SAND Cross-Chain Bridge Exploit Yields Fake Tokens Worth $49 Billion
A significant exploit occurred on August 22 in The Sandbox's SAND cross-chain bridge, which connects Base and BNB Smart Chain. Hackers took advantage of a vulnerability in the LayerZero delegate permissions to mint unbacked versions of the SAND token, resulting in an astonishing $49 billion face value. However, this figure is largely smoke, as it represents tokens without real assets locked on Ethereum.
According to Blockaid, attackers hijacked the LayerZero delegate permissions through an approveAndCall function on SAND's omnichain fungible token contract on Base. This allowed them to create SAND where it shouldn't have existed, but they didn't need to break Ethereum SAND itself.
The real drain appears to be much smaller, with approximately 14.75 million Ethereum-backed SAND leaving the bridge adapter in under a minute, resulting in around $675,000 worth of sales at the time. The Sandbox has identified and contained the vulnerability, switched off bridging to and from Base and BNB Smart Chain, and isolated the SAND on those networks.
The incident highlights the risks associated with cross-chain bridges, which can create a mountain of fake balances on one network while allowing a smaller but very real drain from the reserve that backs the system. The Sandbox has promised a full incident report and technical postmortem to help prevent similar incidents in the future.