A wallet address that had been dormant for 313 days suddenly sprang to life on the night of August 21, 2026, minting 329.24 trillion SAND tokens within five hours. A configuration flaw in the LayerZero bridge connecting the Base and BNB Smart Chain networks served as the entry point for the exploit, with security firm PeckShield being the first to detect it.
The attacker exploited the `approveAndCall` function in the SAND OFT token contract to hijack LayerZero delegation permissions. This maneuver enabled them to mint new tokens without burning the corresponding assets on the source chain. Across 703 separate minting events, the perpetrator generated a stockpile of assets with a nominal paper value exceeding $49 billion at market prices at the time.
Trapped by Market Liquidity
That multi-billion-dollar figure was merely an illusion. The entire haul of trillions of tokens minted on the Base network was effectively worthless, as it could not be liquidated due to the complete lack of market liquidity to absorb such massive supply.
The attacker then pivoted to extract real cash. Through the Ethereum OFT Adapter, the perpetrator scooped up 14.75 million SAND in under 60 seconds. They subsequently dumped the stolen assets into liquidity pools across 26 transactions, each designed to drain 90% of the available ETH pool, ultimately securing 80 ETH worth approximately $675,000.
Pre-attack reconnaissance proved precise. The perpetrator targeted minting 14,743,364.21 SAND - an amount deliberately set exactly 100 tokens below the Ethereum vault balance limit at the time. However, the execution fell short due to front-running arbitrage bots that trimmed the attacker’s net haul to 14,095,483.66 SAND. The Sandbox team stated that the stolen amount accounted for less than 0.01% of the token’s total maximum supply of 3 billion.
Revoking Cross-Chain Access
The Sandbox team disabled the bridge functionality to Base and BNB Smart Chain at the contract level. The developers also removed LayerZero peer connection configurations using multisig access. Follow-up investigations confirmed that the vulnerability stemmed purely from operational contract architecture design rather than any compromise of the project’s private keys.
The fallout from the bridge exploit reached regional exchanges. Two South Korean trading platforms, Upbit and Bithumb, suspended deposits and withdrawals for SAND on August 22 to prevent the influx of illicit tokens.
For investors holding authentic tokens, funds remain safe. The SAND token ecosystem on the Polygon network and all locked deposits on Ethereum were confirmed to be intact and unaffected by the exploit.
Source: crypto.news.
Read also: Russian Network Uses ChatGPT to Build Fake Academic Institute - 34 Studies Turn Out to Be Copies
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




