The Sandbox Bridge Exploit: Fake Tokens Flood In
A major exploit in The Sandbox's (SAND) cross-chain bridge resulted in an attacker minting over $49 billion worth of fake SAND tokens on August 22, 2026. However, this number is largely fictional, and the actual loss was significantly lower.
The attack used a bug tied to The Sandbox's omnichain token setup, allowing the attacker to mint unbacked SAND tokens on Base and BNB Smart Chain without matching collateral locked on Ethereum. The hacker's route involved hijacked LayerZero delegate permissions, which should not have been accepted by the bridge.
The attack was quickly noticed, and The Sandbox halted bridging between Base and BNB Smart Chain, advising users not to buy, sell, or trade SAND on either network. Importantly, no user wallets were compromised in the incident.
Despite the initial $49 billion figure, the actual extraction was around 14.75 million SAND tokens from the Ethereum OFT adapter, converted into roughly 79.74 ETH (approximately $675,000 at the time of the transactions). This represents less than 0.01% of SAND's total token supply.