Overview
- The Sandbox disclosed the breach on Saturday, Aug. 22 and immediately cut bridge links to Base and BNB Smart Chain to isolate millions of unbacked SAND tokens and stop redemptions.
- On‑chain monitors reported as many as 14.9 billion unbacked SAND minted on Base and BSC, but forensic analysis shows about 14.75 million SAND left legitimate reserves and was converted to roughly 80 ETH, worth about $675,000.
- Security firms say the attacker appears to have gained minting authority by abusing LayerZero delegate permissions through an approveAndCall call path, though The Sandbox has not yet published a full technical post‑mortem.
- Major South Korean exchanges Upbit and Bithumb suspended transfers and placed SAND under trading caution while The Sandbox prepares a pre‑incident snapshot and a compensation plan for eligible liquidity providers.
- The incident highlights a structural risk in LayerZero’s Omnichain Fungible Token bridge model where destination‑chain mints can inflate nominal balances without backing on the origin chain and that a detailed reconciliation and post‑mortem are still pending.