EGW-NewsSandkassen blir truffet av en myntverksbedrift på 700 millioner dollar som aldri egentlig var der
Sandkassen blir truffet av en myntverksbedrift på 700 millioner dollar som aldri egentlig var der
285
Add as a Preferred Source
0
0

Sandkassen blir truffet av en myntverksbedrift på 700 millioner dollar som aldri egentlig var der

Denne artikkelen er tilgjengelig på følgende språk

Someone found a hole in The Sandbox's cross-chain plumbing on Saturday, and for a few hours the metaverse project's SAND token existed in two realities at once. On paper, an attacker minted nearly 15 billion unbacked SAND — about five times the token's entire 3 billion supply. In practice, they walked away with roughly $665,000. Both numbers are true, and the gap between them says a lot about how these bridge exploits actually work.

PeckShield flagged the mint first, tracing 14.9 billion SAND across two wallets, 0xAbE0…4D22 and 0x638C…F296. At SAND's price that morning, that's somewhere between $700 million and $718 million of tokens that shouldn't exist. Blockaid, another security firm watching the same contract, put the number even higher — nearly $49 billion in face value across more than 400 transactions — because it was counting mint events as the attack was still unfolding rather than the final tally once things settled.

Here's the mechanism, as far as anyone's pieced together so far. SAND uses LayerZero's omnichain token standard to move between Ethereum, Base, BNB Smart Chain and Polygon without a traditional lock-and-mint bridge on every hop. That setup depends on a "delegate" role that controls minting authority on each chain. Somehow, the attacker got control of that delegate on the Base deployment and used a function called approveAndCall to bypass the checks that would normally stop unbacked tokens from being created. Nobody outside The Sandbox and its auditors knows yet whether that was a smart contract bug, a compromised key, or something else — the team says a full post-mortem is coming, and I'd wait for it before assuming which.

What actually mattered was the Ethereum side. The Sandbox's bridge design locks real SAND on Ethereum to back every token minted elsewhere. The attacker found a path to drain that lock: roughly 14.75 million SAND left the Ethereum OFT adapter, most of it — 14 million-plus — in six transactions inside a 24-second window that has the fingerprints of a script, not a person clicking buttons. That SAND got converted into about 80 ETH, worth around $665,000 to $675,000 depending on which price snapshot you use. That's the real loss. Everything else is inflated supply sitting on an isolated chain with nowhere to go.

The Sandbox confirmed the exploit on X, saying it had "identified and fully contained" the issue and that the damage came to less than 0.01% of total supply. The team cut off LayerZero's bridge connections to Base and BSC, which stops the inflated tokens from being redeemed or moved anywhere that matters. Ethereum and Polygon SAND, they say, were never touched, and no user wallets were compromised. Co-founder Sebastien Borget added more color in a follow-up thread, noting the team caught it within six hours and brought in OpenZeppelin — the firm that originally audited the contract — to help dig into root cause. A pre-incident snapshot is coming, along with compensation for liquidity providers caught on the wrong side of the isolated pools, though there's no payout timeline yet.

Exchanges reacted fast, which tells you something about how nervous this space still is after a year like 2026. Bithumb froze SAND deposits and withdrawals. Upbit put out a warning to users. Coinbase confirmed it's delisting SAND futures on August 26. None of that undoes the exploit, but it does show how quickly a headline number — even a fake one — can ripple through market infrastructure before anyone's confirmed what's real.

And SAND's price? Genuinely messy. Some venues showed the token down 5–10% in the hours after the news broke. Others showed it climbing, CoinMarketCap had it up over 10% at one point, with trading volume spiking several hundred percent as futures traders piled into both directions. I won't pretend to have a clean explanation for that split; thin liquidity and panic in both directions can do strange things to a token that was already down more than 99% from its 2021 high of $8.40.

Ikke gå glipp av nyheter og oppdateringer om esport! Registrer deg og motta ukentlig artikkeloversikt!
Registrer deg
The Sandbox Gets Hit With a $700 Million Mint That Was Never Really There 1

This isn't even a novel category of failure. LayerZero delegate and peer abuse has now shown up in at least three separate incidents since spring — a Polkadot bridge exploit that minted a billion unauthorized DOT, a smaller hit on Alephium's ALPH bridge, and now this. Add Harmony's roughly 4 billion unauthorized ONE tokens from earlier this year and WEMIX's separate ownership breach, and you start to see a pattern: cross-chain minting authority is still, in 2026, frequently sitting behind a single point of failure that projects discover only after someone's already found it. Blockaid's own mid-year report put verified exploit losses at $1.1 billion across 212 incidents for the first half of 2026 alone, with infrastructure and key compromises as a recurring theme rather than an outlier.

The Sandbox says a technical write-up is on the way. Until then, the honest summary is this: nobody stole $700 million, but somebody found a real crack in a widely used bridge standard, and the fix matters more than the scary headline number.

Legge igjen en kommentar
Likte du artikkelen?
0
0

Kommentarer

FREE SUBSCRIPTION ON EXCLUSIVE CONTENT
Receive a selection of the most important and up-to-date news in the industry.
*
*Only important news, no spam.
SUBSCRIBE
LATER