A bridge configuration flaw on Base and BNB Smart Chain let attackers hijack LayerZero delegate permissions, mint trillions of phantom SAND tokens, and drain roughly $675,000 from the Ethereum vault before the team shut everything down.
The Sandbox has pledged to reimburse eligible SAND holders 1:1 after an Aug. 21 bridge exploit drained about 14.7 million tokens worth roughly $700,000 from an Ethereum vault. According to The Sandbox's Aug.
An attacker weaponized a single ERC-20 function to hijack LayerZero delegate permissions and mint 329 trillion unbacked SAND on Base, yet the actual reserve drain totaled just $675,000, exposing both the fragility and the hidden safeguards of cross-chain token architecture.
An attack on The Sandbox's cross-chain bridge created unbacked SAND tokens on Base and BNB Smart Chain on August 22, 2026. Bridging is halted; holdings on Ethereum and Polygon are unaffected, according to the studio.
On August 22, 2026, a security breach granted an unauthorized party unrestricted minting capabilities on The Sandbox's SAND smart contract operating on Base, which utilizes Layer Zero's Omnichain Fungible Token framework for multi-chain token transfers.
Sandbox team said the exploit was only isolated to Base and BSC networks and has been contained.
The Sandbox disabled SAND bridging on Base and BNB Chain after an attacker minted unbacked tokens, while Ethereum and Polygon remained unaffected.
The Sandbox has contained a cross-chain bridge vulnerability that allowed an attacker to mint unbacked SAND on Base and BNB Smart Chain, with the project estimating the direct impact at less than 0.01% of the token's 3 billion supply.
Analyzing why Sandbox was the highest gainer among other gaming tokens.