Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Exclusive Binance’s SB Seker on India's INR Stablecoin Case, the USD Premium & Rebuilding Regulator Trust
    Exclusive: Binance’s SB Seker on India’s INR Stablecoin Case, the USD Premium & Rebuilding Regulator Trust
    Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
    Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
    80% of Major SpaceX Investors Deal With Crypto
    80% of Major SpaceX Investors Deal With Crypto
    SEC Cancels Crypto Meeting Why Rulemaking Just Hit Another Wall
    SEC Cancels Crypto Meeting: Why Rulemaking Just Hit Another Wall
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It's Actually Doing
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It’s Actually Doing
  • Opinion
    OpinionShow More
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Sandbox SAND Hacked: Attackers Mint 329 Trillion Tokens on Base in 5-Hour Rampage

The attacker hijacked LayerZero delegate permissions via approveAndCall, minting 329.24 trillion unbacked SAND across 703 events on Base over five hours.

Written By Dishita Malvania
Published 59 minutes ago
Make The Crypto Times preferred on GoogleGoogle
Sandbox SAND Hacked Attackers Mint 329 Trillion Tokens on Base in 5-Hour Rampage

The Sandbox has become the latest metaverse and gaming project to lose control of its own token supply on a cross-chain adapter, after an attacker hijacked delegate permissions on the SAND Omnichain Fungible Token contract on Base and minted an amount of tokens that, in nominal face value, dwarfs the project’s entire legitimate market capitalization. 

The attack ran uninterrupted for roughly five hours before internal safeguards were belatedly triggered, and it fits a pattern of LayerZero OFT peer manipulation exploits that has now hit at least three notable protocols in 2026 alone.

AI Summary
Show
Attacker hijacked LayerZero delegate via approveAndCall, gaining admin rights to the Base SAND OFT contract.
Compromised delegate allowed unlimited minting on Base, creating trillions of unbacked SAND without burning on Ethereum.
Delayed safeguards let the exploit run five hours, extracting about $665,000 from Ethereum reserves before multisig cut off peers.

While the face value of unbacked SAND printed on Base reached roughly $49 billion, the actual extractable loss sits at approximately $665,000 in drained Ethereum-side reserves, a gap that captures how OFT exploits can look catastrophic on paper while remaining structurally contained.

Web3 security firm Blockaid was the first to flag the incident publicly. In a two-part alert, the firm said its exploit detection system had identified an ongoing exploit on the SAND OFT deployment on Base, with attackers “hijacking LayerZero delegate permissions via approveAndCall and minting unbacked SAND.” 

🚨 Blockaid detected an ongoing exploit on @TheSandboxGame SAND OFT on Base.
Attackers hijacked LayerZero delegate permissions via approveAndCall and minted unbacked SAND.
~$49B face-value SAND minted so far across ~400+ txs. Attack still ongoing.
More details in 🧵

— Blockaid (@blockaid_) August 22, 2026

Blockaid’s initial tally put the face value of newly minted SAND at approximately $49 billion across more than 400 transactions while the attack was still active. PeckShield followed shortly after, tagging two attacker-controlled addresses, 0xAbE0…4D22 and 0x638C…F296, that received 14.9 billion SAND in the first wave visible on its systems.

How the attackers took control

The abused contract is the Base deployment of SAND, a LayerZero v2 OFT that carries the same contract address as its adapter on Ethereum. In a standard OFT setup, a “delegate” address on the destination chain holds administrative rights over the endpoint configuration, including the ability to set trusted peers, update security stacks, and, critically, authorize privileged calls into the token contract. 

Once the delegate is compromised or its permissions can be assumed by a third party, the OFT effectively no longer needs a legitimate burn on the source chain to mint on the destination.

The precise sequence, as reconstructed, began with the attacker exercising the SAND token’s own approveAndCall function, an ERC-20 extension originally designed as a UX shortcut so users could combine an approval and a follow-on contract call in a single transaction. 

In this case, that pattern was weaponized to route a crafted payload through the token contract into the LayerZero endpoint, granting the attacker’s helper contract the effective standing of a delegate. From that point, the mint side of the bridge was open. 

An on-chain investigator confirmed the outcome in a subsequent thread, noting that the Base-side minting produced 329.24 trillion SAND across 703 distinct events distributed to 173 different addresses over a five-hour window that began at 23:42:05 UTC on August 21 and terminated at 04:45:21 UTC on August 22.

The face-value screenshot that circulated widely, showing one address holding $706 million in SAND, is misleading. It reflects reported price multiplied by unbacked balance, and on-chain records show the largest single wallet, 0x638Ccb18370eE228378a565c1d4D0F9620d7F296, currently holds 250 million SAND valued at $12,049,260 alongside $3,245 in USDC, $329 in WETH, an 11 EURC dust position, and a 0.067 ETH gas float. 

That wallet was originally funded by Relay Solver 313 days ago, which suggests the operator has been sitting on a pre-positioned attack address for the better part of a year.

The $706 million valuation shown against that single wallet, and the $49 billion aggregate face value flagged by Blockaid across all attacker addresses, both reflect the on-chain price feed applied to unbacked balances rather than any actual redeemable liquidity.

The real loss lives on Ethereum

While the trillions minted on Base grabbed headlines, the settled economic damage is elsewhere. The Ethereum SAND OFT adapter, sharing the same 0xac531… contract address as its Base counterpart, went from a balance of 14,769,723 SAND at 00:32:11 UTC to 0.0056 SAND at 01:22:11 UTC on August 22. 

All of that flowed out in 15 events, and 14,095,483.66 SAND of it moved to one externally owned account across six transactions inside a 24-second window, a burst characteristic of an automated withdrawal script rather than manual operation.

At SAND’s prevailing price around $0.045, the raw adapter drain represents roughly $665,000 in real economic value, dwarfed by the attacker’s paper mint on Base but very real for anyone holding wrapped SAND on non-Ethereum deployments that relied on that reserve. 

That is the same failure mode analysts flagged after the April 18 KelpDAO exploit, in which 116,500 rsETH worth roughly $292 million was minted on Ethereum against a forged LayerZero packet from a compromised RPC infrastructure, and it echoes the StakeDAO incident in May, where an attacker used a compromised deployer key to reset the trusted LayerZero peer on the vsdCRV OFT and mint 5.4 trillion tokens on Arbitrum, netting only around $91,000 in extractable value against a supply-detonating headline number.

Ethereum L1 supply is untouched, and the peer was killed

The one piece of unambiguously good news for holders is that the underlying SAND supply on Ethereum mainnet was never compromised. The L1 totalSupply function still returns exactly 3,000,000,000 SAND, unchanged from the maximum defined at contract inception. 

The unbacked mints are isolated to the Base deployment and to any inflated balances that were bridged out through the OFT before the response.

At 05:09:19 UTC on August 22, the SAND multisig zeroed out the trusted peers for LayerZero endpoint IDs 30101 and 30102, which correspond to the Ethereum and Base endpoints in LayerZero v2’s addressing scheme. In practical terms, that severs the cross-chain messaging path between the two adapters, meaning any further attempted mints from the compromised Base contract will fail to be honored on the Ethereum side, and any newly minted SAND already sitting on Base cannot be moved back through the OFT to Ethereum. 

The multisig response landed 24 minutes after minting activity organically stopped and roughly five and a half hours after the first exploit transaction, a window during which the vast majority of extractable value had already been rotated.

Exchange response and market impact

South Korea’s two largest exchanges, Bithumb and Upbit, both moved quickly to halt SAND deposits and withdrawals as the unbacked tokens began propagating. The suspensions cut off the most liquid Korean won markets for the token, which historically account for a disproportionate share of SAND spot volume. Neither exchange had reopened services at the time of writing.

Spot price reaction has been comparatively contained given the scale of the paper mint, precisely because most of the market recognized within an hour that the Ethereum L1 supply cap remained intact and that any inflated Base balances would be structurally difficult to redeem. 

SAND traded down between roughly 5.5% and 10% depending on venue, with CoinGecko marking the token at $0.03879 and a market capitalization of $113.7 million against a circulating supply of 2.9 billion tokens. Derivative markets have been noisier. 

Open interest in SAND futures rose approximately 16% within a single hour of the news breaking, spot volume spiked to roughly 24 times its recent baseline, and funding rates flipped sharply negative, indicating aggressive short positioning against a possible follow-through dump if any of the inflated Base supply finds a route to liquid venues.

Silence from the project, and a difficult moment for The Sandbox

At the time of publication, The Sandbox’s official account had not issued a public statement. Neither Animoca Brands, which took majority control of the project in September 2025 after cutting roughly 50% of its workforce, nor SANDChain, the Ethereum layer-2 the team announced in October 2025 with SAND as its native gas token, had commented on the incident. 

The Sandbox team has identified and fully contained a recent vulnerability regarding the SAND cross-chain bridge on Base and BNB Smart Chain (BSC). The impact is minimal, representing less than 0.01% of the total SAND token supply.

SAND tokens on Ethereum and Polygon are NOT…

— The Sandbox (@TheSandboxGame) August 22, 2026

The exploit lands at an already awkward moment for a token whose price is more than 99% below its 2021 all-time high of $8.40.

A verified loss in the six-figure range is small in absolute terms compared to 2026’s headline exploits, but it lands on a project whose fully diluted market capitalization now sits at just $116 million, meaning the drained reserve represents roughly 0.6% of the entire legitimate token base.

Root cause verification remains preliminary. The abuse of approveAndCall to hijack a LayerZero delegate is not, in itself, a vulnerability in the LayerZero protocol, and it fits within the class of application-level configuration failures the protocol operator has consistently characterized as OApp responsibility. 

What it points to is either a delegate whose configuration allowed a low-privilege call path to escalate into control, or a compromise of the deployer or delegate key itself, either of which puts the exploit in the same category as the StakeDAO and Kelp incidents rather than a novel bug class.

A pattern that keeps repeating

Between April and August 2026, LayerZero OFT peer and delegate abuse has now been the direct or proximate cause of nominal token issuance measured in trillions across at least three separate incidents, even where the extractable dollar value has ranged from five figures to nine. 

Blockaid’s H1 2026 Onchain Security Report, published in late July, put verified exploit losses for the first half of the year at $1.1 billion across 212 incidents, with private key and infrastructure compromises accounting for close to three-quarters of that total and cross-chain bridge failures leading the categorical damage. The Sandbox exploit will add to a running 2026 total that already sits above $1.2 billion.

For SAND holders, the questions that matter over the coming days are whether The Sandbox and LayerZero can definitively account for how the delegate was seized, whether any inflated Base balances can be redeemed or bridged before Bithumb and Upbit resume services, and whether the multisig’s peer-zeroing action holds cleanly enough to prevent a second wave. For the industry, this is the third loud reminder in five months that cross-chain minting authority is now the highest value target on the map.

Also Read: Bofur Capital Drained of $2M Minutes After Compound Withdrawal

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

No Safety Net, High Taxes Why Edelweiss CEO Radhika Gupta Says No to Crypto in India
No Safety Net, High Taxes: Why Edelweiss CEO Radhika Gupta Says No to Crypto in India
Bofur Capital Drained of $2M Minutes After Compound Withdrawal
Bofur Capital Drained of $2M Minutes After Compound Withdrawal
Exclusive Binance’s SB Seker on India's INR Stablecoin Case, the USD Premium & Rebuilding Regulator Trust
Exclusive: Binance’s SB Seker on India’s INR Stablecoin Case, the USD Premium & Rebuilding Regulator Trust
Pi Coin Eyes $0.10, Protocol 27 Upgrade Expected On September 15
Pi Coin Eyes $0.10, Protocol 27 Upgrade Expected On September 15
Ripple Tests Permission Delegation for RLUSD on XRPL
Ripple Tests Permission Delegation for RLUSD on XRPL

Find Us on Socials

You may also like

Maya Protocol Hit by $1.7M Exploit in First Major Breach Since 2023

Maya Protocol Hit by $1.7M Exploit in First Major Breach Since 2023

Uniswap to Bring DeFi Liquidity to Circle’s Arc Mainnet in September 

Uniswap to Bring DeFi Liquidity to Circle’s Arc Mainnet in September 

Morpho gains 10% Amid Launch of Open-Source Quoter Bot

Morpho gains 10% Amid Launch of Open-Source Quoter Bot

Compound Announces $52M Program for Onchain Credit

Compound Announces $52M Program for Onchain Credit

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information