خبری درباره‌ی Stake DAO (SDT)

The Sandbox’s $49 billion phantom mint: how a bridge exploit created unbacked SAND tokens

crypto.news ۲۴ روز پیش خلاصه‌ی فارسی · ۴۵۲ کلمه
The Sandbox’s $49 billion phantom mint: how a bridge exploit created unbacked SAND tokens

An attacker weaponized a single ERC-20 function to hijack LayerZero delegate permissions and mint 329 trillion unbacked SAND on Base, yet the actual reserve drain totaled just $675,000, exposing both the fragility and the hidden safeguards of cross-chain token architecture. Summary An attacker exploited the approveAndCall function on The Sandbox\u2019s SAND omnichain fungible token contract on Base, hijacking LayerZero delegate permissions and minting 329.24 trillion unbacked SAND across 703 events over five hours on Aug. 21 and 22, 2026. Blockchain security firm Blockaid flagged $49 billion in face-value SAND minted across more than 400 transactions, while PeckShield counted 14.9 billion SAND directed to two attacker-controlled addresses. The actual financial extraction was far smaller: roughly 14.75 million SAND drained from the Ethereum OFT Adapter in under 60 seconds, yielding approximately 80 ETH (around $675,000 at the time of the transactions). The Sandbox disabled bridging on Base and BNB Smart Chain, removed LayerZero peer settings via multisig, and confirmed that SAND on Ethereum and Polygon was unaffected; Korean exchanges Upbit and Bithumb halted deposits and withdrawals, and Coinbase delisted SAND futures. The incident marks the third major LayerZero-related bridge exploit in five months, following the $292 million Kelp DAO attack in April and the Stake DAO breach in May, accelerating a $15 billion migration wave from LayerZero to Chainlink CCIP. On the night of Aug. 21, 2026, an address that had been dormant for 313 days routed a crafted payload through The Sandbox\u2019s SAND token contract on Base. Within five hours, blockchain explorers showed trillions of freshly minted SAND tokens spreading across 173 wallets. The face value, calculated by multiplying inflated balances against the live market price, briefly crossed $49 billion. That number exceeded the market capitalization of all but a handful of crypto projects. It also had almost no relationship to the money the attacker actually took. The gap between the headline figure and the real extraction ($675,000, roughly the price of a modest house) reveals something important about how cross-chain token systems work and how they fail. It also reveals how crypto security reporting can amplify panic through numbers that are technically accurate but practically meaningless. Understanding why the attacker could mint a number larger than the gross domestic product of several small nations, yet walk away with a fraction of a fraction of that sum, requires examining the architecture that made the exploit possible and the constraints that limited its damage. The Sandbox is one of the most recognizable names in Web3 gaming, with its SAND token powering a virtual world where users create, own, and monetize gaming experiences. The project was expanding its cross-chain presence to Base and BNB Smart Chain through LayerZero\u2019s OFT framework when the vulnerability was exploited.

عنوان اصلی (انگلیسی): The Sandbox’s $49 billion phantom mint: how a bridge exploit created unbacked SAND tokens

مشاهده‌ی خبر کامل در منبع ↗ بازگشت به Stake DAO

این خلاصه به‌صورت خودکار از کوین‌مارکت‌کپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاع‌رسانی است و توصیه‌ی معاملاتی نیست.