The Sandbox halted bridging between its Ethereum mainnet and Base and BNB Smart Chain after an attacker exploited an "approveAndCall" function to mint unbacked SAND tokens across both networks. Blockchain security firm Blockaid, which flagged the attack while it was in progress, said the attacker hijacked LayerZero delegate permissions and minted tokens with a nominal face value of roughly $49 billion across more than 400 transactions. The company said the impact was under 0.01% of SAND's 3 billion token supply, equivalent to fewer than 300,000 SAND, and that no user wallets were compromised.
Why it matters
The $49 billion figure is the headline-grabbing number, but it is nominal: it applies SAND's market price to tokens created without any backing, which far exceeds the actual liquidity available to sell them. PeckShield separately tallied 14.9 billion SAND minted across two addresses, another nominal calculation taken at a different stage of the incident. What matters operationally is the mechanism. A hijacked delegate permission on a cross-chain bridge is the same shape of vulnerability that has drained hundreds of millions from other protocols in past cycles, and it is why The Sandbox moved to freeze bridging rather than try to recover the tokens.
Market impact
SAND saw a near 10% intraday plunge when the exploit surfaced before recovering most of the move, leaving the token down just 0.8% over 24 hours. South Korean exchanges Bithumb and Upbit suspended SAND deposits and withdrawals after citing suspected security issues, a move that can throttle liquidity for Asian-hours traders even when the spot price recovers. The Sandbox said SAND on Ethereum and Polygon was unaffected and that collateral locked on Ethereum to back-bridge tokens remains intact. The network is taking a pre-incident snapshot to compensate qualifying liquidity providers and has promised a technical post-mortem.
Frequently asked questions
-
What happened to The Sandbox?
The Sandbox halted bridging on Base and BNB Smart Chain after an attacker exploited an "approveAndCall" function to mint unbacked SAND tokens across both networks.
-
How much was actually lost in the Sandbox exploit?
The $49 billion figure is the nominal face value of tokens created without any backing. Real supply impact was under 0.01% of SAND's 3 billion token supply, fewer than 300,000 SAND, and no user wallets were compromised.
-
Why is the $49B headline figure misleading?
It applies SAND's market price to tokens created without backing, which far exceeds any liquidity available to sell them. PeckShield separately counted 14.9 billion SAND minted across two addresses, also a nominal calculation taken at a different stage.
-
Which exchanges suspended SAND after the exploit?
South Korean exchanges Bithumb and Upbit suspended SAND deposits and withdrawals after citing suspected security issues, a move that can throttle liquidity for Asian-hours traders even when spot price recovers.
-
What was the exploit mechanism?
Blockaid said the attacker hijacked LayerZero delegate permissions via an "approveAndCall" function and used it to mint unbacked SAND across more than 400 transactions on Base and BNB Smart Chain.
CoinDesk