Skip to main content
Sign in

Audit log

Every state-changing event for The Sandbox SAND — LayerZero Bridge Exploit August 2026: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-25 23:04:20Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    8Cx1XzzM1R6e…47ZiLu4Usha256 → base58
    verifying row…
    canonical bytes (24522 B) ▸
    {"actor":"system:backfill","investigation_id":"46ff4b2e-0b25-454c-9f21-15d1714c0143","kind":"publish","page_slug":"the-sandbox-sand-layerzero-bridge-exploit-august-2026","published_at":"2026-08-25T23:04:20.914Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"The Sandbox SAND — LayerZero Bridge Exploit August 2026","sections":[{"content":"The exploit began at approximately 23:42:05 UTC on August 21, 2026, and continued until 04:45:21 UTC on August 22, 2026, a window of roughly five hours. Security firm Blockaid detected the attack and flagged approximately $49 billion in face-value SAND minted across more than 400 transactions. That headline figure is misleading: it represents the prevailing market price of legitimate SAND multiplied by the number of unbacked tokens minted on-chain, not the value of assets extracted. Actual economic damage was approximately $675,000, derived from draining roughly 14.75 million legitimate SAND from the Ethereum OFT Adapter within the first minute of the attack. The Sandbox confirmed the incident on August 22, 2026, stating 'All bridged SAND funds are backed by SAND locked on Ethereum, which remains entirely secure,' and characterizing the direct impact as less than 0.01% of the 3-billion token total supply. No individual user wallets were compromised. SAND holdings on Ethereum and Polygon were confirmed unaffected.","heading":"Incident Overview","severity":"high","sources":[{"credibility":2,"name":"The Sandbox SAND bridge exploit contained after unbacked token mint — crypto.news","type":"news_article","url":"https://crypto.news/sand-bridge-exploit-contained-unbacked-token-mint/"},{"credibility":2,"name":"The Sandbox SAND bridge exploit: $49B phantom mint — crypto.news","type":"news_article","url":"https://crypto.news/sandbox-bridge-exploit-49-billion-phantom-sand-mint/"},{"credibility":2,"name":"Sandbox exploit created $49B in unbacked SAND nobody could cash out — EdgeX","type":"news_article","url":"https://pro.edgex.exchange/en-US/news/article/sandbox-bridge-exploit-49b-vs-675k-drain"}]},{"content":"Security firm Blockaid attributed the exploit to 'takeover of LayerZero delegate permissions through an approveAndCall function' on The Sandbox's SAND OFT contract deployed on Base. The approveAndCall function is an ERC-20 extension designed to improve user experience by combining token approval and contract call into one transaction. Attackers routed a crafted payload through this function to the LayerZero endpoint, granting attacker-controlled contracts delegate-level administrative rights over the Base OFT contract. With those elevated permissions, the attacker could mint unbacked SAND on Base and BNB Smart Chain without triggering corresponding burns or lock events on Ethereum — subverting the lock-and-mint model that cross-chain OFT bridges depend on. The attacker address had reportedly been dormant for 313 days before the attack, with its Relay Solver funded 313 days prior to execution. Blockaid's analysis identified two primary recipient wallets: 0xAbE0...4D22 and 0x638C...F296, with the latter holding approximately 250 million SAND at the time of reporting. PeckShield's parallel analysis counted approximately 14.9 billion SAND distributed to those two addresses, a figure reflecting a different measurement window than the 329.24 trillion total minting figure. An important editorial note: reporting consistently attributes the root vulnerability to The Sandbox's OFT contract configuration rather than a flaw in the LayerZero protocol itself. The EdgeX analysis specifically cautioned that framing this as 'LayerZero was hacked' overstates confirmed findings; the confirmed issue was that delegate permissions associated with The Sandbox's specific OFT deployment were abused. LayerZero had not formally responded to the incident in available reporting.","heading":"Technical Root Cause","severity":"critical","sources":[{"credibility":2,"name":"Sandbox exploit: 329 trillion tokens minted on Base in 5-hour rampage — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/22/sandbox-sand-hacked-attackers-mint-329-trillion-tokens-on-base-in-5-hour-rampage/"},{"credibility":2,"name":"Sandbox bridge exploit $49B vs $675K drain — EdgeX","type":"news_article","url":"https://pro.edgex.exchange/en-US/news/article/sandbox-bridge-exploit-49b-vs-675k-drain"},{"credibility":2,"name":"The Sandbox SAND bridge exploit attacker mints 14.9B unbacked tokens — Blockonomi","type":"news_article","url":"https://blockonomi.com/the-sandbox-sand-bridge-exploit-attacker-mints-14-9b-unbacked-tokens-on-base-network"}]},{"content":"Multiple distinct figures circulated in the aftermath of this incident, and they measure different things. The $49 billion figure cited by Blockaid and widely repeated in coverage represents the face value of all unbacked tokens minted on-chain, calculated by multiplying the prevailing market price of legitimate SAND by 329.24 trillion newly minted tokens. This is not a measure of extracted value. The EdgeX analysis described it as 'more than 70,000 times larger than the estimated reserve drain.' Actual economic extraction was approximately 14.75 million SAND removed from the Ethereum OFT Adapter — the contract holding legitimate SAND reserves backing cross-chain operations — within approximately one minute of the attack commencing. Converted at contemporaneous market rates, the Ethereum adapter drain yielded roughly 80 ETH, valued at approximately $675,000. The Ethereum adapter balance was reduced to 0.0056 SAND following the drain, after which no further legitimate SAND could be extracted regardless of the volume of unbacked tokens still being minted. SAND's price fell approximately 5.5–10% across venues following public disclosure, trading at approximately $0.043 with a market capitalization near $115 million as of August 24, 2026. Coinbase announced plans to delist SAND perpetual futures contracts on August 26, 2026, alongside nine other tokens; the exploit was coincident with, but not formally cited as the sole cause of, that decision.","heading":"Financial Impact and Headline Figure Discrepancy","severity":"high","sources":[{"credibility":2,"name":"Sandbox exploit $49B vs $675K drain — EdgeX","type":"news_article","url":"https://pro.edgex.exchange/en-US/news/article/sandbox-bridge-exploit-49b-vs-675k-drain"},{"credibility":2,"name":"Sandbox bridge hack mints 14.9B SAND while Coinbase delists futures — news.bitcoin.com","type":"news_article","url":"https://news.bitcoin.com/security/sandbox-sand-bridge-exploit-unbacked-tokens/"},{"credibility":2,"name":"Coinbase to delist 10 perpetual futures including SAND on August 26 — CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/a9298-coinbase-delist-perpetual-futures-sand"},{"credibility":2,"name":"The Sandbox SAND exploit — coinpaprika","type":"news_article","url":"https://coinpaprika.com/news/sandbox-halts-base-bnb-bridges-exploit-49b/"}]},{"content":"The Sandbox's multisig wallet executed a containment transaction at approximately 05:09:19 UTC on August 22, 2026 — roughly 24 minutes after the minting activity ceased. The multisig zeroed out trusted LayerZero peer settings for endpoint IDs 30101 (Ethereum) and 30102 (Base), effectively severing the Base OFT contract's ability to communicate with the Ethereum adapter. Bridging was disabled on both Base and BNB Smart Chain. The Ethereum and Polygon deployments of SAND remained operational and unaffected throughout the incident. South Korean exchanges Upbit and Bithumb halted SAND deposits and withdrawals as a precautionary measure following public disclosure. Spot SAND trading continued on those platforms. The Sandbox committed to compensating eligible liquidity providers using a pre-incident snapshot of affected pool balances, following precedent from Wormhole (2022) and Ronin (2022) recovery procedures. The Sandbox warned users explicitly not to trade SAND on Base or BNB Smart Chain, characterizing the tokens remaining on those networks as carrying 'zero backing and will likely never be honored.' A full technical post-mortem was promised but had not been published as of available reporting. Animoca Brands, The Sandbox's parent company, had not issued a public statement as of available reporting.","heading":"Response and Containment","severity":"medium","sources":[{"credibility":2,"name":"SAND bridge exploit contained after unbacked token mint — crypto.news","type":"news_article","url":"https://crypto.news/sand-bridge-exploit-contained-unbacked-token-mint/"},{"credibility":2,"name":"Sandbox halts Base and BNB Chain bridging after exploit — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/sandbox-halts-bridging-sand-exploit/"},{"credibility":2,"name":"The Sandbox security breach — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/sandbox-security-breach-500m-sand-minted/"}]},{"content":"The Sandbox incident occurred within a sequence of major bridge exploits involving LayerZero infrastructure over a five-month period in 2026. The first was the Kelp DAO exploit on approximately April 18, 2026, in which an attacker drained 116,500 rsETH from Kelp's rsETH bridge, causing approximately $292 million in losses. LayerZero's post-mortem linked the breach to North Korea's Lazarus Group, which reportedly socially engineered a LayerZero Labs developer in March 2026 to harvest session keys. LayerZero attributed the vulnerability to Kelp's use of a single-verifier (1-of-1 DVN) bridge configuration rather than the recommended multi-DVN setup. Kelp disputed this, claiming LayerZero personnel had reviewed and implicitly approved the single-verifier configuration across eight integration meetings spanning 2.5 years. LayerZero's CEO Bryan Pellegrino rejected this characterization. The legal dispute extended to approximately $71 million in exploit-linked ETH frozen on Arbitrum. The second incident involved Stake DAO on approximately May 27, 2026, in which an attacker used a compromised deployer key to reset Stake DAO's LayerZero v2 bridge peer configuration for vsdCRV, redirecting it to a malicious contract that sent forged cross-chain messages triggering 5.4 trillion unbacked vsdCRV mints on Arbitrum. The attacker extracted approximately 43.78 ETH (around $91,000). Security firms Blockaid, BlockSec, and PeckShield confirmed no smart contract bug was involved in Stake DAO; the exploit vector was centralized operational key management. The Stake DAO vsdCRV bridge between Ethereum and Arbitrum was permanently closed following the incident. The three incidents share a structural pattern: attacker access to privileged administrative permissions — whether through social engineering, compromised keys, or contract-level delegation abuse — enabled unbacked token minting that bypassed the reserve-verification logic of the underlying OFT framework.","heading":"Context: Third Major LayerZero Bridge Incident in Five Months","severity":"high","sources":[{"credibility":2,"name":"Kelp DAO claims LayerZero approved setup blamed for $292M hack, migrates to Chainlink — Unchained","type":"news_article","url":"https://unchainedcrypto.com/kelp-dao-claims-layerzero-approved-the-setup-it-blamed-for-292-million-hack-migrates-to-chainlink/"},{"credibility":1,"name":"Kelp DAO ditches LayerZero for Chainlink after $292M exploit — The Block","type":"news_article","url":"https://www.theblock.co/post/400131/kelp-dao-ditches-layerzero-chainlink-cross-chain-infrastructure-292-million-exploit"},{"credibility":2,"name":"Stake DAO exploit: attacker mints 5.4T vsdCRV on Arbitrum — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/stake-dao-exploit-vsdcrv-arbitrum/"},{"credibility":2,"name":"Stake DAO exploited: hacker mints 5.4 trillion fake vsdCRV — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/05/27/stake-dao-exploited-as-hacker-mints-5-4-trillion-fake-vsdcrv/"},{"credibility":1,"name":"Kelp says LayerZero approved setup it blamed for $292M bridge hack — CoinDesk","type":"news_article","url":"https://www.coindesk.com/web3/2026/05/05/kelp-claims-that-layerzero-approved-the-setup-it-blamed-for-usd292-million-bridge-hack"}]},{"content":"The cumulative effect of the three incidents accelerated a pre-existing shift away from LayerZero toward Chainlink's Cross-Chain Interoperability Protocol (CCIP). As of approximately August 20, 2026 — two days before the Sandbox incident — publicly announced migrations from LayerZero to Chainlink CCIP had reached approximately $15 billion in total value. BitGo announced a migration of approximately $7.4 billion in wrapped Bitcoin (WBTC), described as the largest single transfer in the wave. Wyoming's stablecoin infrastructure initiatives also moved to CCIP. Kelp DAO described itself as 'the first major protocol to move away from LayerZero since the exploit.' The architectural argument for CCIP centers on its requirement for multiple independent oracle networks to approve each cross-chain transfer, in contrast to single-verifier or configurable DVN setups that characterize LayerZero's OFT standard. The Sandbox had not announced a migration to an alternative cross-chain standard as of available reporting.","heading":"Industry Migration: LayerZero to Chainlink CCIP","severity":"medium","sources":[{"credibility":2,"name":"LayerZero crypto migration hits $15B as BitGo, Wyoming exit to Chainlink — CryptoNomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/08/20/layerzero-crypto-migration-shift/"},{"credibility":2,"name":"$15B exodus: why crypto is leaving LayerZero for Chainlink — crypto.news","type":"news_article","url":"https://crypto.news/layerzero-chainlink-exodus-15-billion-bridge-migration/"},{"credibility":2,"name":"KelpDAO slams LayerZero after $300M exploit, shifts rsETH to Chainlink CCIP — Bitcoin.com","type":"news_article","url":"https://news.bitcoin.com/kelpdao-slams-layerzero-after-300m-exploit-shifts-rseth-to-chainlink-ccip/"}]},{"content":"Several material facts remained unresolved or unconfirmed in available reporting as of August 25, 2026. The Sandbox had not published a formal technical post-mortem. LayerZero had not publicly responded to the Sandbox incident specifically. Animoca Brands, The Sandbox's parent company, had not commented. The compensation plan for affected liquidity providers lacked a payment timeline, eligibility criteria detail, or claim-opening date. It is not confirmed whether the attacker's identity or the precise method by which delegate permissions were obtained (beyond the approveAndCall vector) has been established. The Coinbase SAND futures delisting on August 26 was announced in the context of a ten-token batch review; Coinbase did not formally cite the exploit as the reason, and it is not established that the two events are causally linked rather than coincident. The characterization of this incident as the 'third major LayerZero bridge exploit' reflects reporting framing; a key distinction noted across sources is that the Sandbox and Stake DAO incidents may reflect exploited administrative permission configurations rather than vulnerabilities intrinsic to the LayerZero protocol itself, a distinction that LayerZero contested in the Kelp DAO dispute context.","heading":"Outstanding Uncertainties and Pending Items","severity":"low","sources":[{"credibility":2,"name":"Sandbox exploit contained — crypto.news","type":"news_article","url":"https://crypto.news/sand-bridge-exploit-contained-unbacked-token-mint/"},{"credibility":2,"name":"Sandbox bridge exploit $49B vs $675K — EdgeX","type":"news_article","url":"https://pro.edgex.exchange/en-US/news/article/sandbox-bridge-exploit-49b-vs-675k-drain"}]}],"sources_used":[{"credibility":2,"name":"The Sandbox's $49 billion phantom mint — crypto.news","type":"news_article","url":"https://crypto.news/sandbox-bridge-exploit-49-billion-phantom-sand-mint/"},{"credibility":2,"name":"SAND bridge exploit contained after unbacked token mint — crypto.news","type":"news_article","url":"https://crypto.news/sand-bridge-exploit-contained-unbacked-token-mint/"},{"credibility":2,"name":"Sandbox SAND hacked — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/22/sandbox-sand-hacked-attackers-mint-329-trillion-tokens-on-base-in-5-hour-rampage/"},{"credibility":2,"name":"Sandbox security breach — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/sandbox-security-breach-500m-sand-minted/"},{"credibility":2,"name":"Sandbox halts Base and BNB Chain bridging — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/sandbox-halts-bridging-sand-exploit/"},{"credibility":2,"name":"Sandbox bridge exploit $49B vs $675K drain — EdgeX","type":"news_article","url":"https://pro.edgex.exchange/en-US/news/article/sandbox-bridge-exploit-49b-vs-675k-drain"},{"credibility":2,"name":"Sandbox SAND bridge exploit — Blockonomi","type":"news_article","url":"https://blockonomi.com/the-sandbox-sand-bridge-exploit-attacker-mints-14-9b-unbacked-tokens-on-base-network"},{"credibility":2,"name":"The Sandbox SAND exploit: $49B in new tokens flood Base — CoinPaprika","type":"news_article","url":"https://coinpaprika.com/news/sandbox-halts-base-bnb-bridges-exploit-49b/"},{"credibility":2,"name":"Sandbox bridge hack mints 14.9B SAND while Coinbase delists futures — news.bitcoin.com","type":"news_article","url":"https://news.bitcoin.com/security/sandbox-sand-bridge-exploit-unbacked-tokens/"},{"credibility":2,"name":"Coinbase to delist 10 perpetual futures including SAND on August 26 — CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/a9298-coinbase-delist-perpetual-futures-sand"},{"credibility":2,"name":"Kelp DAO claims LayerZero approved setup blamed for $292M hack — Unchained","type":"news_article","url":"https://unchainedcrypto.com/kelp-dao-claims-layerzero-approved-the-setup-it-blamed-for-292-million-hack-migrates-to-chainlink/"},{"credibility":1,"name":"Kelp says LayerZero approved setup blamed for $292M bridge hack — CoinDesk","type":"news_article","url":"https://www.coindesk.com/web3/2026/05/05/kelp-claims-that-layerzero-approved-the-setup-it-blamed-for-usd292-million-bridge-hack"},{"credibility":1,"name":"Kelp DAO ditches LayerZero for Chainlink after $292M exploit — The Block","type":"news_article","url":"https://www.theblock.co/post/400131/kelp-dao-ditches-layerzero-chainlink-cross-chain-infrastructure-292-million-exploit"},{"credibility":2,"name":"Stake DAO exploit: attacker mints 5.4T vsdCRV on Arbitrum — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/stake-dao-exploit-vsdcrv-arbitrum/"},{"credibility":2,"name":"Stake DAO exploited: hacker mints 5.4 trillion fake vsdCRV — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/05/27/stake-dao-exploited-as-hacker-mints-5-4-trillion-fake-vsdcrv/"},{"credibility":2,"name":"LayerZero crypto migration hits $15B — CryptoNomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/08/20/layerzero-crypto-migration-shift/"},{"credibility":2,"name":"$15B exodus: why crypto is leaving LayerZero for Chainlink — crypto.news","type":"news_article","url":"https://crypto.news/layerzero-chainlink-exodus-15-billion-bridge-migration/"},{"credibility":2,"name":"KelpDAO slams LayerZero after $300M exploit, shifts rsETH to Chainlink CCIP — Bitcoin.com","type":"news_article","url":"https://news.bitcoin.com/kelpdao-slams-layerzero-after-300m-exploit-shifts-rseth-to-chainlink-ccip/"},{"credibility":2,"name":"Sandbox SAND exploit: $49B in new tokens — BeInCrypto","type":"news_article","url":"https://beincrypto.com/sandbox-sand-bridge-exploit-base-bsc/"}],"summary":"On August 21–22, 2026, an attacker exploited a vulnerability in The Sandbox's SAND omnichain fungible token (OFT) contract on Base by hijacking LayerZero delegate permissions through the approveAndCall function, enabling unauthorized minting of approximately 329.24 trillion unbacked SAND tokens across 703 events over five hours. Actual financial extraction was substantially lower than headline figures: roughly 14.75 million SAND drained from the Ethereum OFT Adapter yielded approximately 80 ETH (~$675,000), while The Sandbox estimated the incident affected less than 0.01% of the 3-billion total SAND supply. The exploit was the third major LayerZero bridge incident in five months and contributed to accelerating an industry-wide migration from LayerZero to Chainlink CCIP, with publicly announced moves totaling approximately $15 billion.","timeline":[{"date":"2026-03-06","event":"Alleged Lazarus Group social engineering of a LayerZero Labs developer, reportedly harvesting session keys that later enabled access into LayerZero's RPC cloud environment.","source":"Unchained Crypto","source_url":"https://unchainedcrypto.com/kelp-dao-claims-layerzero-approved-the-setup-it-blamed-for-292-million-hack-migrates-to-chainlink/"},{"date":"2026-04-18","event":"Kelp DAO's rsETH LayerZero bridge exploited; approximately 116,500 rsETH (~$292 million) drained. LayerZero attributed the root cause to Kelp's single-verifier bridge configuration; Kelp disputed this attribution.","source":"CoinDesk / The Block","source_url":"https://www.coindesk.com/web3/2026/05/05/kelp-claims-that-layerzero-approved-the-setup-it-blamed-for-usd292-million-bridge-hack"},{"date":"2026-05-27","event":"Stake DAO's vsdCRV LayerZero v2 bridge exploited via a compromised deployer key; attacker minted approximately 5.4 trillion unbacked vsdCRV on Arbitrum and extracted roughly 43.78 ETH (~$91,000). vsdCRV bridge permanently closed.","source":"CryptoBriefing / CryptoTimes","source_url":"https://cryptobriefing.com/stake-dao-exploit-vsdcrv-arbitrum/"},{"date":"2026-08-20","event":"Publicly announced migrations from LayerZero to Chainlink CCIP reach approximately $15 billion, led by BitGo's $7.4 billion WBTC migration. Article published two days before the Sandbox incident.","source":"CryptoNomist","source_url":"https://en.cryptonomist.ch/2026/08/20/layerzero-crypto-migration-shift/"},{"date":"2026-08-21","event":"Exploit begins at approximately 23:42:05 UTC. Attacker uses the approveAndCall function on The Sandbox's SAND OFT contract on Base to hijack LayerZero delegate permissions, enabling unbacked SAND minting.","source":"CryptoTimes / crypto.news","source_url":"https://www.cryptotimes.io/2026/08/22/sandbox-sand-hacked-attackers-mint-329-trillion-tokens-on-base-in-5-hour-rampage/"},{"date":"2026-08-22","event":"Minting activity continues until approximately 04:45:21 UTC; 329.24 trillion unbacked SAND minted across 703 events. The Ethereum OFT Adapter is drained of approximately 14.75 million SAND (~80 ETH, ~$675,000) within the first minute. Blockaid publicly alerts on the incident, citing $49 billion in face-value minting across 400+ transactions.","source":"crypto.news / Blockaid / CryptoTimes","source_url":"https://crypto.news/sandbox-bridge-exploit-49-billion-phantom-sand-mint/"},{"date":"2026-08-22","event":"The Sandbox's multisig executes containment at approximately 05:09:19 UTC, zeroing LayerZero peer settings for Ethereum (ID 30101) and Base (ID 30102). Bridging disabled on Base and BNB Smart Chain. Ethereum and Polygon SAND confirmed unaffected.","source":"crypto.news / CryptoBriefing","source_url":"https://crypto.news/sand-bridge-exploit-contained-unbacked-token-mint/"},{"date":"2026-08-22","event":"South Korean exchanges Upbit and Bithumb halt SAND deposits and withdrawals. SAND price declines approximately 5.5–10% intraday across venues.","source":"CryptoBriefing / CoinPaprika","source_url":"https://cryptobriefing.com/sandbox-halts-bridging-sand-exploit/"},{"date":"2026-08-22","event":"The Sandbox issues public statement confirming the breach, characterizing impact as less than 0.01% of total SAND supply, and committing to LP compensation using a pre-incident snapshot. No technical post-mortem published.","source":"crypto.news","source_url":"https://crypto.news/sand-bridge-exploit-contained-unbacked-token-mint/"},{"date":"2026-08-26","event":"Coinbase scheduled to delist SAND perpetual futures contracts alongside nine other tokens, following a periodic liquidity and regulatory review announced after the exploit.","source":"CryptoRank / news.bitcoin.com","source_url":"https://cryptorank.io/news/feed/a9298-coinbase-delist-perpetual-futures-sand"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision dddc2198-07b8-4814-87c2-a63c828e27ea
  2. #2reviewby reviewerreviewer
    2026-08-26 00:03:50Z
    Score: 2222 (no score change)
    The page's central technical, financial, and fault-attribution claims are well supported by its cited sources, including granular details (timestamps, endpoint IDs, wallet addresses) that were independently verified against the underlying reporting. Fault attribution correctly follows sources in placing the root cause with The Sandbox's own OFT deployment configuration rather than LayerZero's core protocol. The main weaknesses are: The Sandbox's own 'less than 0.01%' impact framing is presented with less skepticism than independent coverage warrants, a Wormhole/Ronin compensation-precedent comparison appears to be uncited editorializing, a handful of granular figures (e.g., 0.0056 SAND residual balance) could not be independently traced to any source, and the page's account of exchange-delisting risk is not current as of the most recent (Aug 24) reporting.
    anchorpending
    chain
    hash
    97wW4cZseFVh…SEC4Qkz9sha256 → base58
    verifying row…
    canonical bytes (1257 B) ▸
    {"actor":"reviewer","decided_at":"2026-08-26T00:03:50.648Z","decision":"review","investigation_id":"46ff4b2e-0b25-454c-9f21-15d1714c0143","new_score":22,"page_slug":"the-sandbox-sand-layerzero-bridge-exploit-august-2026","prev_score":22,"reason":"The page's central technical, financial, and fault-attribution claims are well supported by its cited sources, including granular details (timestamps, endpoint IDs, wallet addresses) that were independently verified against the underlying reporting. Fault attribution correctly follows sources in placing the root cause with The Sandbox's own OFT deployment configuration rather than LayerZero's core protocol. The main weaknesses are: The Sandbox's own 'less than 0.01%' impact framing is presented with less skepticism than independent coverage warrants, a Wormhole/Ronin compensation-precedent comparison appears to be uncited editorializing, a handful of granular figures (e.g., 0.0056 SAND residual balance) could not be independently traced to any source, and the page's account of exchange-delisting risk is not current as of the most recent (Aug 24) reporting.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision a43bb581-5aff-47f4-97d9-e4471c89fea2
  3. #3review reviseby judgejudge
    2026-08-26 00:03:50Z
    Score: 2212 (-10)
    Recomputing from the reviewer's 32-entry claim array (not the mismatched summary totals) gives 26 confirmed, 2 partially supported, 4 unverifiable, and 0 disputed, for a disputed_pct of 12.5% under the reviewer's own (disputed + unverifiable) / total formula — placing this page in the minor-issues band. The page's central claims hold up well: the exploit mechanism, financial figures, and the fault-attribution finding placing responsibility on The Sandbox's own contract configuration rather than LayerZero's core protocol (claim_findings[13]) are all confirmed against independent reporting, as is the $675,000 actual-loss figure against the $49 billion face-value figure (claim_findings[2], claim_findings[8]). The issues that keep this out of approval are narrower: the page repeats The Sandbox's 'less than 0.01% of supply' framing without adequately flagging that independent on-chain data described roughly five times total supply as minted (claim_findings[3]), a Wormhole/Ronin compensation-precedent comparison appears to be uncited editorializing rather than sourced fact (claim_findings[21]), and a high-priority coverage gap means the page's account of exchange halts is stale — Upbit has since moved to a formal delisting-warning status not reflected on the page (coverage_gaps[0]). None of these rise to disputed core claims, and reviewer confidence (0.78) supports treating this as a revision matter rather than a denial.
    anchorpending
    chain
    hash
    7YyhhMNPJt5b…tW3kmnhXsha256 → base58
    verifying row…
    canonical bytes (1833 B) ▸
    {"actor":"judge","decided_at":"2026-08-26T00:03:50.648Z","decision":"review_revise","investigation_id":"46ff4b2e-0b25-454c-9f21-15d1714c0143","new_score":12,"page_slug":"the-sandbox-sand-layerzero-bridge-exploit-august-2026","prev_score":22,"reason":"Recomputing from the reviewer's 32-entry claim array (not the mismatched summary totals) gives 26 confirmed, 2 partially supported, 4 unverifiable, and 0 disputed, for a disputed_pct of 12.5% under the reviewer's own (disputed + unverifiable) / total formula — placing this page in the minor-issues band. The page's central claims hold up well: the exploit mechanism, financial figures, and the fault-attribution finding placing responsibility on The Sandbox's own contract configuration rather than LayerZero's core protocol (claim_findings[13]) are all confirmed against independent reporting, as is the $675,000 actual-loss figure against the $49 billion face-value figure (claim_findings[2], claim_findings[8]). The issues that keep this out of approval are narrower: the page repeats The Sandbox's 'less than 0.01% of supply' framing without adequately flagging that independent on-chain data described roughly five times total supply as minted (claim_findings[3]), a Wormhole/Ronin compensation-precedent comparison appears to be uncited editorializing rather than sourced fact (claim_findings[21]), and a high-priority coverage gap means the page's account of exchange halts is stale — Upbit has since moved to a formal delisting-warning status not reflected on the page (coverage_gaps[0]). None of these rise to disputed core claims, and reviewer confidence (0.78) supports treating this as a revision matter rather than a denial.","score_delta":-10,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 2a24252b-e6b4-4a91-b306-f429a395578d
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.