Markets
BTC
ETH
SOL
XRP
BNB
ADA
DOGE
MCap
BTC
ETH
SOL
XRP
BNB
ADA
DOGE
MCap
Markets

$49 Billion of Unbacked SAND Minted Before Sandbox Froze Its Bridges

A hijacked LayerZero delegate on Base and BSC turned an approveAndCall into a mint function. Actual extraction came to about $675,000, but Upbit and Bithumb still halted SAND deposits.

By Aubrey Swanson··4 min read
$49 Billion of Unbacked SAND Minted Before Sandbox Froze Its Bridges

Key Points

  • A hijacked LayerZero delegate on Base and BSC turned an approveAndCall into a mint function.
  • Actual extraction came to about $675,000, but Upbit and Bithumb still halted SAND deposits.

The Sandbox suspended cross-chain bridging on Base and BNB Smart Chain on Friday after an attacker exploited its SAND omnichain token contract and minted billions of unbacked tokens across both networks. On-chain monitoring flagged the face value at roughly $49 billion. The actual extraction to usable wallets came in around 14.75 million SAND, or about $675,000.

The gap between those two numbers is the story.

SAND on Ethereum, where all bridged supply is collateralised, was never at risk. Every additional token the attacker created on Base and BSC sat on chains whose bridge The Sandbox promptly cut off; none of them can be redeemed against the Ethereum reserve. What the exploit produced was a large stock of technically live but economically worthless tokens, and a smaller pool of tokens that got out into liquidity pools before the platform noticed.

Advertisement

728×90

The attack path ran through LayerZero's Omnichain Fungible Token standard, the design that lets a single token exist natively across multiple chains rather than sitting behind a lock-and-mint bridge. The attacker compromised the delegate permissions on SAND's OFT contract on Base and used the approveAndCall function to authorise the creation of tokens without corresponding locked collateral on Ethereum. Blockaid flagged the minting activity across more than 400 transactions before The Sandbox intervened.

The impact assessment from the team came in quickly: less than 0.01 per cent of the 3 billion SAND total supply, no user wallets compromised, no funds lost on Ethereum or Polygon. The Sandbox told holders on those networks that no action was required. It also warned users not to buy, sell, or trade SAND on Base or BSC, because liquidity on both chains is now backed by nothing.

South Korea's two largest exchanges did not wait for further clarification. Upbit and Bithumb halted SAND deposits and withdrawals within hours of the disclosure. That response matters because SAND is one of the more actively traded gaming tokens on Korean platforms, and any tokens that traveled from Base or BSC to a Korean order book before the freeze would represent a delivery problem the exchanges cannot easily unwind.

The Sandbox says it took a pre-incident snapshot of the affected liquidity pools and will use it as the basis for compensating qualified LPs. The platform has not published a timeline for that payout, nor for the technical post-mortem it has promised. The mechanics of the compensation will depend on which pools were snapshotted, at what block, and how the platform intends to treat LP positions that were partially drained before the halt.

There is nothing novel about the underlying failure mode. Cross-chain bridges, including the Wormhole bridge that lost $320 million on Solana in 2022, the Ronin bridge exploit that cost Axie Infinity $625 million, and the Multichain collapse that stranded $126 million in user funds, remain the most consistently exploited primitive in DeFi. The OFT design was supposed to reduce that exposure by removing the need for a separate custody contract. In practice it moves the trust surface onto delegate permissions and the functions that manipulate them, which is exactly where this exploit lived.

For The Sandbox, the operational damage is contained. For Base, the reputational cost is harder to price. Coinbase's layer-2 has spent two years positioning itself as the mainstream-friendly rollup for onchain consumer applications, and gaming tokens are precisely the kind of asset it wants to attract. An exploit that produced an on-paper mint bigger than the entire token supply, on a bridge sitting on top of Base, is not the sort of headline the chain benefits from.

LayerZero has not publicly commented on the incident. The company's OFT standard is deployed across dozens of tokens on hundreds of chain pairs, and none of the disclosures so far suggest a vulnerability in LayerZero's own messaging layer. The attack pivoted on how The Sandbox configured its delegate permissions and how the approveAndCall entry point was exposed on the Base and BSC contracts. That distinction will matter for other OFT deployments trying to work out whether they need to audit their own permission model this weekend.

The Sandbox has said the incident report and technical breakdown are coming. Until they arrive, the outstanding questions are practical ones: how the delegate keys were compromised, whether the same permission structure exists on any of the SAND contracts on other chains, and how much of the 14.75 million SAND that did leave was already inside centralised exchanges before Upbit and Bithumb pulled the plug. The gap between $49 billion and $675,000 is a lucky one. On a slower-moving team, it would not have stayed that small.

MiningPool content is intended for information and educational purposes only and does not constitute financial, investment, or legal advice.

Advertisement

728×90

Related Stories

Stay informed

Verifiable crypto journalism, delivered to your inbox.

Weekday mornings. No hype. No financial advice. Just what happened and why it matters.

No spam. Unsubscribe anytime. Read our privacy policy.