Sandbox Suffers 14.7 Million Token Loss in Bridge Exploit
The Sandbox has confirmed that it was hit by a security exploit, resulting in the loss of approximately 14.7 million SAND tokens from its Ethereum vault.
This is significantly more than initially reported, with the studio stating that the actual loss is around 0.5% of the total supply, rather than the previously mentioned 0.01%. The revised figure was determined through a forensic review and reflects the studio's commitment to transparency.
The exploit occurred due to weaknesses in the LayerZero bridge on Base and BNB Chain, which allowed an attacker to mint tokens without authorization.
The SAND token is deployed as a dual-purpose contract that serves both as a standard for the LayerZero bridge and as a utility token. The attacker was able to abuse a configuration function to install themselves as the only verifier for inbound bridge messages, allowing them to rubber-stamp their own transactions and mint unbacked SAND on Base and BNB Chain.
The studio has taken steps to contain the damage, including halting bridging to Base and BNB Chain and flagging the attacker's wallet with TRM Labs and Chainalysis. It also captured a snapshot of the tokens before the incident, which will be used to compensate affected users in liquidity pools.