Particle.news
Download on the App Store

The Sandbox Bridge Exploit Mints Billions of Unbacked SAND

Security firms say a LayerZero delegate‑permissions failure let the attacker drain about 14.75 million SAND from the Ethereum adapter.

Overview

  • On August 22, on‑chain monitors and security firms flagged unauthorized minting on Base and BNB Smart Chain that created huge unbacked SAND balances.
  • The Sandbox disabled bridging to Base and BNB Smart Chain and isolated the compromised deployments to stop the fake tokens from being redeemed.
  • Independent forensics show roughly 14.75 million SAND left the Ethereum adapter and the attacker converted proceeds to about 80 ETH, making the real outflow far smaller than headline face‑value estimates.
  • Security firms including Blockaid and PeckShield point to a takeover of LayerZero delegate permissions via an approveAndCall path as the likely vector, but The Sandbox has not yet published a full technical post‑mortem.
  • The Sandbox captured a pre‑incident snapshot and says it will compensate eligible liquidity providers, though the project has not announced a final restitution method or timeline and affected Base/BSC tokens remain non‑redeemable.