On August 22, 2026, attackers exploited The Sandbox’s LayerZero powered SAND bridge on Base and BNB Smart Chain to mint unbacked tokens. Blockaid said the attackers hijacked LayerZero delegate permissions through approveAndCall, enabling repeated unauthorized mints across more than 400 transactions.
Research answer

Create a landscape editorial hero image for this Studio Global article: What happened in The Sandbox’s SAND token bridge exploit—including how attackers used LayerZero’s approveAndCall delegate-permission vulnera. Article summary: On August 22, The Sandbox’s LayerZero-powered SAND bridge on Base and BNB Smart Chain was exploited to create unbacked SAND. The incident was contained, but the headline “$49 billion” figure refers to the notional value . Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fa
The Sandbox contained a vulnerability in its SAND cross-chain bridge on August 22, 2026, after attackers used compromised LayerZero delegate permissions to mint unbacked SAND on Base and BNB Smart Chain. The incident produced a striking headline—nearly $49 billion in face-value tokens—but that number should not be confused with money stolen or successfully extracted.
The affected system was The Sandbox’s LayerZero-powered SAND Omnichain Fungible Token deployment on Base and BNB Smart Chain. According to Blockaid, attackers abused the approveAndCall function to hijack delegate permissions associated with the bridge. That authority allowed them to carry out repeated unauthorized minting of the cross-chain SAND representation.
This was a token-issuance failure, rather than a reported compromise of individual user wallets. The exploit was limited to the Base and BNB Smart Chain deployments; The Sandbox said SAND on Ethereum and Polygon was not affected.
Blockaid reported approximately $49 billion in face-value SAND minted across more than 400 transactions. “Face value” applies the market price to the quantity of tokens created; it does not show that the attacker could sell all those tokens at that price.
A newly minted token can have a large quoted value while having insufficient liquidity to support meaningful sales. Once the exploit was detected, bridge shutdowns, exchange restrictions, liquidity fragmentation and the loss of market confidence further limited the amount that could potentially be realized.
Other on-chain reporting cited approximately 14.9 billion SAND at attacker-controlled addresses, while a separate report estimated that the amount actually extracted was far smaller than the headline minting figure. These numbers measure different things—minted supply, wallet balances and realized or potentially realized proceeds—so they should not be treated as interchangeable loss estimates.
The available evidence does not establish a single final, independently verified extraction total. The safest conclusion is that the unauthorized issuance was enormous in nominal terms, while the economic loss was substantially smaller than $49 billion.
The Sandbox described the direct impact as less than 0.01% of SAND’s 3 billion-token supply. Security firms and on-chain analysts, by contrast, highlighted the quantity of unauthorized tokens minted or held by attacker-controlled addresses.
Those statements are not necessarily measuring the same outcome:
Until The Sandbox publishes its post-mortem and a fuller accounting, the figures should be presented as competing measurements of the incident—not as one reconciled damage total.
The Sandbox said it fixed and contained the vulnerability, blocked transfers through the affected cross-chain bridges and disabled bridging involving Base and BNB Smart Chain. It also said Ethereum and Polygon SAND remained unaffected.
The project indicated that it would snapshot affected liquidity positions, address eligible liquidity providers and publish a detailed post-mortem. At the time covered by the available reporting, final compensation rules, eligibility criteria and payment amounts had not been established publicly.
Users should therefore distinguish between the immediate containment measures and any later recovery or compensation plan. Bridge functionality being paused prevents further use of the reported exploit path; it does not, by itself, resolve the value of tokens already minted or losses suffered by liquidity providers.
The incident triggered precautionary measures from South Korean exchanges. Bithumb suspended SAND deposits and withdrawals, while Upbit issued a trading caution because of abnormal on-chain activity and the possibility of increased volatility.
Some reports described SAND’s market price as comparatively resilient during the incident rather than collapsing. That market reaction does not prove that the exploit was economically harmless: exchange controls and thin or isolated liquidity can delay price discovery, while the longer-term effect depends on how the unauthorized tokens and affected pools are handled.
The SAND incident and the April 18 KelpDAO exploit both involved applications built with LayerZero-based cross-chain infrastructure, but the reported failure modes were different.
In the KelpDAO case, attackers compromised infrastructure used by a LayerZero Decentralized Verifier Network and exploited a single-verifier configuration. The resulting forged cross-chain message caused the bridge to release 116,500 rsETH, valued at approximately $292 million at the time. LayerZero described the incident as isolated to KelpDAO’s rsETH configuration.
The SAND event instead centered on delegated contract permissions and the abuse of approveAndCall to enable unauthorized token minting. That distinction matters: the two incidents show different risks in cross-chain deployments—verification infrastructure on one side and contract authorization or permission design on the other—but the available evidence does not show that one identical LayerZero protocol bug caused both attacks.
The most important distinction is between tokens created, tokens held, and value actually extracted. A bridge can fail in a way that creates a huge nominal supply without producing an equivalent amount of spendable proceeds for the attacker. Conversely, a smaller-looking issuance event can still damage liquidity providers and market confidence if it releases or drains valuable assets.
For users, the practical questions are which chain and contract were affected, whether deposits and withdrawals remain paused, and whether a project has published eligibility and recovery rules. For developers, the incident reinforces the need to scrutinize every delegated permission, privileged minting path and cross-chain authorization boundary—not only the message-verification layer.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
On August 22, 2026, attackers exploited The Sandbox’s LayerZero powered SAND bridge on Base and BNB Smart Chain to mint unbacked tokens.
On August 22, 2026, attackers exploited The Sandbox’s LayerZero powered SAND bridge on Base and BNB Smart Chain to mint unbacked tokens. Blockaid said the attackers hijacked LayerZero delegate permissions through approveAndCall, enabling repeated unauthorized mints across more than 400 transactions.
Base and BNB Smart Chain bridging was disabled, while Ethereum and Polygon deployments were reported unaffected.