The Sandbox SAND — LayerZero Bridge Exploit August 2026
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
Summary
On August 21–22, 2026, an attacker exploited a vulnerability in The Sandbox's SAND omnichain fungible token (OFT) contract on Base by hijacking LayerZero delegate permissions through the approveAndCall function, enabling unauthorized minting of approximately 329.24 trillion unbacked SAND tokens across 703 events over five hours. Actual financial extraction was substantially lower than headline figures: roughly 14.75 million SAND drained from the Ethereum OFT Adapter yielded approximately 80 ETH (~$675,000), while The Sandbox estimated the incident affected less than 0.01% of the 3-billion total SAND supply. The exploit was the third major LayerZero bridge incident in five months and contributed to accelerating an industry-wide migration from LayerZero to Chainlink CCIP, with publicly announced moves totaling approximately $15 billion.
Connected Entities
1 entitiesTimeline(10 events)
2026-03-06
Alleged Lazarus Group social engineering of a LayerZero Labs developer, reportedly harvesting session keys that later enabled access into LayerZero's RPC cloud environment.
Unchained Crypto2026-04-18
Kelp DAO's rsETH LayerZero bridge exploited; approximately 116,500 rsETH (~$292 million) drained. LayerZero attributed the root cause to Kelp's single-verifier bridge configuration; Kelp disputed this attribution.
CoinDesk / The Block2026-05-27
Stake DAO's vsdCRV LayerZero v2 bridge exploited via a compromised deployer key; attacker minted approximately 5.4 trillion unbacked vsdCRV on Arbitrum and extracted roughly 43.78 ETH (~$91,000). vsdCRV bridge permanently closed.
CryptoBriefing / CryptoTimes2026-08-20
Publicly announced migrations from LayerZero to Chainlink CCIP reach approximately $15 billion, led by BitGo's $7.4 billion WBTC migration. Article published two days before the Sandbox incident.
CryptoNomist2026-08-21
Exploit begins at approximately 23:42:05 UTC. Attacker uses the approveAndCall function on The Sandbox's SAND OFT contract on Base to hijack LayerZero delegate permissions, enabling unbacked SAND minting.
CryptoTimes / crypto.news2026-08-22
Minting activity continues until approximately 04:45:21 UTC; 329.24 trillion unbacked SAND minted across 703 events. The Ethereum OFT Adapter is drained of approximately 14.75 million SAND (~80 ETH, ~$675,000) within the first minute. Blockaid publicly alerts on the incident, citing $49 billion in face-value minting across 400+ transactions.
crypto.news / Blockaid / CryptoTimes2026-08-22
The Sandbox's multisig executes containment at approximately 05:09:19 UTC, zeroing LayerZero peer settings for Ethereum (ID 30101) and Base (ID 30102). Bridging disabled on Base and BNB Smart Chain. Ethereum and Polygon SAND confirmed unaffected.
crypto.news / CryptoBriefing2026-08-22
South Korean exchanges Upbit and Bithumb halt SAND deposits and withdrawals. SAND price declines approximately 5.5–10% intraday across venues.
CryptoBriefing / CoinPaprika2026-08-22
The Sandbox issues public statement confirming the breach, characterizing impact as less than 0.01% of total SAND supply, and committing to LP compensation using a pre-incident snapshot. No technical post-mortem published.
crypto.news2026-08-26
Coinbase scheduled to delist SAND perpetual futures contracts alongside nine other tokens, following a periodic liquidity and regulatory review announced after the exploit.
CryptoRank / news.bitcoin.comDecision Log
- #3review revise-10⛓ pending8/26/2026, 12:03:50 AMhash: 7YyhhMNPJt5bymZj5hWQiW9Hv7XWvzZk8g81tW3kmnhX
- #2review⛓ pending8/26/2026, 12:03:50 AMhash: 97wW4cZseFVhLDgXdxNcyxUSQBVPNMbXZ3gHSEC4Qkz9
- #1publish⛓ pending8/25/2026, 11:04:20 PMhash: 8Cx1XzzM1R6enxnnfCWUM2ba8oXadiyB3XEX47ZiLu4U
17 of 19 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/25/2026, 11:04:11 PM
last updated: 8/26/2026, 4:37:27 AM
avoid.net — verified advice for a post-truth world