NewsCryptoThe Sandbox's SAND Rallies as Suspected Mint Attack Adds Over 500 Million Tokens

The Sandbox's SAND Rallies as Suspected Mint Attack Adds Over 500 Million Tokens

Author: Cryptopolitan·

Key Takeaways

  • More than 500 million SAND tokens, equal to at least 16.7% of the 3 billion maximum supply, were minted in the suspected breach on Base, where the affected contract previously held only about 14.699 million tokens.
  • Lookonchain described the incident as an "infinite mint attack" and reported that the suspected exploit remained active on August 22, 2026, with the linked wallet having executed 302 transactions as of 05:23:10 UTC.
  • Upbit advised traders to treat SAND with special caution, and both Upbit and Bithumb restricted SAND deposits and withdrawals without halting operations.
  • Despite the exchange warnings, SAND rose more than 19% over the past seven days and recorded $87 million in 24-hour trading volume.
  • The Sandbox has not issued an official statement, and key questions—including how minting rights were obtained and where the newly created tokens moved—remain unanswered.
The Sandbox's SAND Rallies as Suspected Mint Attack Adds Over 500 Million Tokens

A suspected security breach involving SAND — the utility token of The Sandbox, a blockchain-based virtual gaming world — has unsettled traders after on-chain researchers flagged the creation of several hundred million new tokens. On August 22, 2026, South Korean exchange Upbit cautioned traders to treat SAND with "special caution," citing indications of security problems and potential price fluctuations (Upbit notice).

Despite the warning, SAND has continued to post gains. The token has surged by more than 19% over the past seven days, and its 24-hour trading volume stood at $87 million.

The central concern, however, is supply. On-chain analytics firm Lookonchain reported that more than 500 million new SAND were created during the incident — equivalent to at least 16.7% of the token's maximum supply of 3 billion. A snapshot from BaseScan, the block explorer for Base — the Ethereum layer-2 network where the affected contract operates — shows the Base contract held a total supply of just 14.699 million SAND, meaning the new mint exceeded the chain's previous total supply by more than 34 times.

When new tokens are created without corresponding market demand, existing holders can be diluted — particularly if the newly minted tokens reach exchanges. The risk also extends beyond SAND itself: sudden supply shocks can erode trust in other utility tokens traded on exchanges when major platforms notify customers of a problem.

Upbit announced the situation and advised token holders to prepare for the possibility of increased volatility. The exchange did not halt operations, but both Upbit and fellow South Korean exchange Bithumb placed restrictions on SAND deposits and withdrawals.

What on-chain sleuths say happened

According to Lookonchain, SAND on Base may contain a serious loophole that could let attackers mint tokens at any time. The on-chain monitoring firm described the event as an "infinite mint attack" — a scenario in which minting permissions are compromised, enabling tokens to be minted without limits.

The Base SAND contract is 0xac531Eb26Ca1d21b85126De8FB87E80E09002DcF, while the address linked to the suspected unauthorized minting is 0x67624BFadee937c9281B4f98Ce18aF1bee01257e.

On August 22, Lookonchain announced that more than 500 million SAND had been minted and that the suspected attack was still active. According to BaseScan, the wallet in question had executed 302 transactions as of 05:23:10 UTC.

Many questions remain unanswered. As of the time of writing, The Sandbox has not issued an official statement on the episode, the reasons behind the incident, how the attacker obtained minting rights, or what happened to the new tokens. BaseScan exposed the wallet summary, but attempts to open individual transaction details encountered a bot-protection screen. As a result, no exploit-specific transaction hash is included, rather than relying on an unverified repost.

The market has seen this movie before

Crypto traders have witnessed similar supply shocks in the past. In May 2024, Blockchain Game Partners Inc. — the company behind Gala Games — said a compromised minter key allowed a malicious contractor to create 5 billion GALA tokens on Ethereum (incident report). The company said it stopped the incident before blocklisting the wallet and burning the supply.

More recently, Cryptopolitan reported that Harmony, a layer-1 blockchain, rolled back its network to reverse the effects of a roughly 4 billion ONE mint of its native token — equal to about 26% of the token's supply — after an attacker exploited a cross-shard flaw (coverage). ONE fell following the mint.

Those cases illustrate the two outcomes SAND holders are now weighing: whether The Sandbox can neutralize the unauthorized supply, or whether the market reprices the token before that happens.

What to watch next

The next signals to monitor are an official statement from The Sandbox, confirmation of the final amount minted, evidence showing where the new tokens moved, and whether more exchanges move to restrict SAND.

The incident also comes during an active year for crypto exploits. Global Ledger counted 224 publicly disclosed hacks totaling about $1.32 billion in losses during the first half of 2026. It also found that incidents are now being disclosed roughly twice as quickly as a year earlier, helping explain why exchange warnings can reach traders within hours of an emerging breach.