NewsCryptoThe Sandbox Hack: Nearly $49 Billion Worth of Unbacked SAND Minted on Base

The Sandbox Hack: Nearly $49 Billion Worth of Unbacked SAND Minted on Base

Author: Tron Weekly·

Key Takeaways

  • Attackers hijacked LayerZero delegate permissions through the approveAndCall function on The Sandbox's SAND OFT contract on Base, allowing them to mint SAND without any collateral.
  • Security firms reported nearly $49 billion in face-value SAND minted across more than 400 transactions, with PeckShield counting about 14.9 billion SAND created across two wallet addresses, but this represents the value of tokens generated rather than the amount stolen.
  • Actual losses were approximately 14.75 million SAND, worth almost $675,000, from which roughly 79.74 ETH was withdrawn by the hackers.
  • Bithumb blocked SAND deposits and withdrawals, Upbit warned investors about unusual on-chain activity, and The Sandbox halted bridge functions on Base and BNB Smart Chain while stating that user wallets were not compromised.
  • The Sandbox said the vulnerability on Base and BNB Smart Chain was identified and fully contained with impact below 0.01% of total supply, Ethereum and Polygon were unaffected, and SAND's price rose 4.76% to $0.04737 with trading volume up more than 400%.
The Sandbox Hack: Nearly $49 Billion Worth of Unbacked SAND Minted on Base

The Sandbox is confronting a major security incident after attackers exploited the SAND cross-chain OFT (Omnichain Fungible Token) contract deployed by the project on the Base blockchain. The breach gave the attackers the ability to mint tokens without any collateral at all, and the incident has since raised a wave of security concerns around cross-chain bridge infrastructure.

The Sandbox is a blockchain-based virtual gaming platform, and SAND is its native token. Base, where the compromised contract was deployed, is an Ethereum layer-2 network developed by Coinbase.

On-chain data showed that the attack had been ongoing, with more than 400 transactions creating nearly $49 billion worth of tokens. That figure, however, relates to the value of the tokens generated rather than the amount stolen from the project.

Security firm Blockaid was among the first to detect the exploit:

🚨 Blockaid detected an ongoing exploit on @TheSandboxGame SAND OFT on Base. Attackers hijacked LayerZero delegate permissions via approveAndCall and minted unbacked SAND. ~$49B face-value SAND minted so far across ~400+ txs. Attack still ongoing. More details in 🧵

— Blockaid (@blockaid_), August 22, 2026 — x.com/blockaid_/status/2091016046555582891

How the Sandbox Hack Happened

According to security firm Blockaid, the hacker compromised LayerZero permissions related to SAND's OFT on the Base blockchain. OFT is the omnichain token standard used with the LayerZero interoperability protocol, one of the most widely adopted cross-chain messaging networks, which allows tokens to move across blockchains. Because new tokens on a destination chain are authorized through LayerZero messaging, control of the associated delegate permissions effectively determines who can mint — the access Blockaid says was hijacked here. By exploiting the approveAndCall function, the hacker was able to circumvent the usual checks and create new SAND without any backing.

At one point, 500 million SAND had already been minted, an amount equal to nearly 17% of the token's total 3 billion supply.

PeckShield, another blockchain security firm, separately reported that a total of about 14.9 billion SAND had been created across the two wallet addresses involved in the hack. Blockaid, for its part, put the figure at nearly $49 billion worth of SAND minted across more than 400 transactions.

#PeckShieldAlert Seems like The @TheSandboxGame ( $SAND ) got exploited. 14.9B $SAND minted across 2 addresses: 0xAbE0…4D22 & 0x638C…F296 pic.twitter.com/a5Jgym87gR

— PeckShieldAlert (@PeckShieldAlert), August 22, 2026 — x.com/PeckShieldAlert/status/2091037704314339331

The sheer magnitude of the exploit alarmed observers over the possible effect the freshly minted tokens could have on the SAND market. Cross-chain infrastructure has repeatedly ranked among the most attacked corners of the crypto industry, with bridge exploits such as Ronin and Wormhole in 2022 still counted among the largest thefts on record.

Sandbox Hack Losses Remain Limited

The frequently cited $49 billion figure cannot be considered the amount that was stolen by the hacker. The number corresponds to the market value of the tokens that were created.

Selling the tokens for that amount is impossible, because there is no sufficient collateral behind the creation of such tokens. In the event of a sale, the price of SAND would decrease drastically.

The amount actually stolen turned out to be far lower. According to reports, the hackers took approximately 14.75 million SAND, or almost $675,000 worth of tokens, from which roughly 79.74 ETH was withdrawn.

Exchanges Respond to the Sandbox Hack

Several major exchanges moved quickly to address the abnormality. Bithumb blocked deposits and withdrawals of SAND tokens, while Upbit warned investors about unusual on-chain activity. Such suspensions are a standard protective response when unbacked or exploited tokens surface on-chain, as they prevent those tokens from being converted into other assets on a liquid venue. A number of security firms, including CertiK, also reported the security flaw while investigations were still ongoing.

The Sandbox later stated that the cross-chain bridge of the SAND token on Base and BNB Smart Chain had been fixed. The project reported that the overall effect was below 0.01% of the entire SAND supply and revealed that Ethereum and Polygon were unaffected.

The Sandbox team has identified and fully contained a recent vulnerability regarding the SAND cross-chain bridge on Base and BNB Smart Chain (BSC). The impact is minimal, representing less than 0.01% of the total SAND token supply. SAND tokens on Ethereum and Polygon are NOT…

— The Sandbox (@TheSandboxGame), August 22, 2026 — x.com/TheSandboxGame/status/2091063415649251821

The team also said that user wallets were not compromised and that SAND locked up on Ethereum was not at risk. The project has halted the bridge functions on Base and BSC and warned users against purchasing, selling, and trading SAND on these networks. With the Base and BSC bridges still switched off and investigations ongoing, a fuller technical account of exactly how the LayerZero delegate permissions were compromised had yet to be published.

Even as the incident unfolded, the price of SAND continued to surge, rising 4.76% to hit $0.04737, with trading volume up by more than 400%.