South Korea’s largest crypto exchange Upbit has designated The Sandbox (SAND) as an investment warning asset, with the tag taking effect at 15:00 KST on August 24. The move formalises a review that could end in trading support being terminated by early October, and follows the deposit and withdrawal freeze that both Upbit and Bithumb imposed on August 22 after a compromise of the SAND cross-chain bridge on Base and BNB Smart Chain.
The designation window runs through the fifth week of September 2026, from September 28 to October 4, and coincides almost exactly with Bithumb’s expected review dates.
What the Upbit notice says
The Upbit designation notice invokes Article 17, Paragraph 1, Item (e) of the Enforcement Decree of the Act on the Protection of Virtual Asset Users, the same statutory provision Upbit used to freeze SAND transfers over the weekend. The affected markets are SAND/KRW and SAND/BTC. Upbit said the assessment weighed unresolved or unmitigated security incidents affecting the asset itself, wallets managed by the issuer, or the ledger where the asset is issued, transmitted, or stored.
Deposits will not be processed for the duration of the designation, and any attempted deposits will be returned. When services resume, only withdrawals will reopen initially, with deposit resumption to be announced separately.
SAND has also been removed from Upbit’s Coin Lending pool under Article 3, meaning no new or additional lending applications will be accepted. Existing loans will remain valid until their maturity dates.
Bithumb prepares a parallel review
The two-exchange sequence noted that Bithumb, South Korea’s second-largest venue, is scheduled to review SAND between September 28 and October 2 to decide whether to lift, extend, or terminate its own caution designation.
Bithumb had halted SAND deposits and withdrawals at 11:11 KST on August 22, one minute before Upbit. Spot trading has continued uninterrupted on both platforms, though the Korean won book carries a disproportionate share of global SAND volume, and the twin review windows now function as a de facto listing referendum for the token.
The exploit that triggered the action
The regulatory response was set in motion by a five-hour attack on the SAND Omnichain Fungible Token deployment on Base, covered in detail by The Crypto Times. The attacker exploited the token’s approveAndCall function to hijack LayerZero delegate permissions on the Base contract, gaining administrative control over the endpoint configuration and, from there, unrestricted minting rights on the destination chain.
Web3 security firm Blockaid was the first to flag the incident publicly, reporting roughly $49 billion in face-value SAND minted across more than 400 transactions while the attack was still active. PeckShield tagged two attacker-controlled addresses that received 14.9 billion SAND in the first visible wave.
On-chain reconstruction later put the total mint at 329.24 trillion SAND across 703 events distributed to 173 addresses, all inside a window that opened at 23:42:05 UTC on August 21 and closed at 04:45:21 UTC on August 22.
Real losses versus paper losses
Despite the headline figures, the settled economic damage was modest. The Ethereum SAND OFT adapter drained from 14,769,723 SAND to effectively zero across 15 events, with roughly 14 million SAND rotated through one externally owned account inside a 24-second window characteristic of an automated withdrawal script.
At SAND’s spot price near $0.045, that translates to roughly $665,000 in real value, alongside an additional take of around 80 ETH.
The SAND multisig zeroed out the trusted LayerZero peers for the Ethereum and Base endpoint IDs at 05:09:19 UTC on August 22, cutting the cross-chain messaging path between the two adapters and stranding any unredeemed Base balances on that network. The Ethereum mainnet totalSupply for SAND still returns exactly 3,000,000,000 tokens, unchanged from contract inception.
The Sandbox response
In a statement posted on X, The Sandbox said it had identified and fully contained the vulnerability, and that the impact represents less than 0.01% of the total SAND supply. The team confirmed that no user wallets were compromised, that SAND on Ethereum and Polygon was never at risk, and that the reserve backing all bridged SAND on Ethereum remains intact.
Bridging to and from Base and BSC has been disabled, users have been told not to trade SAND on either network, and a pre-incident snapshot is being used to prepare compensation for eligible liquidity providers. A full post-mortem has been promised, though no timeline has been given for the restoration of bridge functionality.
Neither Animoca Brands, which took majority control of The Sandbox in September 2025, nor the team behind the previously announced SANDChain layer-2 has commented on the Korean exchange designations.
Price and derivative reaction
Spot SAND has been comparatively orderly given the scale of the paper mint. The token dropped between 5.5% and 10% depending on venue in the hours following disclosure, with CoinGecko marking a market capitalisation near $113.7 million against the intact 2.9 billion circulating supply.
Derivatives told a different story. Open interest in SAND futures rose approximately 16% within an hour of the news breaking, spot volume spiked to roughly 24 times its recent baseline, and funding rates flipped sharply negative, indicating aggressive short positioning against the possibility that inflated Base balances find a route to liquid venues before the multisig containment is stress-tested.
The Korean delisting playbook
Upbit’s designation sequence for SAND now mirrors two recent cases that ended in trading termination. The exchange used the same framework to delist BONK on September 7 following the $20 million Bonk DAO hack, and to terminate Loopring’s KRW pair in March 2026 after a January caution designation.
In both cases, the exchange moved from suspected security or disclosure failure to warning designation within days, and from warning designation to termination within roughly a month.
The framework itself became more consequential in June when the Financial Services Commission classified exchanges serving more than 11 million users as critical public infrastructure, a designation that underpins ongoing proposals for ownership restructuring at Upbit and Bithumb and for bank-level, no-fault compensation duties on virtual asset service providers.
A third LayerZero OFT incident in five months
The SAND exploit is the third notable LayerZero OFT peer or delegate abuse of 2026. In April, an attacker minted 116,500 rsETH on Ethereum against a forged LayerZero packet in the KelpDAO exploit. In May, a compromised deployer key was used to reset the trusted peer on StakeDAO’s vsdCRV OFT and mint 5.4 trillion tokens on Arbitrum for a real take of around $91,000.
Weaponising approveAndCall to hijack a LayerZero delegate is not a vulnerability in the LayerZero protocol itself. It sits inside the class of application-level configuration failures the protocol operator has consistently characterised as OApp responsibility.
Whether the SAND delegate was seized through a low-privilege call path or through direct compromise of a deployer or delegate key remains unresolved, and it is a distinction that will materially shape the conclusions of both the Upbit and Bithumb reviews.
The five-week question
Blockaid’s H1 2026 Onchain Security Report put verified exploit losses for the first half of the year at $1.1 billion across 212 incidents, with private key and infrastructure compromises accounting for close to three-quarters of the total and cross-chain bridge failures leading the categorical damage. The SAND incident pushes the running 2026 total above $1.2 billion.
For the next five weeks, the practical questions for the market are whether The Sandbox and LayerZero can definitively account for how the delegate was seized, whether the compensation plan for liquidity providers is executed before the reviews conclude, and whether the multisig’s peer-zeroing action holds cleanly enough to prevent any second-wave attempt. The answers will decide whether SAND retains its Korean won pairs, or joins BONK and Loopring on the list of tokens that failed to clear the same review.
Also Read: Phantom to Drop Sui Network on Sept 24: Migration Window Opens for Holders