Sandbox Bridge Exploit Creates Fake Tokens Worth Nearly $700 Million
The Sandbox's cross-chain bridge was exploited on Saturday, allowing an attacker to mint nearly $700 million in fake SAND tokens. However, the actual loss was much lower, around $665,000.
The attacker used a function called approveAndCall to bypass checks and create unbacked tokens. The tokens were then drained from the Ethereum side of the bridge, where they were converted into 80 ETH worth around $675,000.
The team has confirmed that the exploit was contained within six hours and no user wallets were compromised. Exchanges such as Bithumb and Upbit have frozen SAND deposits and withdrawals, while Coinbase is delisting SAND futures on August 26.
LayerZero's delegate role was compromised, allowing the attacker to mint tokens on the Base deployment. This is not an isolated incident, with at least three previous incidents involving LayerZero delegates and peer abuse.