NewsCryptoSandbox Exploit Created $49B in Unbacked SAND Nobody Could Cash Out

Sandbox Exploit Created $49B in Unbacked SAND Nobody Could Cash Out

Author: Coindoo·

Key Takeaways

  • Blockaid detected the attack after an approveAndCall route was used to hijack LayerZero delegate permissions tied to The Sandbox’s SAND OFT on Base.
  • The $49 billion figure reflected unbacked token balances multiplied by market price, not cash or redeemable collateral.
  • Independent tracking indicates about 14.75 million SAND, worth roughly $675,000 at the time, left legitimate reserves before containment, along with about 79.74 ETH converted during the attack.
  • The Sandbox said SAND on Ethereum and Polygon was not affected, no user wallets were compromised, and cross-chain transfers for SAND on Base and BNB Chain were disabled.
  • The project said it has secured a pre-incident snapshot and is preparing compensation measures for eligible liquidity providers.
Sandbox Exploit Created $49B in Unbacked SAND Nobody Could Cash Out

An exploit of The Sandbox's cross-chain bridge infrastructure produced roughly $49 billion in face-value SAND that could not be cashed out, according to blockchain security firm Blockaid, which detected the ongoing attack on August 22, 2026. Independent on-chain tracking indicates that only about $675,000 in backed assets appears to have left legitimate reserves before the bridge was shut down, making the reserve drain — not the headline figure — the true measure of the incident's cost. The Sandbox is a virtual gaming world where SAND, its Ethereum-based token, is used to buy land and in-game assets, and the compromised routes ran through the versions of that token on Base, the Ethereum layer-2 network developed by Coinbase, and BNB Chain.

What the $49B Figure Actually Measured

The $49 billion valuation came from multiplying the market price of legitimate SAND by token balances created without any backing. Blockchain trackers could display $49 billion because they had two inputs: a token price and an enormous token balance. They did not have $49 billion in collateral, buyers, or redeemable assets behind those balances.

The money trail is much smaller and far more important. Independent on-chain tracking indicates that roughly 14.75 million SAND, valued near $675,000 at the time, left legitimate bridge reserves before the response. Around 79.74 ETH was also converted during the attack. That is the part of the event with an actual economic cost — not the inflated number attached to an unbacked supply.

How a Price Feed Turned a Broken Mint into a $49B Headline

Blockaid said the attacker hijacked LayerZero delegate permissions tied to the SAND Omnichannel Fungible Token (OFT) on Base through an approveAndCall route. From there, the attacker could mint SAND without the normal backing on Ethereum.

🚨 Blockaid detected an ongoing exploit on @TheSandboxGame SAND OFT on Base. Attackers hijacked LayerZero delegate permissions via approveAndCall and minted unbacked SAND. ~$49B face-value SAND minted so far across ~400+ txs. Attack still ongoing. More details in 🧵

Blockaid (@blockaid_), August 22, 2026

A cross-chain token is supposed to preserve one simple relationship: a token created on one network must correspond to an equivalent token locked, burned, or otherwise accounted for on another. That is what stops a bridge from turning one asset into several competing claims on the same collateral. Cross-chain infrastructure has produced some of the largest losses in crypto's history — the Ronin Network breach drained more than $600 million in 2022, and the Wormhole exploit that same year took roughly $320 million — because bridges and their underlying messaging layers are where claims on assets held elsewhere get processed.

The attack severed that relationship. New SAND appeared on the affected networks without a matching reduction or reserve arrangement on Ethereum. Explorers then treated the balances as ordinary SAND and applied the prevailing market price. The calculation was mechanically correct; economically, it was nonsense.

A wallet can show a billion-dollar token balance and still be unable to turn it into meaningful money. The attacker did not control a pool with $49 billion waiting to buy SAND, nor could that volume have been sold at the quoted price without overwhelming every available market. The inflated balances were a threat because they could be exchanged against limited pools of genuine assets — not because the headline valuation was ever available to withdraw.

The Attack Was About Access to the Bridge's Exit Liquidity

Minting the unbacked tokens was only the first step. The useful part of the attack was the period before the bridge and related liquidity could be shut down, when those balances could still be swapped for assets with real backing.

That is where the estimate of roughly $675,000 comes from. On-chain reporting indicates that around 14.75 million SAND left the Ethereum OFT adapter, with part of the proceeds converted into ETH. Those assets came from legitimate reserves. Unlike the artificial Base-side balances, they had an established market and could be moved outside the compromised route.

The gap between the two numbers is the clearest way to read the exploit. The $49 billion face-value figure was more than 70,000 times larger than the estimated reserve drain. One measures the size of the false claim created on-chain; the other measures the value that appears to have escaped the system.

That also explains why liquidity providers are at the centre of the recovery. An unbacked token becomes someone else's loss only when it reaches a pool containing genuine SAND, ETH, stablecoins, or other assets. The fake balance is the weapon; the liquidity pool is where it can do financial damage.

The Emergency Response Ring-Fenced the Inflated Supply

The Sandbox said it had contained the vulnerability affecting its cross-chain bridge on Base and BNB Chain. It disabled cross-chain functionality for SAND on both networks, leaving the affected balances isolated and unable to move or be redeemed through the bridge.

The team said SAND on Ethereum and Polygon was not affected, no user wallets had been compromised, and holders on those networks did not need to take action. It also warned users not to buy, sell, or trade SAND on Base or BNB Chain while liquidity there remains compromised.

That response is why the project can describe the impact as less than 0.01% of the legitimate SAND supply while researchers tracked an enormous quantity of unbacked tokens. The statement is not saying that only a tiny amount of false SAND was minted. It is saying that the impact on recognised supply and backed reserves was limited once the bridge routes were cut.

Containment, however, is not the same as a final loss report. It tells holders that the known path has been closed. It does not yet establish the full reserve drain, identify every affected pool, or show how the project will restore the liquidity damaged during the attack.

Permission Failure First, LayerZero Verdict Later

The available evidence points to delegate permissions associated with The Sandbox's OFT deployment being abused. That is not the same as proving a protocol-wide vulnerability in LayerZero itself. LayerZero's OFT standard is used by a wide range of tokens to keep a single supply spread across multiple chains, which is why the application-versus-protocol distinction matters well beyond The Sandbox: a flaw in one deployment is contained, while a flaw in the shared standard would implicate every project built on it.

The root cause still matters, because several different failures could produce the same outcome: an exposed delegate key, overly broad permissions, an unsafe call path, or another configuration weakness in the application's own cross-chain setup. Blockaid identified the use of approveAndCall and the resulting delegate takeover, but The Sandbox has not yet published its promised technical report.

For that reason, the precise wording matters. "LayerZero was hacked" reaches further than the evidence currently allows. The confirmed point is narrower and more useful: an attacker obtained the authority needed to mint unbacked SAND within The Sandbox's cross-chain system.

The Post-Mortem Has a Narrow Job

The next meaningful update is not another estimate of how many trillions of tokens appeared in attacker wallets. The incident report needs to settle the questions that determine the final cost:

  • The permission failure: How did the attacker obtain or assume LayerZero delegate authority?
  • The reserve loss: What amount of legitimate SAND, ETH, and other assets left before the bridge was halted?
  • The affected pools: Which Base and BNB Chain liquidity providers absorbed the fake supply or lost backing?
  • The compensation method: Which pre-incident snapshot will be used, who qualifies, and whether reimbursement will be in SAND, stablecoins, or another asset?
  • The path to reopening: What security changes must be completed before Base and BNB Chain SAND can be bridged again?

The Sandbox says it has secured a pre-incident snapshot and is preparing compensation measures for eligible LPs. There is precedent for projects absorbing such losses: the Wormhole bridge's 2022 shortfall was replenished by its backer Jump Crypto, and Ronin's operator Sky Mavis raised funding to reimburse users. That is the right starting point, but it is not yet a completed remedy. Until the methodology is public, affected providers do not know how losses will be measured or when they will be made whole.

Ignore the $49B Ticker; Follow the Reserves

The exploit was serious because a bridge-permission failure opened a route from fabricated SAND into real liquidity. It was not a $49 billion theft, despite the number attached to the minted balances.

The figure worth following is the amount of backed value that left before the bridge was isolated, followed by the amount The Sandbox ultimately returns to affected LPs. The $49 billion headline describes what an attacker could make a price tracker display. The reserve drain and recovery plan will show what the exploit actually cost.

Sources: The Sandbox's official security update; Blockaid's initial exploit alert; and independent on-chain reporting on the estimated reserve drain. The Sandbox has said a full incident report and technical analysis will follow.