The Sandbox (SAND omnichain bridge) hack — August 2026
Incident facts
| Date of incident | |
|---|---|
| Target type | Gaming or metaverse |
| Loss | $675,000Price at time of incident |
| Method | Access control flawLayerZero delegate permissions on the SAND omnichain token were taken over through an approveAndCall function, granting mint rights on the Base and BSC sides without collateral on Ethereum |
| Chains | Base, BNB Chain |
| Outcome | Unresolved |
What happened
An attacker minted unbacked SAND on Base and BNB Smart Chain on 22 August 2026 after taking over the LayerZero delegate permissions on the token's omnichain contract through an approveAndCall function, which granted minting rights on those two chains without depositing anything on Ethereum.
The face value and the realised loss are far apart, and the distinction matters. Blockaid flagged close to $49bn of nominal SAND across more than 400 transactions and PeckShield counted 14.9bn unbacked tokens across two addresses, but nothing like that could be sold. The extraction that actually cleared was about $675,000: roughly 14.75m genuine SAND pulled from the Ethereum adapter and around 80 ETH realised from sales. The figure recorded here is the amount extracted, not the amount minted.
The Sandbox stopped bridging to Base and BNB Smart Chain, isolated the unauthorised tokens and said the SAND locked on Ethereum was untouched, putting the direct impact below 0.01% of the 3bn token supply. Ethereum and Polygon SAND were unaffected. The team said it would compensate eligible liquidity providers on their pre-attack balances; that had been announced but not completed at the time of recording. Upbit and Bithumb suspended SAND deposits and withdrawals. No official post-mortem confirming the delegate mechanism has been published.
Sources
- crypto.newsSecondary · retrieved 2026-08-26
- BeInCryptoSecondary · retrieved 2026-08-26
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "The Sandbox (SAND omnichain bridge) hack — August 2026", iTokenly, accessed 2026-08-27, https://itokenly.com/hacks/the-sandbox-bridgehttps://itokenly.com/hacks/the-sandbox-bridgePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.