خبری درباره‌ی سندباکس (SAND)

The Sandbox minted 329 trillion unbacked SAND tokens in 5 hours and only $675K was stolen

crypto.news ۱۶ روز پیش خلاصه‌ی فارسی · ۴۴۷ کلمه
The Sandbox minted 329 trillion unbacked SAND tokens in 5 hours and only $675K was stolen

A bridge configuration flaw on Base and BNB Smart Chain let attackers hijack LayerZero delegate permissions, mint trillions of phantom SAND tokens, and drain roughly $675,000 from the Ethereum vault before the team shut everything down. The $49 billion face value headline masked the real story: structural constraints meant the attacker could never have cashed out more than a fraction of what was created. Summary An attacker exploited the `approveAndCall` function on The Sandbox’s SAND omnichain fungible token contract on Base, hijacking LayerZero delegate permissions and minting 329.24 trillion unbacked SAND across 703 events over five hours on Aug. 21 and 22, 2026. The face value of minted tokens reached approximately $49 billion according to security firm Blockaid, but the actual extraction totaled roughly 14.75 million SAND (about 80 ETH, or $675,000) drained from the Ethereum OFT Adapter in under 60 seconds. The Sandbox disabled bridging on Base and BNB Smart Chain, removed LayerZero peer settings via multisig governance, and confirmed that SAND on Ethereum and Polygon remained untouched throughout the incident. The project announced a 1:1 reimbursement plan from its treasury for eligible holders, with no new SAND tokens to be minted and a claims portal expected within two weeks of the Aug. 27 post-mortem. The exploit marked the third major LayerZero-related bridge failure in five months, accelerating a $15 billion migration wave from LayerZero to Chainlink CCIP led by BitGo, Mantle, and Lombard. On the night of Aug. 21, 2026, an address that had been dormant for 313 days routed a crafted payload through The Sandbox’s SAND token contract on Base. Within five hours, blockchain explorers showed trillions of freshly minted SAND tokens spreading across 173 wallets. Security firm PeckShield flagged the activity first, and by the time The Sandbox team responded, the attacker had already extracted what they could and moved on. The headline numbers were staggering, but the actual financial damage told a very different story. The gap between the face value of minted tokens and the real amount stolen reveals something important about how bridge exploits actually work. It also exposes a recurring pattern in cross-chain infrastructure: the same design choices that make bridges useful also make them fragile, and a single misconfiguration can open a door that costs millions to close. How the approveAndCall exploit worked The technical root of the attack sat inside a function called `approveAndCall` on The Sandbox’s SAND omnichain fungible token contract deployed on Base. In a standard OFT setup built on LayerZero, a delegate address on the destination chain holds administrative rights over the endpoint configuration. Those rights include the ability to set trusted peers, update security stacks, and authorize privileged calls into the token contract.

عنوان اصلی (انگلیسی): The Sandbox minted 329 trillion unbacked SAND tokens in 5 hours and only $675K was stolen

مشاهده‌ی خبر کامل در منبع ↗ بازگشت به سندباکس

این خلاصه به‌صورت خودکار از کوین‌مارکت‌کپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاع‌رسانی است و توصیه‌ی معاملاتی نیست.