Showing posts with label The Sandbox exploit. Show all posts
Showing posts with label The Sandbox exploit. Show all posts

The Sandbox Bridge Was Exploited, Creating More SAND Than Was Ever Supposed to Exist...

Sandbox Bridge SAND Exploit

The Sandbox has contained a cross-chain bridge exploit that allowed an attacker to create unbacked SAND tokens on Base and BNB Smart Chain, producing one of those crypto headlines that sounds physically impossible at first glance: security researchers counted billions of newly minted SAND, with one estimate putting their nominal value near $49 billion.

No, an attacker did not steal $49 billion from The Sandbox. There was never $49 billion of real value sitting there waiting to be withdrawn. The number came from applying SAND's normal market price to an absurd quantity of tokens that had been created without collateral behind them.

That distinction is the center of this story.

What the Attacker Actually Found

The affected infrastructure was the cross-chain version of SAND used on Base and BNB Smart Chain. In a normal bridge setup, SAND is locked on Ethereum and a corresponding amount can then exist on another supported network. The supply on the destination chain is supposed to remain backed by the original tokens.

According to blockchain security firm Blockaid, the attacker hijacked LayerZero delegate permissions tied to SAND's omnichain fungible token contract and used the approveAndCall function to mint tokens that had no corresponding SAND locked behind them. Blockaid flagged roughly $49 billion in face-value minting across more than 400 transactions while the attack was still underway.

PeckShield later counted roughly 14.9 billion SAND minted across two attacker addresses. For perspective, SAND's stated maximum supply is only 3 billion tokens. The forged amount identified by PeckShield was therefore close to five times the maximum supply the token was ever supposed to have.

Crypto has found many creative ways to make token supply charts look strange. Creating several extra lifetimes' worth of supply in one exploit is certainly one of them.

Why $49 Billion Was Never Really $49 Billion

At the time of the incident, SAND's entire market capitalization was only around $140 million. There was obviously nowhere near enough liquidity on Base, BNB Chain, centralized exchanges, or anywhere else to turn tens of billions of newly created tokens into tens of billions of dollars.

If someone creates 10 billion unbacked tokens and the legitimate token trades at five cents, a block explorer can display a theoretical value of $500 million. That does not mean there are buyers willing to hand over $500 million. In an exploit like this, the displayed value becomes increasingly fictional as the unauthorized supply grows.

The economically important questions are how much legitimate liquidity the attacker could reach, whether any backed tokens or other assets escaped before containment, and who was left holding affected liquidity positions. The Sandbox has not yet published a full technical post-mortem or a final audited loss figure.

The Sandbox Shut the Doors on Base and BNB Chain

The Sandbox said it identified and contained the vulnerability, disabled bridging to and from Base and BNB Smart Chain, and isolated SAND on those networks so the affected tokens cannot be moved or redeemed through the official bridge.

The company also said SAND on Ethereum and Polygon was unaffected, no user wallets were compromised, and the Ethereum-held SAND backing legitimate bridged tokens remains intact. It warned users not to buy, sell or trade SAND on Base or BNB Smart Chain while liquidity on those networks is compromised. CoinDesk's report also noted that Upbit and Bithumb suspended SAND deposits and withdrawals after the incident.

The team is taking a pre-incident snapshot and says it is preparing compensation for eligible users of the affected liquidity pools. A full incident report and technical post-mortem are still expected.

There Is One Number That Still Needs Clarification

The Sandbox described the impact as less than 0.01% of total SAND supply. Taken literally against a 3 billion-token maximum supply, 0.01% would be fewer than 300,000 SAND.

That clearly does not describe the total number of unauthorized tokens minted, because independent security firms observed billions. The most reasonable reading is that The Sandbox is using "impact" to describe the amount of legitimate value affected rather than the quantity of fake tokens created. The company has not yet fully reconciled those figures publicly, so investors should avoid treating the 0.01% statement as a measurement of the exploit's minting activity.

That distinction matters because headlines can easily swing from one bad interpretation to another. Calling this a $49 billion theft would be wrong. Calling it a trivial exploit because the project says the impact was under 0.01% would also skip over what actually happened.

The Weak Link Was the Cross-Chain Layer

Ethereum SAND itself was not reported compromised. The exploit targeted the machinery that lets representations of SAND exist on other networks. That is a familiar pattern in crypto security: the underlying chain or token can work exactly as designed while permissions in a bridge create a completely separate attack surface.

The technical issue is particularly important because the attack involved LayerZero-related delegate permissions. That does not automatically mean LayerZero itself was compromised. The available reports point to permissions associated with The Sandbox's SAND OFT deployment. The final post-mortem will need to explain precisely where control failed, how the delegate authority was obtained, and why the minting path accepted it.

Until that report arrives, traders should focus on the facts that can be established: unbacked SAND was minted on Base and BNB Smart Chain, the affected bridge routes have been disabled, Ethereum and Polygon SAND were reported safe, and the eye-popping $49 billion figure measures theoretical face value rather than money stolen.

The exploit may ultimately prove modest in direct financial losses, but the permission failure was anything but modest. When a bridge can create several times a token's maximum supply before someone hits the stop button, the post-mortem matters almost as much as the reimbursement plan.

---------------

Author: Cedric Holloway
New York Newsroom
Breaking Crypto News