NewsCryptoThe Sandbox Exploit Minted 329 Trillion SAND, but Only $675,000 in Value Was Actually Drained

The Sandbox Exploit Minted 329 Trillion SAND, but Only $675,000 in Value Was Actually Drained

Author: CryptoMeter io·

Key Takeaways

  • •An attacker minted approximately 329.24 trillion unbacked SAND tokens on Base over about five hours on August 21-22.
  • •The exploit used the approveAndCall function to hijack LayerZero delegate permissions and authorize unauthorized minting across 703 events involving 173 wallets.
  • •Despite the nominal $49 billion figure, the attacker extracted only about $675,000 by draining 14.75 million SAND, converted to roughly 80 ETH.
  • •The Sandbox disabled cross-chain bridging involving Base and BNB Smart Chain, and reserves on Ethereum and Polygon were not compromised.
  • •The incident exposed weaknesses in cross-chain delegate and approval controls, adding to a pattern of bridge and messaging-layer exploits.
The Sandbox Exploit Minted 329 Trillion SAND, but Only $675,000 in Value Was Actually Drained

The Sandbox's SAND token suffered a major cross-chain exploit on August 21-22, during which an attacker created roughly 329.24 trillion unbacked tokens over a period of about five hours. Despite the staggering headline figure, the attacker managed to extract only about $675,000 in real economic value.

The incident illustrates the gap between token balances displayed on-chain and assets that can actually be redeemed or sold. The 329 trillion SAND created in the attack carried a nominal value of roughly $49 billion, but most of those tokens had no corresponding reserves backing them.

How the SAND exploit unfolded

The attacker targeted the Base deployment of SAND, exploiting its LayerZero omnichain configuration. LayerZero is a widely used interoperability protocol that lets tokens move across chains through Omnichain Fungible Token (OFT) adapters, which rely on delegate permissions to govern cross-chain actions. Investigators determined that the token's approveAndCall function was used to hijack LayerZero delegate permissions.

With that access, the attacker gained the ability to authorize unauthorized minting on Base. The resulting activity generated 329.24 trillion SAND across 703 minting events involving 173 wallets.

The legitimate SAND supply on Ethereum remained capped at 3 billion tokens, meaning the newly created Base tokens were effectively unbacked and could not simply be redeemed against the Ethereum reserves.

The key figure was what actually left the reserves

Although the headline mint appeared catastrophic, the attacker's actual extraction was far smaller. Approximately 14.75 million SAND was drained from the Ethereum-side OFT adapter and converted into roughly 80 ETH, worth about $675,000 at the time of the attack.

In response, The Sandbox disabled cross-chain bridging involving Base and BNB Smart Chain. According to available incident reporting, reserves on Ethereum and Polygon were not compromised.

The exploit demonstrates why a token's apparent market value can be misleading during a smart-contract attack. Multiplying a legitimate market price by an enormous quantity of newly minted tokens does not mean that amount of liquidity actually exists.

Cross-chain infrastructure has repeatedly been a focal point for large crypto losses in past years, and this incident adds to a pattern of exploits centered on bridge and messaging-layer configurations rather than the underlying token contracts themselves. What remains to be seen is how quickly The Sandbox and other projects using omnichain token setups audit and tighten delegate and approval controls before re-enabling bridging.

For The Sandbox, the immediate financial loss was therefore measured in hundreds of thousands of dollars rather than tens of billions. Nevertheless, the incident exposed serious weaknesses in cross-chain permission controls and raised fresh concerns about the security of token bridge infrastructure.