The Sandbox bridge exploit led to 329 trillion unbacked SAND minted on Base

The Sandbox bridge exploit led to 329 trillion unbacked SAND minted on Base

N
News Editor
2026-08-24 06:59:33
The Sandbox’s cross-chain bridge was exploited, with the attacker using a delegated-permission flaw in LayerZero to mint 329 trillion unbacked SAND tokens on Base, according to Techub, citing Crypto.news. The scale of the mint was massive, but the amount actually drained from reserves was far smaller. The report said built-in limits on cross-chain transfers kept the total value stolen from reserves to $675,000. The incident highlights a key weakness in cross-chain token designs: if minting controls are compromised, an attacker may be able to create large amounts of unsupported assets even if other guardrails limit direct losses. At the same time, the case also showed that internal transfer restrictions can reduce the financial impact of an exploit, at least in part. No additional details on remediation or recovery were provided in the source digest.

The Sandbox’s cross-chain bridge was exploited, and the attacker used a delegated-permission flaw in LayerZero to mint 329 trillion unbacked SAND tokens on Base, according to Techub, citing Crypto.news.

The amount actually taken from reserves was much smaller. The report said built-in limits on cross-chain transfers capped the total drained at $675,000.

The incident exposed the fragility of cross-chain token architecture and also pointed to the role of embedded security restrictions in limiting losses.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
2800

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.