< Back to situation

[REVISION HISTORY]

The Sandbox cross-chain bridge exploit

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-08-29 04:39 UTC → 2026-08-29 04:59 UTC · added removed

A security breach occurred involving The Sandbox’s cross-chain bridge on the Base and BNB Smart Chain networks. Attackers exploited a LayerZero ‘approveAndCall’ function to hijack delegate permissions, enabling the unauthorized minting of unbacked SAND tokens. While the face value of minted tokens was reported by Blockaid to reach approximately $49 billion, the actual economic impact involved the extraction of roughly 14.75 million Ethereum-backed SAND, valued at approximately $675,000. In response to the exploit, The Sandbox disabled bridging to and from the affected networks and confirmed that SAND held on Ethereum and Polygon remained secure. South Korean exchanges Upbit and Bithumb suspended SAND transactions to mitigate volatility. Following the incident, The Sandbox announced a 1:1 compensation plan for affected holders using treasury funds to ensure the total maximum supply of 3 billion tokens remains unchanged. The project decommissioned the compromised bridge contracts and reported the attacker’s addresses to TRM Labs and Chainalysis. More than 72% of the affected assets were held by Coinbase and Binance, which will facilitate direct compensation for their users, while individual wallet holders must apply through an official claim process. Recent details clarify that the exploit resulted from a configuration vulnerability in the SAND token contracts deployed on Base and BNB Chain, which allowed an attacker to register as the sole validator for bridge messages. This enabled the unauthorized withdrawal of approximately 14.74 million SAND from the Ethereum-based vault, representing roughly 0.5% of the total supply. The Sandbox intends to provide Ethereum-based SAND to eligible holders and expects the official claim page for individual wallet holders to open within two weeks of the post-mortem report's release.

Versions

  1. 2026-08-29 04:59 UTC The Sandbox cross-chain bridge exploit
  2. 2026-08-29 04:39 UTC The Sandbox cross-chain bridge exploit

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.