citing a suspected security incident, and Coinbase delisted SAND perpetual futures contracts.

The case also added to broader scrutiny of LayerZero-linked deployments. The source article described it as the third major bridge exploit tied to LayerZero integrations in five months, after the Kelp DAO attack in April and a Stake DAO breach in May. In all three cases, the common issue was unauthorized control over cross-chain permissions, even though the immediate causes differed.

The next confirmed step is compensation for eligible liquidity providers based on the pre-incident snapshot. Beyond that, the key established facts are that bridging on Base and BNB Smart Chain was disabled, trusted peer settings were removed, and the Ethereum-side 3 billion SAND cap remains unchanged.

Source: crypto.news