A $49bn Mint That Was Worth $675,000: Inside the Sandbox Exploit
By Antonina Tupikova · Founder, iGaming Times2 min read
An attacker minted 329 trillion SAND on Base, roughly 110,000 times the token's entire legitimate supply, and walked away with about $675,000. The gap between those two numbers is the whole story, and it is not a reassuring one.
- An attacker minted about 329.24 trillion unbacked SAND on Base between 23:42 UTC on 21 August and 04:45 UTC on 22 August, across 703 minting events reaching 173 wallets
- Security firm Blockaid put the face value at roughly $49 billion; PeckShield counted 14.9 billion SAND, and the differing figures reflect different measurement points rather than a dispute
- Only about 14.75 million SAND was actually drawn out of the Ethereum adapter and converted, realising roughly 79.74 ETH, about $675,000
- The exploit routed a crafted payload through the SAND token contract's
approveAndCallfunction into the LayerZero endpoint, borrowing the token contract's own delegate authority to authorise minting - The Sandbox severed its cross-chain links by multisig at 05:09 UTC, disabling bridging to Base and BNB Smart Chain; Upbit and Bithumb halted deposits and withdrawals and Coinbase delisted SAND perpetual futures
Five Hours, 703 Mints, and One Function Call
The attacker's wallet had been in place since 13 October 2025. The exploit itself ran for a little over five hours.
The mechanism turned an ordinary ERC-20 convenience function against the contract that offered it. approveAndCall lets a holder approve a spender and trigger a call in one transaction. Here it was used to route a crafted payload through the SAND token contract into the LayerZero endpoint, which meant the call arrived carrying the token contract's own delegate authority. That authority was enough to reconfigure the endpoint and authorise minting on Base without any corresponding collateral being locked on Ethereum.
The scale is easier to state than to picture. SAND's legitimate maximum supply on Ethereum is 3 billion tokens. The attacker minted roughly 329.24 trillion, about 110,000 times the entire supply, in 703 separate events spread across 173 wallets.
Blockaid flagged the exploit as it ran and put the face value at approximately $49 billion. PeckShield counted 14.9 billion SAND. Both figures circulated widely and neither is wrong: they measure different things at different points in a fast-moving incident, which is normal in the first hours and unhelpful in a headline.
What actually left was far smaller. The unbacked tokens on Base and BNB Smart Chain could not be redeemed against real reserves, so the only realisable value was whatever could be pulled from the Ethereum adapter before the bridge closed. That came to about 14.75 million SAND, converted into roughly 79.74 ETH, or about $675,000.
The Sandbox closed the bridge by multisig at 05:09 UTC, 24 minutes after the last mint. It has described the impact as minimal. On the narrow question of realised loss it has a case. On the question of what the contract permitted, it does not.
The Headline Number and the Real Number Are Both True, and Only One Matters
A $49 billion mint that yields $675,000 sounds like a failure of the attack. It is better read as a demonstration of where the value actually sits in a bridged token. Minting on a destination chain is trivially easy once the endpoint trusts you; converting it is not, because the liquidity that would let you exit lives on the origin chain behind an adapter holding real reserves. The attacker hit the ceiling of what the adapter held and the bridge was closed on top of that. The lesson is not that the exploit was small, it is that the containment worked and the authorisation did not. That distinction is easily lost in a sector where the legal framing is already unsettled. A different token with deeper adapter reserves and a slower multisig produces a very different second number from exactly the same first one.
Three Incidents in Five Months Is a Pattern, Not a Run of Bad Luck
This is the third significant failure in the same messaging layer this year. Kelp DAO lost $292 million on 18 April through a compromised one-of-one verifier. Stake DAO saw 5.4 trillion vsdCRV minted in May for about $91,000 realised, the same shape as this incident at smaller scale. Each had a different proximate cause, which is precisely the problem: the common factor is a cross-chain trust model in which a single misconfigured or borrowed authority mints without limit on the far side. The market has drawn its own conclusion, with around $15 billion in assets announced as migrating from LayerZero to Chainlink CCIP, including BitGo's $7.4 billion in WBTC, Mantle's $2.5 billion, Lombard's more than $1 billion and Solv Protocol's $700 million.
Why a Metaverse Token Matters to This Industry
The Sandbox is a gaming platform, and this sector's crypto exposure runs through exactly this kind of infrastructure. Operators experimenting with blockchain-based gambling products and those simply taking crypto deposits are relying on bridged representations of assets whose backing they do not verify and mostly cannot. A player depositing a token that exists on three chains is trusting a messaging layer, not an issuer, in the same way that a holder of a tokenised commodity trusts the custody behind it. That the market repriced SAND upward, 4.76% to $0.0476 in the 24 hours after an unlimited mint, tells you how little of that trust is currently expressed in price.
The bridge held the loss to $675,000. Nothing in the design held the mint to anything at all.


