YFarmX

Tools Crypto Exploit Tracker exploit-0012

Exploit record

The Sandbox OFT Bridge Mint

Loss
$1M
Attack vector
Access Control
Chain
Multichain
Sector
Gaming

What happened

From 23:41 UTC on 21 August 2026, an attacker used a call-on-behalf convenience feature in SAND's omnichain token contract on Base to register itself as bridge administrator, reconfigured the LayerZero verification settings so it alone could authorise mints, and minted unbacked SAND on Base and BNB Smart Chain. The sums extracted were far smaller than the mint: 14,742,341.84 SAND, about $697,000, was withdrawn from the Ethereum vault, and a further 93,415,334.86 SAND was sold on Base for 327.59 WETH, for a total attacker capture of about $987,000. The Sandbox's own post-mortem puts the total economic impact at about $1,496,784, and that is the figure logged here.

PeckShield counted 14.9bn unbacked SAND across two addresses; Blockaid put the face value near $49bn across more than 400 transactions while the attack was still running, and later stressed the flaw was in The Sandbox's SAND OFT contract, not LayerZero, whose contracts behaved as designed. The Sandbox's same-morning statement said the impact was under 0.01 per cent of total SAND supply, that SAND on Ethereum and Polygon was unaffected, and that no user wallets were compromised. Its 27 August post-mortem closed the record: bridging was shut at contract level on all three chains at 05:26 UTC on 22 August, no SAND left the vault after 02:21 UTC, about 647,880 SAND of the vault redemption was front-run by an unrelated arbitrage bot (which is why the impact figure exceeds the attacker's capture), and holders on Base and BNB Smart Chain are compensated 1:1 in Ethereum SAND from treasury, snapshots at Base block 50,283,176 and BSC block 117,321,965, with claims opening within two weeks.

Sources

One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026