Sandbox Bridge Exploit: Trillions of Phantom Tokens Minted
An attacker exploited a configuration flaw on The Sandbox's SAND omnichain fungible token contract on Base, hijacking LayerZero delegate permissions and minting 329.24 trillion phantom SAND tokens across 703 events over five hours on August 21 and 22.
The face value of the minted tokens reached approximately $49 billion, but the actual extraction totaled roughly $675,000 drained from the Ethereum OFT Adapter in under 60 seconds.
The attacker used the `approveAndCall` function to hijack delegate permissions, gaining control over the minting process on Base. This allowed them to approve fraudulent messages without authorization, essentially becoming the sole verifier for incoming bridge messages.
The Sandbox team moved quickly to disable bridging on Base and BNB Smart Chain, removed LayerZero peer settings via multisig governance, and confirmed that SAND tokens on Ethereum and Polygon remained untouched throughout the incident.