
Sandbox Bridge exploit drains 14.7M SAND from an Ethereum vault. Explore the flaw, timeline, disclosure gap, and 1:1 reimbursement plan.
Author: Akshay
27th August 2026 – The Sandbox bridge exploit finally has an official post-mortem. The team confirmed attackers drained about 14.7 million SAND from its Ethereum vault. That haul equals roughly 0.5% of the fixed 3 billion supply.
High Signal Summary For A Quick Glance
NaoX | Post-Quantum Chain
@NaoXprotocol
@TheSandboxGame Good on them for publishing the full breakdown. Worth flagging that this sits in a different bucket than most bridge incidents we track. This wasn't a signature or key compromise. Instead, it was a config mismatch between two deployments of the same bridge logic
August 22 exploit Post-Mortem is now live. TL;DR: attacker drained 14,742,341.84 SAND (~0.5% of max supply) from the Ethereum vault via a bridge configuration flaw on Base/BSC. Ethereum and Polygon were never affected. We've reported the attacker's wallet to TRM Labs and https://t.co/FPKmrJznfE
12:35 PM·Aug 27, 2026
High attention and emotional sentiment detected.
The exploit hit on 22 August through a bridge configuration flaw on Base and BNB Chain. Ethereum and Polygon stayed untouched. Still, the disclosure raised hard questions about how the team first sized the damage.
According to the 27 August post-mortem, the attacker pulled 14,742,341.84 SAND from the Ethereum OFT adapter. That adapter contract is the vault that backs every cross-chain SAND token. Independent researcher BlockWatchdog measured a near-identical 14.75 million SAND leaving the same contract.
In dollar terms, on-chain trackers valued the haul near $665,000 to $675,000. The attacker converted the stolen SAND into roughly 79.74 ETH within the first hour. So the real loss stayed small next to the token’s headline supply.
On Base and BNB Chain, the SAND token contract also runs the LayerZero bridge integration. That design handed one contract control over who verifies incoming bridge messages. The attacker exploited that overlap.
Security firm Blockaid traced the method to an approveAndCall function. Through it, the attacker made the contract call setDelegate on itself. As a result, the attacker became the sole verifier and forged bridge messages to mint unbacked SAND.
Blockaid stressed one point clearly. This was not a LayerZero protocol bug. Instead, the LayerZero contracts behaved as designed, and the flaw sat in The Sandbox’s own configuration.
The project multisig cut the trusted LayerZero peers at 05:09 UTC on 22 August. After that, the unbacked tokens on Base and BSC could no longer redeem real SAND.
The attack unfolded fast across a single night. BlockWatchdog dates the first Base mint to 23:42 UTC on 21 August. The Ethereum adapter drain then ran for 24 seconds near 00:32 UTC on 22 August.
Within the hour, the attacker sold the stolen SAND for ETH. Blockaid flagged the live exploit at 04:14 UTC, while minting still continued. So the team moved to contain it, cutting the bridge peers at 05:09 UTC. PeckShield’s public alert followed at 05:40 UTC.
Timeline: The Sandbox’s August 2026 SAND bridge exploit, from the initial unbacked mint and Ethereum vault drain through containment, loss clarification, the five-day post-mortem, and 1:1 treasury reimbursement plan.
Researchers later identify the attacker wallet as having been dormant for roughly 313 days before being pre-positioned on this date. This is background to the incident rather than the exploit itself.
The exploit begins on Base when the attacker creates an initial 50 million unbacked SAND. Minting continues for approximately five hours, eventually producing an enormous volume of tokens that are not backed by the Ethereum-side supply.
The attacker drains the Ethereum OFT adapter/vault, with independent on-chain analysis recording roughly 14.75 million SAND transferred across multiple events. The later official accounting puts the final loss at 14,742,341.84 SAND.
The stolen tokens are moved through several wallets and sold for approximately 79.74 ETH. Researchers also track hundreds of trillions of unbacked SAND across Base and BSC addresses as the exploit continues before the bridge is contained.
Blockaid publicly warns that the SAND OFT exploit on Base is still active, while PeckShield separately flags billions of newly minted SAND. Exchanges begin restricting SAND transfers and deposits on affected networks as the incident unfolds.
The containment multisig removes the relevant LayerZero peers for Base and BSC. This cuts the cross-chain pathway and prevents the unbacked token balances from continuing to propagate through the bridge infrastructure.
The Sandbox publicly confirms that the issue has been identified and contained. The initial statement estimates the impact at less than 0.01% of supply, says the Ethereum vault is intact, disables Base/BSC bridging, and promises a snapshot, LP compensation, and a full post-mortem.
The team says the attacker wallet has been submitted to TRM Labs and Chainalysis for stolen-funds tagging. Exchanges are also asked to restrict deposits and withdrawals on the affected networks. No confirmed freeze or recovery of the stolen funds is publicly reported at this stage.
The Sandbox updates its accounting and confirms that 14,742,341.84 SAND was drained from the Ethereum vault, equivalent to roughly 0.5% of the 3 billion maximum supply. The team identifies the root cause as a configuration function that allowed the attacker to become the sole verifier of inbound bridge messages.
The Sandbox publishes its technical post-mortem roughly five days after the exploit. The final response confirms the permanent deactivation of the Base and BSC SAND contracts and outlines a 1:1 treasury reimbursement for eligible pre-attack holders based on an on-chain snapshot, without creating new SAND.
The reimbursement portal has not yet gone live. The stated plan is for claims to open within two weeks and remain open for two weeks. Ethereum and Polygon remain unaffected, while the team continues working with exchanges and blockchain-intelligence firms on potential recovery of stolen funds.
The next milestones are the launch of the reimbursement portal, verification of eligible pre-attack balances, and distribution of 1:1 Ethereum SAND from the treasury. Base and BSC bridging will not simply reopen after a hot-fix, making any future cross-chain architecture a separate decision.
The Ethereum SAND contract was never a minter in this design. So its total supply held at exactly 3 billion tokens throughout the attack. Polygon runs a separate deployment and sat outside the affected bridge mesh entirely.
Because of that split, holders on Ethereum and Polygon kept every token. The huge mint numbers that spread online only ever existed as unbacked paper on Base and BSC. In fact, PeckShield counted 14.9 billion minted SAND, while BlockWatchdog logged 329 trillion on Base.
Those figures measure face value, not stolen money. Only the 14.7 million SAND from the Ethereum vault carried real backing. Everything else became worthless once the team zeroed the bridge peers.
The Sandbox bridge exploit also became a disclosure story. On 22 August, the team called the impact minimal, at less than 0.01% of supply. Two days later, the same account revised that to 14.74 million SAND, or about 0.5%.
CoinDesk noted that the first estimate would imply under 300,000 SAND against a 3 billion supply. The gap between the two figures fueled most of the holder anger. According to Chinese-language recaps, the official economic impact reached about $1.5 million, with roughly $987,000 retained.
That dollar figure sits above the on-chain estimate of roughly $675,000. So far, English-language coverage has not reconciled the two numbers. For now, treat the higher figure as an unverified official claim.
SAND felt the pressure fast. On 22 August, trading volume spiked to about $260 million, roughly triple the prior day. Meanwhile, the price wicked up to $0.052 before sliding toward $0.044.
By 27 August, SAND traded near $0.042, with a market cap around $123 million. Over the week, the token slid about 14% from its 21 August close. Korean venues such as Upbit and Bithumb also froze SAND transfers during the incident.
None of this counts as financial advice, and prices could move either way from here.
The Sandbox says it will make affected users whole. According to 27 August recaps from Odaily and BlockBeats, the team will pay 1:1 Ethereum SAND from its treasury. Crucially, that payout uses existing tokens, with no new mint.
Eligibility covers wallets that legitimately held cross-chain SAND before the attack. The team says a claims window opens within two weeks and stays open two weeks. Meanwhile, the Base and BSC contracts stay permanently deactivated.
Two questions still hang over the case. First, The Sandbox says it is asking why auditor OpenZeppelin missed the flaw. Second, the team has referred the attacker wallets to TRM Labs and Chainalysis, though no arrest has followed.
The Sandbox bridge exploit now moves into its recovery phase. For now, SAND holders on Base and BSC should avoid buying or moving those tokens. Watch The Sandbox’s official channels for the exact eligibility terms.
Our Crypto Talk is committed to unbiased, transparent, and true reporting to the best of our knowledge. This news article aims to provide accurate information in a timely manner. However, we advise the readers to verify facts independently and consult a professional before making any decisions based on the content since our sources could be wrong too. Check our Terms and conditions for more info.