Morning Edition · Sunday, August 23, 2026Published at 1:46 AM EDT · New York
The gaming network disabled bridging to Base and BNB Smart Chain and said the direct impact was under 0.01% of supply, though researchers put the actual extraction near $675,000 against tens of billions of dollars in face-value tokens.

The Sandbox, the blockchain gaming network behind the SAND token, stopped bridging on Base and BNB Smart Chain after an attacker minted SAND on those networks with nothing locked behind it. The company warned users not to trade SAND on the affected chains and put the direct impact at less than 0.01% of the token's 3 billion supply, a figure crypto.news also reported.
The mechanism was not a broken mathematical assumption. It was privileged configuration. The token uses the omnichain fungible token standard from LayerZero, a cross-chain messaging protocol, in which a designated delegate account can set the contract's messaging configuration. According to the proof-of-concept published by DeFiHackLabs and a parallel reconstruction of the same path, the attacker reached that delegate role through the token's approveAndCall function, then used the resulting control to have destination-chain contracts credit tokens that no source-chain deposit backed.
The headline numbers and the real numbers diverge sharply. Security researchers cited by The Cryptonomist and other outlets counted hundreds of mint transactions creating tens of billions of dollars of face-value SAND. Tokens created without backing cannot be sold for anything close to their nominal value, because the order books on Base and BNB Smart Chain are thin. The extraction that mattered ran through the Ethereum-side adapter, roughly 14.75 million SAND, about $675,000, part of which was converted into ether. The Sandbox says it is preparing compensation for affected liquidity providers.
The pattern is familiar and getting expensive. Cross-chain token standards concentrate authority in a small set of administrative roles, and those roles are frequently reachable through a function nobody modelled as an entry point. The contract behaved as written, but the permission model failed to anticipate that a callback function could reach the delegate role.
Part of a tracked trend
Bridge and Mint Exploits Sustain Heavy DeFi Losses
Over 3-6 months, recurring bridge proof-validation and unauthorized-mint exploits keep monthly DeFi losses elevated, including drains of deprecated contracts.
Start a discussion in Townsquare.
More from this edition
The Sandbox gains from measuring the incident against total token supply, which produces a figure under 0.01%, while security firms and the outlets citing them gain attention from the face-value figure of tens of billions of dollars.
Both headline numbers describe something other than the actual loss: Blockaid counted roughly $49 billion in face-value SAND across more than 400 transactions that could never be sold at that price, the company's supply percentage is not a loss measure, and the amount owed to liquidity providers remains unpublished.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Those bearing the loss are the automated market maker liquidity providers on Base and BNB Smart Chain who took unbacked tokens in exchange for real assets, and secondarily any holder whose SAND cannot currently be moved because the bridges are disabled. The wider consequence is a discount on any asset whose supply integrity depends on a delegate key in a cross-chain messaging contract, which now includes a large share of tokens deployed on more than one network. Expect exchanges and market makers to widen spreads or suspend bridged versions of such tokens before investigating further.
What to watch
Observations to monitor, not financial advice.
Synthesized from: CoinDesk · crypto.news · DeFiHackLabs
Comments
0No comments yet.