An attacker hijacked LayerZero delegate permissions through The Sandbox's SAND token contract on Base, minting 329.24 trillion unbacked SAND over five hours. The notional face value hit $49 billion, but liquidity constraints limited the actual theft to roughly $675,000 drained from the Ethereum vault in under 60 seconds.
The gap between those two numbers tells the real story of the Aug. 21-22, 2026 exploit. The attacker minted 329.24 trillion unbacked SAND across 703 separate events over about five hours on Base, with secondary exposure on BNB Smart Chain. Ethereum and Polygon, where most of SAND's legitimate supply sits, were never touched.
How the approveAndCall exploit worked
The flaw sat inside approveAndCall, a function on SAND's omnichain fungible token contract on Base. A dormant address, inactive for 313 days before the attack, routed a crafted payload through that function to hijack the LayerZero delegate permissions governing the bridge. Once in control of the delegate, the attacker could authorize mints on Base without any matching burn on the source chain. The Sandbox's post-mortem stressed that no private keys were compromised — the flaw was a configuration problem in the contract structure, not stolen credentials.
The $49 billion illusion versus $675,000 reality
Security firm Blockaid attached a $49 billion face value to the minted tokens, a figure reached by multiplying the mint count by SAND's market price. But the trillions minted on Base had no path to liquidity. Bridging was disabled before any meaningful redemption, and Base's pools held nowhere near enough paired assets to absorb the supply. The attacker instead drained about 14.75 million SAND from the Ethereum OFT Adapter in under 60 seconds, converting it into roughly 80 ETH, worth about $675,000. An arbitrage bot disrupted the plan mid-attack, cutting the intended haul.
The Sandbox shuts down the bridge
The Sandbox disabled bridging on Base and BNB Smart Chain within hours of PeckShield's initial alert and removed LayerZero peer settings via multisig governance. The team said the impact came to less than 0.01% of SAND's 3 billion maximum supply. Still, Korean exchanges Upbit and Bithumb suspended SAND deposits and withdrawals under South Korea's Virtual Asset User Protection Act, and Coinbase delisted SAND perpetual futures. SAND's price fell nearly 10% intraday before recovering most of the drop within 24 hours.
Reimbursement and a wider bridge problem
The Sandbox announced a 1:1 reimbursement plan funded from its treasury on Aug. 27, covering the roughly 14.7 million SAND lost, with no new tokens minted and a claims portal expected within two weeks. The exploit marked the third major LayerZero-related bridge failure in five months, following the Kelp DAO and Stake DAO incidents. It has accelerated a $15 billion migration from LayerZero to Chainlink CCIP, led by BitGo's move of $7.4 billion in WBTC, with Mantle and Lombard among other participants.
Source: crypto.news
Trading involves risk.