Skip to main content
Sign in

Audit log

Every state-changing event for The Sandbox SAND Bridge Exploit: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-27 12:05:01Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    98YcGuGGxc7V…tcwWuRAisha256 → base58
    verifying row…
    canonical bytes (20153 B) ▸
    {"actor":"system:backfill","investigation_id":"0faf0992-5629-4b23-ba09-b5a70bd78c2b","kind":"publish","page_slug":"the-sandbox-sand-bridge-exploit","published_at":"2026-08-27T12:05:01.083Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"The Sandbox SAND Bridge Exploit","sections":[{"content":"The attack targeted The Sandbox's SAND Omnichain Fungible Token (OFT) contract deployed on the Base network. According to blockchain security firm Blockaid, which first publicly flagged the incident during its active phase, the attacker weaponized the contract's approveAndCall function to route a crafted payload through the token contract into the LayerZero endpoint, thereby hijacking the Base deployment's LayerZero delegate permissions. Once delegate control was established, the attacker was able to trigger token minting on Base and BNB Smart Chain without corresponding burns or locks on Ethereum, where the canonical SAND supply is held. Security researchers described the vulnerability as an application-level configuration failure specific to The Sandbox's OFT implementation, not a flaw in the LayerZero protocol itself. A total of 329.24 trillion unbacked SAND tokens were minted across 703 transactions distributed to 173 addresses between approximately 23:42:05 UTC on August 21 and 04:45:21 UTC on August 22, 2026. The canonical Ethereum supply of 3 billion SAND was not altered during the attack.","heading":"Exploit Mechanism","severity":"high","sources":[{"credibility":3,"name":"Blockaid alert on X: ongoing exploit on SAND OFT on Base","type":"social_media","url":"https://x.com/blockaid_/status/2091016046555582891"},{"credibility":2,"name":"Sandbox SAND Hacked: Attackers Mint 329 Trillion Tokens on Base in 5-Hour Rampage — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/22/sandbox-sand-hacked-attackers-mint-329-trillion-tokens-on-base-in-5-hour-rampage/"},{"credibility":2,"name":"The Sandbox's $49 billion phantom mint: how a bridge exploit created unbacked SAND tokens — crypto.news","type":"news_article","url":"https://crypto.news/sandbox-bridge-exploit-49-billion-phantom-sand-mint/"},{"credibility":2,"name":"Sandbox halts Base and BNB Chain bridging after exploit mints billions of unbacked SAND tokens — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/sandbox-halts-bridging-sand-exploit/"}]},{"content":"The exploit produced two very different figures that circulated widely and require careful distinction. The face-value figure of approximately $49 billion, cited by Blockaid and widely repeated, reflects the market price of SAND applied to the 329.24 trillion tokens minted — a mathematically large number that bears no relationship to realizable value, because the token's circulating supply is approximately 3 billion and no market could absorb even a small fraction of that volume at quoted prices. The actual extracted loss was substantially smaller. On-chain tracking by PeckShield and independent researchers indicates the attacker drained approximately 14.75 million SAND from the Ethereum OFT Adapter within the first stages of the exploit, converting that to approximately 80 ETH, worth an estimated $665,000–$675,000 at the time of the transactions. PeckShield separately reported that 14.9 billion SAND was minted across two attacker addresses (0xAbE0...4D22 and 0x638C...F296). The Sandbox's own statement placed the supply impact at less than 0.01% of total SAND. The discrepancy between the 329 trillion minted figure and the 14.9 billion PeckShield figure reflects different counting methodologies applied at different points during the multi-hour attack window; neither figure represents realizable market value.","heading":"Scale and Actual Financial Impact","severity":"high","sources":[{"credibility":3,"name":"PeckShieldAlert on X: 14.9B SAND minted across 2 addresses","type":"social_media","url":"https://x.com/PeckShieldAlert/status/2091037704314339331"},{"credibility":2,"name":"Sandbox Exploit Created $49B in Unbacked SAND Nobody Could Cash Out — EdgeX","type":"news_article","url":"https://pro.edgex.exchange/en-US/news/article/sandbox-bridge-exploit-49b-vs-675k-drain"},{"credibility":2,"name":"The Sandbox Halts Base and BNB Bridges After Exploit Mints $49B in Phantom SAND — CoinPaprika","type":"news_article","url":"https://coinpaprika.com/news/sandbox-halts-base-bnb-bridges-exploit-49b/"},{"credibility":2,"name":"The Sandbox Contains Bridge Exploit After Unbacked SAND Minted on Base and BSC — BeInCrypto","type":"news_article","url":"https://beincrypto.com/sandbox-sand-bridge-exploit-base-bsc/"}]},{"content":"The Sandbox disclosed the breach on August 22, 2026, and immediately suspended all cross-chain transfers on Base and BNB Smart Chain. At approximately 05:09:19 UTC — 24 minutes after minting activity ceased — the project's multisig removed LayerZero peer settings for the affected chains, severing cross-chain messaging and preventing further extraction attempts. The Ethereum and Polygon SAND deployments were not affected and remained operational throughout. Unbacked tokens minted on Base and BNB Smart Chain were described by The Sandbox as isolated, non-transferable, and non-redeemable against Ethereum-backed reserves. The Sandbox's official statement read: 'The Sandbox team has identified and fully contained a recent vulnerability regarding the SAND cross-chain bridge on Base and BNB Smart Chain (BSC). The impact is minimal, representing less than 0.01% of the total SAND token supply.' No timeline for restoring the Base and BNB Smart Chain bridges had been announced as of August 27, 2026. A comprehensive technical post-mortem was committed to but not published as of the same date.","heading":"Containment Response","severity":"medium","sources":[{"credibility":2,"name":"SAND bridge exploit contained after unbacked token mint — crypto.news","type":"news_article","url":"https://crypto.news/sand-bridge-exploit-contained-unbacked-token-mint/"},{"credibility":2,"name":"The Sandbox Contains Bridge Exploit After Unbacked SAND Minted on Base and BSC — BeInCrypto","type":"news_article","url":"https://beincrypto.com/sandbox-sand-bridge-exploit-base-bsc/"},{"credibility":2,"name":"The Sandbox Halts Base and BNB Bridges After Exploit Mints $49B in Phantom SAND — CoinPaprika","type":"news_article","url":"https://coinpaprika.com/news/sandbox-halts-base-bnb-bridges-exploit-49b/"}]},{"content":"The Sandbox stated it would take a snapshot of impacted liquidity pool positions from before the exploit and use that baseline to compensate eligible liquidity providers. The methodology for calculating compensation, the token or currency in which payments would be made, and any payment schedule had not been publicly disclosed as of August 27, 2026. Affected LP providers therefore lacked clarity on how losses would be measured or when they would be made whole at the time of this report.","heading":"Liquidity Provider Compensation","severity":"medium","sources":[{"credibility":2,"name":"Sandbox halts Base and BNB Chain bridging after exploit mints billions of unbacked SAND tokens — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/sandbox-halts-bridging-sand-exploit/"},{"credibility":2,"name":"SAND bridge exploit contained after unbacked token mint — crypto.news","type":"news_article","url":"https://crypto.news/sand-bridge-exploit-contained-unbacked-token-mint/"}]},{"content":"South Korean exchanges Upbit and Bithumb suspended SAND deposits and withdrawals on August 22, 2026, citing the security incident and compliance obligations under South Korea's Virtual Asset User Protection Act. Bithumb's suspension was reported at approximately 11:11 a.m. Korea Standard Time, with Upbit following shortly after. Coinbase announced the delisting of SAND perpetual futures contracts, effective August 26, 2026, as part of a broader removal of ten perpetual futures contracts that also included MEME, BIRB, BLUR, KAT, SPX, ZORA, AXS, AI, and ZRO. Open positions were to be automatically settled at an average price from the final hour of trading. Coinbase's delisting notice covered the futures instrument only; spot SAND trading on Coinbase and other venues was unaffected. SAND's spot price dropped an estimated 5.5–10% across venues in the immediate aftermath of the exploit disclosure, with derivative markets recording a 16% spike in open interest and sharply negative funding rates reflecting aggressive short positioning. Prices partially recovered once the limited actual-drain figure became more widely understood. As of August 24, 2026, reports indicated that Upbit and Bithumb were evaluating potential delisting of SAND spot trading, though no formal delisting decision had been announced.","heading":"Exchange and Market Reactions","severity":"medium","sources":[{"credibility":2,"name":"Upbit Warns, Bithumb Suspends SAND After 500M+ Token Mint Exploit on Base — CryptoNews.net","type":"news_article","url":"https://cryptonews.net/news/security/33334239/"},{"credibility":2,"name":"SAND Faces Upbit, Bithumb Delisting Risk After $49B Mint Attack — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/24/sand-faces-upbit-bithumb-delisting-risk-after-49b-mint-attack/"},{"credibility":2,"name":"Coinbase to Delist 10 Perpetual Futures Including SAND on Aug. 26 — CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/a9298-coinbase-delist-perpetual-futures-sand"},{"credibility":2,"name":"Sandbox Bridge Hack Mints 14.9B SAND While Coinbase Delists Futures — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/security/sandbox-sand-bridge-exploit-unbacked-tokens/"}]},{"content":"Multiple security analysts contextualized the SAND exploit within a pattern of LayerZero OFT-related incidents in 2026. Crypto.news reported this was described as 'the third major LayerZero-related bridge exploit in five months,' following incidents affecting Kelp DAO in April 2026 and Stake DAO in May 2026. Security researchers consistently characterized the SAND incident as an application-level failure in The Sandbox's OFT contract configuration rather than a protocol-level vulnerability in LayerZero itself. The distinction matters because it places responsibility for the security gap with The Sandbox's implementation choices rather than with the LayerZero infrastructure. The incident was reported to have contributed to a broader migration trend among DeFi protocols toward alternative cross-chain messaging infrastructure.","heading":"Broader LayerZero OFT Security Context","severity":"medium","sources":[{"credibility":2,"name":"The Sandbox's $49 billion phantom mint: how a bridge exploit created unbacked SAND tokens — crypto.news","type":"news_article","url":"https://crypto.news/sandbox-bridge-exploit-49-billion-phantom-sand-mint/"},{"credibility":2,"name":"The Sandbox Contains Bridge Exploit After Unbacked SAND Minted on Base and BSC — BeInCrypto","type":"news_article","url":"https://beincrypto.com/sandbox-sand-bridge-exploit-base-bsc/"}]},{"content":"As of August 27, 2026, several material questions remain unresolved. The Sandbox has not published a technical post-mortem, meaning the precise root cause has not been officially confirmed by the project and relies on third-party security firm reporting from Blockaid and PeckShield. The compensation plan for impacted liquidity providers lacks a published methodology, payment timeline, or funding source. The attacker or attackers have not been publicly identified. The Base and BNB Smart Chain bridges remain suspended with no restoration timeline announced. The on-chain fate of the approximately 329 trillion unbacked tokens — whether they will be burned, remain frozen, or otherwise addressed — has not been specified. Potential delisting of SAND from Upbit and Bithumb spot markets had not been resolved. Users holding SAND on Base or BNB Smart Chain should consult The Sandbox's official channels before taking any action, as those tokens remain non-redeemable against Ethereum-backed reserves.","heading":"Open Questions and Ongoing Risks","severity":"high","sources":[{"credibility":2,"name":"SAND bridge exploit contained after unbacked token mint — crypto.news","type":"news_article","url":"https://crypto.news/sand-bridge-exploit-contained-unbacked-token-mint/"},{"credibility":2,"name":"SAND Faces Upbit, Bithumb Delisting Risk After $49B Mint Attack — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/24/sand-faces-upbit-bithumb-delisting-risk-after-49b-mint-attack/"}]}],"sources_used":[{"credibility":2,"name":"Sandbox SAND Hacked: Attackers Mint 329 Trillion Tokens on Base in 5-Hour Rampage — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/22/sandbox-sand-hacked-attackers-mint-329-trillion-tokens-on-base-in-5-hour-rampage/"},{"credibility":2,"name":"The Sandbox's $49 billion phantom mint: how a bridge exploit created unbacked SAND tokens — crypto.news","type":"news_article","url":"https://crypto.news/sandbox-bridge-exploit-49-billion-phantom-sand-mint/"},{"credibility":2,"name":"SAND bridge exploit contained after unbacked token mint — crypto.news","type":"news_article","url":"https://crypto.news/sand-bridge-exploit-contained-unbacked-token-mint/"},{"credibility":2,"name":"The Sandbox Contains Bridge Exploit After Unbacked SAND Minted on Base and BSC — BeInCrypto","type":"news_article","url":"https://beincrypto.com/sandbox-sand-bridge-exploit-base-bsc/"},{"credibility":2,"name":"The Sandbox Halts Base and BNB Bridges After Exploit Mints $49B in Phantom SAND — CoinPaprika","type":"news_article","url":"https://coinpaprika.com/news/sandbox-halts-base-bnb-bridges-exploit-49b/"},{"credibility":2,"name":"Sandbox halts Base and BNB Chain bridging after exploit mints billions of unbacked SAND tokens — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/sandbox-halts-bridging-sand-exploit/"},{"credibility":1,"name":"Web3 gaming network Sandbox stops Base and BNB chain bridging after exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/web3/2026/08/22/web3-gaming-network-sandbox-stops-base-and-bnb-chain-bridging-after-exploit"},{"credibility":2,"name":"Sandbox Exploit Created $49B in Unbacked SAND Nobody Could Cash Out — EdgeX","type":"news_article","url":"https://pro.edgex.exchange/en-US/news/article/sandbox-bridge-exploit-49b-vs-675k-drain"},{"credibility":2,"name":"SAND Faces Upbit, Bithumb Delisting Risk After $49B Mint Attack — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/24/sand-faces-upbit-bithumb-delisting-risk-after-49b-mint-attack/"},{"credibility":2,"name":"Upbit Warns, Bithumb Suspends SAND After 500M+ Token Mint Exploit on Base — CryptoNews.net","type":"news_article","url":"https://cryptonews.net/news/security/33334239/"},{"credibility":2,"name":"Coinbase to Delist 10 Perpetual Futures Including SAND on Aug. 26 — CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/a9298-coinbase-delist-perpetual-futures-sand"},{"credibility":2,"name":"Sandbox Bridge Hack Mints 14.9B SAND While Coinbase Delists Futures — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/security/sandbox-sand-bridge-exploit-unbacked-tokens/"},{"credibility":3,"name":"Blockaid alert on X: ongoing exploit on SAND OFT on Base","type":"social_media","url":"https://x.com/blockaid_/status/2091016046555582891"},{"credibility":3,"name":"PeckShieldAlert on X: 14.9B SAND minted across 2 addresses","type":"social_media","url":"https://x.com/PeckShieldAlert/status/2091037704314339331"},{"credibility":2,"name":"The Sandbox Reports Security Incident Impacting Cross-Chain Bridging Infrastructure — Crowdfund Insider","type":"news_article","url":"https://www.crowdfundinsider.com/2026/08/300900-the-sandbox-reports-security-incident-impacting-cross-chain-bridging-infrastructure/"},{"credibility":2,"name":"SAND Bridge Exploit: Base and BNB Chain Isolated — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/sandbox-sand-bridge-exploit-base-bnb-chain/"}],"summary":"On August 21-22, 2026, an attacker exploited a vulnerability in The Sandbox's SAND omnichain fungible token (OFT) contract on Base and BNB Smart Chain, hijacking LayerZero delegate permissions via the approveAndCall function to mint 329.24 trillion unbacked SAND tokens across 703 transactions over approximately five hours. Although the notional face value of minted tokens was reported at approximately $49 billion, the attacker extracted an estimated $665,000-$675,000 in actual value (approximately 80 ETH) by draining the Ethereum OFT Adapter before The Sandbox halted bridging and severed LayerZero peer connections. The Sandbox characterized the direct supply impact as less than 0.01% of the 3 billion total SAND supply and stated it would compensate eligible liquidity providers using a pre-incident snapshot.","timeline":[{"date":"2026-08-21","event":"Attack begins at approximately 23:42:05 UTC. Attacker exploits approveAndCall function on SAND OFT contract on Base, hijacking LayerZero delegate permissions and beginning unbacked token minting.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/08/22/sandbox-sand-hacked-attackers-mint-329-trillion-tokens-on-base-in-5-hour-rampage/"},{"date":"2026-08-22","event":"Attack ceases at approximately 04:45:21 UTC. By this point 329.24 trillion unbacked SAND have been minted across 703 transactions to 173 addresses. Approximately 80 ETH (~$675,000) has been extracted from the Ethereum OFT Adapter.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/08/22/sandbox-sand-hacked-attackers-mint-329-trillion-tokens-on-base-in-5-hour-rampage/"},{"date":"2026-08-22","event":"At approximately 05:09:19 UTC — 24 minutes after minting stops — The Sandbox multisig removes LayerZero peer settings for Base and BNB Smart Chain, severing cross-chain messaging.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/08/22/sandbox-sand-hacked-attackers-mint-329-trillion-tokens-on-base-in-5-hour-rampage/"},{"date":"2026-08-22","event":"Blockaid posts public alert on X flagging approximately $49 billion face-value SAND minted in an ongoing exploit. PeckShield separately reports 14.9 billion SAND minted across two attacker addresses.","source":"Blockaid / PeckShield via X","source_url":"https://x.com/blockaid_/status/2091016046555582891"},{"date":"2026-08-22","event":"The Sandbox discloses breach publicly and halts Base and BNB Smart Chain bridging. Issues official statement characterizing impact as less than 0.01% of total SAND supply. Announces LP compensation snapshot plan.","source":"CoinPaprika","source_url":"https://coinpaprika.com/news/sandbox-halts-base-bnb-bridges-exploit-49b/"},{"date":"2026-08-22","event":"South Korean exchanges Bithumb (approximately 11:11 a.m. KST) and Upbit suspend SAND deposits and withdrawals citing the security incident.","source":"CryptoNews.net","source_url":"https://cryptonews.net/news/security/33334239/"},{"date":"2026-08-24","event":"Reports emerge that Upbit and Bithumb are evaluating potential spot delisting of SAND. No formal delisting decision announced.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/08/24/sand-faces-upbit-bithumb-delisting-risk-after-49b-mint-attack/"},{"date":"2026-08-26","event":"Coinbase delists SAND perpetual futures contracts along with nine other tokens. Open positions auto-settled at average price from the final hour of trading. Spot SAND unaffected on Coinbase.","source":"CryptoRank","source_url":"https://cryptorank.io/news/feed/a9298-coinbase-delist-perpetual-futures-sand"},{"date":"2026-08-27","event":"As of this date, The Sandbox has not published a technical post-mortem, bridge restoration timeline, or LP compensation methodology. Base and BNB Smart Chain bridges remain suspended.","source":"crypto.news","source_url":"https://crypto.news/sand-bridge-exploit-contained-unbacked-token-mint/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 6375cbc6-8dee-41ba-a58d-7162f1621d0a
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.