Sandbox bridge exploit drains $675,000 after attackers mint 329 trillion phantom SAND tokens
An exploit on The Sandbox's SAND bridge on Base and BNB Smart Chain allowed attackers to hijack LayerZero delegate permissions and mint 329.24 trillion phantom tokens. While the face value reached $49 billion, liquidity constraints limited the actual theft to $675,000. The Sandbox suspended bridging and announced a 1:1 treasury reimbursement. The incident marks the third major LayerZero failure in five months, accelerating a $15 billion migration wave to Chainlink CCIP.
SAND bridge exploit mechanics
▪The attacker extracted approximately 14.75 million SAND, worth roughly $675,000, from The Sandbox's Ethereum vault in under 60 seconds during the August 2026 exploit.
▪During the August 2026 exploit, the attacker sold stolen SAND tokens across 26 transactions, each sized to extract approximately 90 percent of available ether from the liquidity pool.
▪During the August 2026 exploit of The Sandbox, an arbitrage bot disrupted the attacker's plan, leaving the attacker with 14,095,483.66 SAND instead of the intended 14,743,364.21 SAND.
▪An attacker exploited the `approveAndCall` function on The Sandbox's SAND token contract on Base on August 21 and 22, 2026, to mint 329.24 trillion unbacked tokens.
LayerZero delegate permission vulnerability
▪The Sandbox's August 27, 2026 post-mortem confirmed that no private keys were compromised, attributing the exploit entirely to design flaws in the contract structure.
▪During the August 2026 exploit, an attacker weaponized the `approveAndCall` function on The Sandbox's SAND contract on Base to hijack LayerZero delegate permissions.
Phantom token liquidity constraints
▪The phantom SAND tokens minted on Base during the August 2026 exploit were worthless because they could not be redeemed or sold due to liquidity constraints.
▪Security firm Blockaid valued the 329.24 trillion phantom SAND tokens minted during the August 2026 exploit at a face value of approximately $49 billion.
Sandbox bridge shutdown response
▪The Sandbox disabled bridging on Base and BNB Smart Chain and removed LayerZero peer settings via multisig governance following the August 2026 exploit.
▪Coinbase delisted SAND perpetual futures contracts following the disclosure of the bridge exploit on August 22, 2026.
▪Korean exchanges Upbit and Bithumb suspended SAND deposits and withdrawals on August 22, 2026, citing South Korea's Virtual Asset User Protection Act.
▪The Sandbox announced on August 27, 2026, a 1:1 reimbursement plan from its treasury for eligible holders who held bridged SAND before the August 21 attack.
LayerZero bridge security failures
▪The KelpDAO hack wiped $13 billion from DeFi within 48 hours, prompting Curve Finance to halt its LayerZero infrastructure as a precaution.
▪The Sandbox exploit was the third major LayerZero-related bridge failure in five months, following the Kelp DAO attack in April 2026 and the Stake DAO breach in May 2026.
▪Attackers linked to North Korea's Lazarus Group drained 116,500 rsETH, worth approximately $292 million, from KelpDAO's LayerZero-powered bridge on April 18, 2026.
▪LayerZero's Decentralized Verifier Network allows applications to select as few as one verifier, whereas Chainlink CCIP requires a minimum of 16 independent node operators.
Chainlink CCIP migration wave
▪LayerZero's ZRO token fell to approximately $302 million in market capitalization from an all-time high near $7.47 following the series of exploits.
▪By August 2026, publicly announced migrations from LayerZero to Chainlink CCIP totaled approximately $15 billion in secured value, led by BitGo, Mantle, and Lombard.
▪BitGo migrated $7.4 billion in WBTC, Mantle shifted its $2.5 billion Super Portal, and Lombard transferred over $1 billion in bitcoin-backed assets to Chainlink CCIP.
Story comments
Loading comments…