Skip to main content
Sign in
The Sandbox (SAND)1 decision on this page

Audit log

Every state-changing event for The Sandbox (SAND): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-24 12:09:20Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    49HaKmEB1UDV…gCcFpuQ5sha256 → base58
    verifying row…
    canonical bytes (26665 B) ▸
    {"actor":"system:backfill","investigation_id":"c755b6a4-dcf8-43cf-9777-53595004dc81","kind":"publish","page_slug":"the-sandbox-sand","published_at":"2026-08-24T12:09:20.024Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"The Sandbox (SAND)","sections":[{"content":"On August 21–22, 2026, an unidentified attacker exploited a vulnerability in The Sandbox's SAND Omnichain Fungible Token (OFT) bridge deployed on Base and BNB Smart Chain. The exploit began at approximately 23:42:05 UTC on August 21 and minting activity ceased around 04:45:21 UTC on August 22, a span of roughly five hours. Blockchain security firm Blockaid flagged the anomaly in real time. The Sandbox's multisig zeroed out trusted LayerZero peer settings for the affected endpoints at approximately 05:09:19 UTC on August 22, containing the minting.\n\nThe attacker exploited the token contract's approveAndCall function — an ERC-20 extension designed to combine approval and contract calls in a single transaction — routing a crafted payload through the SAND contract into the LayerZero endpoint. This granted the attacker's helper contract LayerZero delegate standing on Base. In the OFT framework, each chain deployment has a delegate address with configuration rights over how the chain's OFT contract verifies and executes cross-chain messages, including the authority to set trusted peers and authorize privileged calls. Once the delegate role was hijacked, the Base OFT contract no longer required a legitimate SAND burn on the source chain to authorize minting on the destination chain, removing the critical cross-chain verification requirement.\n\nThe scale of the unauthorized minting was 329.24 trillion SAND across 703 distinct events directed to 173 different addresses, with an initial wave of approximately 14.9 billion SAND sent to two attacker-controlled wallets. On-chain analysis identified two primary attacker addresses: 0xAbE0...4D22 and 0x638C...F296 (the latter holding approximately 250 million SAND and originally funded 313 days before the attack, suggesting pre-positioned infrastructure).\n\nDespite the notional face-value figure of approximately $49 billion, actual economic extraction was far smaller. The attacker drained the Ethereum OFT Adapter — reducing its balance from 14,769,723 SAND to approximately 0.0056 SAND — across six transactions executed within approximately 24 seconds, consistent with automated script behavior. Approximately 14.75 million SAND was transferred, yielding roughly 79.74 ETH at approximately $675,000 in value at the time of the transactions. The $49 billion figure reflects the minted token count multiplied by the prevailing SAND market price, not redeemable liquidity, as the unbacked tokens could not be converted against Ethereum reserves.","heading":"August 2026 SAND OFT Bridge Exploit","severity":"high","sources":[{"credibility":2,"name":"Sandbox SAND Hacked: Attackers Mint 329 Trillion Tokens on Base in 5-Hour Rampage — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/22/sandbox-sand-hacked-attackers-mint-329-trillion-tokens-on-base-in-5-hour-rampage/"},{"credibility":2,"name":"The Sandbox's $49 billion phantom mint: how a bridge exploit created unbacked SAND tokens — Crypto.news","type":"news_article","url":"https://crypto.news/sandbox-bridge-exploit-49-billion-phantom-sand-mint/"},{"credibility":2,"name":"The Sandbox (SAND) Bridge Exploit: Attacker Mints 14.9B Unbacked Tokens on Base Network — Blockonomi","type":"news_article","url":"https://blockonomi.com/the-sandbox-sand-bridge-exploit-attacker-mints-14-9b-unbacked-tokens-on-base-network"},{"credibility":2,"name":"Sandbox Exploit Created $49B in Unbacked SAND Nobody Could Cash Out — EdgeX","type":"news_article","url":"https://pro.edgex.exchange/en-US/news/article/sandbox-bridge-exploit-49b-vs-675k-drain"}]},{"content":"The Sandbox disclosed the exploit publicly on August 22, 2026, and stated that its team had identified and fully contained the vulnerability. The team disabled cross-chain bridging to and from Base and BNB Smart Chain, removed LayerZero peer settings via multisig, and confirmed that SAND on Base and BSC was isolated and could not be moved or redeemed against Ethereum reserves. The project stated that all bridged SAND funds are backed by SAND locked on Ethereum, which remained entirely secure, and that Ethereum and Polygon deployments were unaffected.\n\nThe Sandbox estimated the actual impact at less than 0.01% of the total 3 billion SAND supply. The project warned users not to buy, sell, or provide liquidity for SAND on Base or BNB Smart Chain while the affected deployments remained isolated, noting that the unbacked tokens carried zero redeemable value. The team announced plans to prepare a snapshot of affected liquidity pools and develop a compensation plan for eligible liquidity providers, with a full technical incident report and post-mortem to follow.\n\nSouth Korean exchanges Upbit and Bithumb suspended SAND deposits and withdrawals, citing suspected security incidents under South Korea's Virtual Asset User Protection Act. Coinbase announced it would delist SAND perpetual futures contracts effective August 26, 2026, as part of a broader delisting of ten tokens. Notably, the SAND spot price response was muted to positive on the day of disclosure, trading up approximately 1.6–4.8% with elevated volume, suggesting the market credited the containment response.","heading":"The Sandbox's Response and Containment","severity":"medium","sources":[{"credibility":2,"name":"The Sandbox Contains Bridge Exploit After Unbacked SAND Minted on Base and BSC — BeInCrypto","type":"news_article","url":"https://beincrypto.com/sandbox-sand-bridge-exploit-base-bsc/"},{"credibility":2,"name":"Sandbox halts Base and BNB Chain bridging after exploit mints billions of unbacked SAND tokens — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/sandbox-halts-bridging-sand-exploit/"},{"credibility":2,"name":"The Sandbox Confirms SAND Cross-Chain Bridge Vulnerability, Pauses Base and BSC Functions — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/the-sandbox-confirms-sand-cross-chain-bridge-vulnerability-pauses-base-and-bsc-functions"},{"credibility":2,"name":"SAND bridge exploit contained after unbacked token mint — Crypto.news","type":"news_article","url":"https://crypto.news/sand-bridge-exploit-contained-unbacked-token-mint/"},{"credibility":2,"name":"Sandbox Bridge Hack Mints 14.9B SAND While Coinbase Delists Futures — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/security/sandbox-sand-bridge-exploit-unbacked-tokens/"},{"credibility":2,"name":"SAND Faces Upbit, Bithumb Delisting Risk After $49B Mint Attack — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/24/sand-faces-upbit-bithumb-delisting-risk-after-49b-mint-attack/"}]},{"content":"Security researchers classified the exploit as an application-level configuration failure rather than a vulnerability in the LayerZero protocol itself. LayerZero's documentation designates delegate management as the responsibility of the OApp (omnichain application) operator, not the protocol layer. The approveAndCall function used to hijack delegate standing is a feature of the SAND token contract, not of LayerZero's messaging infrastructure.\n\nThe SAND exploit was, according to reporting by Crypto.news, the third notable LayerZero OFT peer or delegate abuse documented in 2026. In April 2026, the KelpDAO rsETH OFT bridge on Ethereum was exploited for approximately $292 million via a forged cross-chain message, a more severe incident in which LayerZero Labs subsequently acknowledged it had made a mistake. In May 2026, a compromised deployer key was used to reset trusted peer settings on StakeDAO's vsdCRV OFT on Arbitrum, resulting in approximately $91,000 in losses. The pattern of application-level OFT configuration abuse across multiple protocols in 2026 prompted reporting of increased migration interest toward alternative cross-chain infrastructure, including Chainlink CCIP.\n\nThe weaponization of approveAndCall to escalate to delegate-level permissions represents a novel attack class for gaming protocol bridges. The 313-day pre-positioning of the attacker's funding address suggests deliberate operational planning rather than an opportunistic attack.","heading":"Attack Vector: LayerZero OFT Delegate Abuse","severity":"high","sources":[{"credibility":2,"name":"The Sandbox's $49 billion phantom mint: how a bridge exploit created unbacked SAND tokens — Crypto.news","type":"news_article","url":"https://crypto.news/sandbox-bridge-exploit-49-billion-phantom-sand-mint/"},{"credibility":1,"name":"KelpDAO Incident Statement — LayerZero","type":"official","url":"https://layerzero.network/blog/kelpdao-incident-statement"},{"credibility":1,"name":"LayerZero Labs KelpDAO Incident Report — LayerZero","type":"official","url":"https://layerzero.network/blog/layerzero-labs-kelpdao-incident-report"},{"credibility":1,"name":"LayerZero says it 'made a mistake' in $292 Million Kelp exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/05/09/layerzero-says-it-made-a-mistake-in-usd292-million-kelp-exploit"},{"credibility":2,"name":"Crypto Hacks Drain $15M in a Week as Maya, BounceBit, Sandbox and Term Labs Fall — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/24/crypto-hacks-drain-15m-in-a-week-as-maya-bouncebit-sandbox-and-term-labs-fall/"}]},{"content":"The Sandbox is a blockchain-based three-dimensional multiplayer game focused on world-building and virtual land ownership, operating primarily on Ethereum. The platform originated as a two-dimensional mobile game created by Pixowl, a studio founded by Arthur Madrid and Sebastien Borget. By April 2018, the mobile game had accumulated over 40 million downloads. In August 2018, Animoca Brands, a Hong Kong-based blockchain gaming and NFT company, acquired Pixowl and its intellectual property, transitioning The Sandbox into a blockchain-based metaverse with its own token.\n\nThe SAND token is the native utility and governance token of The Sandbox, capped at a total supply of 3 billion tokens and operating on the Ethereum network. During the 2021 metaverse investment cycle, SAND's price reached its all-time high and the platform sold approximately $350 million worth of virtual LAND NFTs.\n\nThe platform has undergone significant operational restructuring. In August 2025, The Sandbox announced it was cutting more than 50% of its roughly 250-person workforce, closing offices in Argentina, Uruguay, South Korea, Thailand, Turkey, and Lyon, France. Co-founders Arthur Madrid and Sebastien Borget were removed from executive roles; Animoca Brands CEO Robby Yung assumed the role of CEO of The Sandbox, with Madrid transitioning to a non-executive chairman role and Borget to a public ambassador role. As of the restructuring, SAND's market capitalization had declined approximately 90% from its 2021 peak to around $700 million. Reported daily active users had dwindled to a few hundred. The Sandbox treasury was estimated to hold between $100 million and $300 million, largely from virtual land sale proceeds.","heading":"Background: The Sandbox Platform and Animoca Brands","severity":"medium","sources":[{"credibility":1,"name":"Metaverse Platform The Sandbox Cuts 50% Staff, Restructures as Animoca Brands Take Control — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2025/08/28/the-sandbox-cuts-50-staff-restructures-as-animoca-brands-take-control"},{"credibility":2,"name":"The Sandbox Founders Exit as Animoca Assumes Full Control in Major Overhaul — CryptoNews","type":"news_article","url":"https://cryptonews.com/news/the-sandbox-founders-exit-as-animoca-assumes-full-control-in-major-overhaul/"},{"credibility":2,"name":"What is the Sandbox? (SAND) — Bitstamp Learn Center","type":"other","url":"https://www.bitstamp.net/en-gb/learn/cryptocurrency-guide/what-is-the-sandbox-sand/"}]},{"content":"In February 2023, The Sandbox disclosed a separate, unrelated security incident. On February 26, 2023, an unauthorized party gained access to a computer belonging to a Sandbox employee, obtaining user email addresses. The attacker used this data to send phishing emails to users under the subject line 'The Sandbox Game (PURELAND) Access,' which contained hyperlinks to malware capable of remotely installing software granting control over recipients' machines. The Sandbox stated that the breach was limited to one employee's computer and that no other internal services or accounts were compromised. In response, the company blocked the employee's accounts, reformatted the affected laptop, and reset related passwords while requiring two-factor authentication. The company's CoinDesk-covered disclosure urged users to avoid clicking hyperlinks in the email. This incident involved a social engineering or endpoint compromise rather than a smart contract vulnerability.","heading":"Prior Security Incident: February 2023 Email Breach","severity":"low","sources":[{"credibility":1,"name":"Blockchain Game The Sandbox Warns of Phishing Email After Security Breach — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2023/03/02/blockchain-game-the-sandbox-warns-of-phishing-email-after-security-breach"},{"credibility":1,"name":"Notice of Security Incident (February 2023) — The Sandbox on Medium","type":"official","url":"https://sandboxgame.medium.com/notice-of-security-incident-february-2023-ea692ee8094b"},{"credibility":1,"name":"The Sandbox warns users of security breach used for email phishing campaign — The Block","type":"news_article","url":"https://www.theblock.co/post/216471/the-sandbox-warns-users-of-security-breach-used-for-email-phishing-campaign"},{"credibility":2,"name":"Sandbox blockchain game breached to send emails linking to malware — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/sandbox-blockchain-game-breached-to-send-emails-linking-to-malware/"}]},{"content":"The Sandbox's trust score reflects a confluence of factors. On the positive side: the August 2026 bridge exploit was contained before funds reached Ethereum, actual realized losses (~$675,000) were modest relative to the nominal figure cited in initial reporting, the team responded publicly and promptly, multisig controls functioned to terminate minting within hours, and core Ethereum and Polygon SAND reserves were not compromised. A compensation plan for affected liquidity providers was announced.\n\nOn the negative side: the attack exploited a smart contract function (approveAndCall) in The Sandbox's own OFT configuration, representing an application-level security failure for which the operator bears responsibility. The 313-day pre-staging of attacker infrastructure indicates deliberate targeting. The exploit is the third LayerZero OFT abuse of 2026, raising questions about the platform's cross-chain security review practices. The platform also experienced an employee endpoint breach in 2023. More broadly, The Sandbox has undergone significant business deterioration — a 90% decline in token value from peak, mass layoffs, founder departures, and a shift of executive control — which introduces operational and governance uncertainty beyond the immediate security incident. No regulatory actions, fraud allegations, or adjudicated wrongdoing have been identified against the project or its principals.","heading":"Trust Score Assessment","severity":"medium","sources":[{"credibility":2,"name":"The Sandbox Contains Bridge Exploit After Unbacked SAND Minted on Base and BSC — BeInCrypto","type":"news_article","url":"https://beincrypto.com/sandbox-sand-bridge-exploit-base-bsc/"},{"credibility":1,"name":"Metaverse Platform The Sandbox Cuts 50% Staff, Restructures as Animoca Brands Take Control — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2025/08/28/the-sandbox-cuts-50-staff-restructures-as-animoca-brands-take-control"}]}],"sources_used":[{"credibility":2,"name":"Sandbox SAND Hacked: Attackers Mint 329 Trillion Tokens on Base in 5-Hour Rampage — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/22/sandbox-sand-hacked-attackers-mint-329-trillion-tokens-on-base-in-5-hour-rampage/"},{"credibility":2,"name":"The Sandbox's $49 billion phantom mint: how a bridge exploit created unbacked SAND tokens — Crypto.news","type":"news_article","url":"https://crypto.news/sandbox-bridge-exploit-49-billion-phantom-sand-mint/"},{"credibility":2,"name":"The Sandbox (SAND) Bridge Exploit: Attacker Mints 14.9B Unbacked Tokens on Base Network — Blockonomi","type":"news_article","url":"https://blockonomi.com/the-sandbox-sand-bridge-exploit-attacker-mints-14-9b-unbacked-tokens-on-base-network"},{"credibility":2,"name":"The Sandbox Contains Bridge Exploit After Unbacked SAND Minted on Base and BSC — BeInCrypto","type":"news_article","url":"https://beincrypto.com/sandbox-sand-bridge-exploit-base-bsc/"},{"credibility":2,"name":"Sandbox halts Base and BNB Chain bridging after exploit mints billions of unbacked SAND tokens — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/sandbox-halts-bridging-sand-exploit/"},{"credibility":2,"name":"The Sandbox Says It Contained Bridge Exploit That Minted Unbacked SAND on Base and BSC — The Defiant","type":"news_article","url":"https://thedefiant.io/news/hacks/the-sandbox-says-it-contained-bridge-exploit-that-minted-unbacked-sand-on-base-and-bsc"},{"credibility":2,"name":"Sandbox Exploit Created $49B in Unbacked SAND Nobody Could Cash Out — EdgeX","type":"news_article","url":"https://pro.edgex.exchange/en-US/news/article/sandbox-bridge-exploit-49b-vs-675k-drain"},{"credibility":2,"name":"SAND bridge exploit contained after unbacked token mint — Crypto.news","type":"news_article","url":"https://crypto.news/sand-bridge-exploit-contained-unbacked-token-mint/"},{"credibility":2,"name":"SAND Bridge Exploit: The Sandbox Isolates Base and BNB Chain After Unbacked Token Mint — CoinPaper","type":"news_article","url":"https://coinpaper.com/34597/sand-bridge-exploit-the-sandbox-isolates-base-and-bnb-chain-after-unbacked-token-mint"},{"credibility":2,"name":"SAND Bridge Exploit: 14.9B Tokens Minted Overnight — Shattered.io","type":"news_article","url":"https://shattered.io/sandbox-sand-bridge-exploit-2026/"},{"credibility":2,"name":"Sandbox Bridge Hack Mints 14.9B SAND While Coinbase Delists Futures — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/security/sandbox-sand-bridge-exploit-unbacked-tokens/"},{"credibility":2,"name":"SAND Faces Upbit, Bithumb Delisting Risk After $49B Mint Attack — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/24/sand-faces-upbit-bithumb-delisting-risk-after-49b-mint-attack/"},{"credibility":2,"name":"Crypto Hacks Drain $15M in a Week as Maya, BounceBit, Sandbox and Term Labs Fall — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/24/crypto-hacks-drain-15m-in-a-week-as-maya-bouncebit-sandbox-and-term-labs-fall/"},{"credibility":2,"name":"The Sandbox Confirms SAND Cross-Chain Bridge Vulnerability, Pauses Base and BSC Functions — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/the-sandbox-confirms-sand-cross-chain-bridge-vulnerability-pauses-base-and-bsc-functions"},{"credibility":2,"name":"The Sandbox SAND Exploit: $49B in New Tokens Flood Base — CoinPedia","type":"news_article","url":"https://coinpedia.org/news/the-sandbox-sand-exploit-49b-in-new-tokens-flood-base/"},{"credibility":1,"name":"Metaverse Platform The Sandbox Cuts 50% Staff, Restructures as Animoca Brands Take Control — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2025/08/28/the-sandbox-cuts-50-staff-restructures-as-animoca-brands-take-control"},{"credibility":2,"name":"The Sandbox Founders Exit as Animoca Assumes Full Control in Major Overhaul — CryptoNews","type":"news_article","url":"https://cryptonews.com/news/the-sandbox-founders-exit-as-animoca-assumes-full-control-in-major-overhaul/"},{"credibility":1,"name":"Notice of Security Incident (February 2023) — The Sandbox on Medium","type":"official","url":"https://sandboxgame.medium.com/notice-of-security-incident-february-2023-ea692ee8094b"},{"credibility":1,"name":"Blockchain Game The Sandbox Warns of Phishing Email After Security Breach — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2023/03/02/blockchain-game-the-sandbox-warns-of-phishing-email-after-security-breach"},{"credibility":1,"name":"The Sandbox warns users of security breach used for email phishing campaign — The Block","type":"news_article","url":"https://www.theblock.co/post/216471/the-sandbox-warns-users-of-security-breach-used-for-email-phishing-campaign"},{"credibility":2,"name":"Sandbox blockchain game breached to send emails linking to malware — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/sandbox-blockchain-game-breached-to-send-emails-linking-to-malware/"},{"credibility":1,"name":"KelpDAO Incident Statement — LayerZero","type":"official","url":"https://layerzero.network/blog/kelpdao-incident-statement"},{"credibility":1,"name":"LayerZero Labs KelpDAO Incident Report — LayerZero","type":"official","url":"https://layerzero.network/blog/layerzero-labs-kelpdao-incident-report"},{"credibility":1,"name":"LayerZero says it 'made a mistake' in $292 Million Kelp exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/05/09/layerzero-says-it-made-a-mistake-in-usd292-million-kelp-exploit"},{"credibility":2,"name":"What is the Sandbox? (SAND) — Bitstamp Learn Center","type":"other","url":"https://www.bitstamp.net/en-gb/learn/cryptocurrency-guide/what-is-the-sandbox-sand/"}],"summary":"The Sandbox is a blockchain-based metaverse gaming platform owned by Animoca Brands and operating on Ethereum, with a native SAND token capped at 3 billion units. On August 22, 2026, the platform's SAND cross-chain OFT bridge on Base and BNB Smart Chain was exploited via hijacked LayerZero delegate permissions, enabling unauthorized minting of approximately 329 trillion face-value SAND tokens across 703 events over five hours; actual realized losses were approximately $675,000 in SAND plus roughly 79.74 ETH drained from the Ethereum OFT Adapter before bridging was paused. The Sandbox contained the exploit by disabling bridging on the affected networks and confirmed that SAND reserves on Ethereum and Polygon remained uncompromised.","timeline":[{"date":"2011-05-01","event":"Pixowl founded by Arthur Madrid and Sebastien Borget; original 2D Sandbox mobile game created.","source":"Bitstamp Learn Center","source_url":"https://www.bitstamp.net/en-gb/learn/cryptocurrency-guide/what-is-the-sandbox-sand/"},{"date":"2018-08-01","event":"Animoca Brands acquires Pixowl, including The Sandbox IP; project transitions to blockchain-based 3D metaverse with SAND token.","source":"Bitstamp Learn Center","source_url":"https://www.bitstamp.net/en-gb/learn/cryptocurrency-guide/what-is-the-sandbox-sand/"},{"date":"2021-11-01","event":"SAND reaches all-time high price during metaverse investment cycle; first play-to-earn event hosted. Platform sells approximately $350 million in virtual LAND NFTs over subsequent months.","source":"Bitstamp Learn Center","source_url":"https://www.bitstamp.net/en-gb/learn/cryptocurrency-guide/what-is-the-sandbox-sand/"},{"date":"2023-02-26","event":"Unauthorized party gains access to an employee computer, obtaining user email addresses and sending phishing emails with malware links. The Sandbox discloses incident and implements response measures.","source":"Notice of Security Incident (February 2023) — The Sandbox on Medium","source_url":"https://sandboxgame.medium.com/notice-of-security-incident-february-2023-ea692ee8094b"},{"date":"2025-08-28","event":"The Sandbox announces restructuring: over 50% of approximately 250 staff laid off, multiple offices closed, co-founders removed from executive roles, Animoca Brands CEO Robby Yung installed as CEO.","source":"Metaverse Platform The Sandbox Cuts 50% Staff, Restructures as Animoca Brands Take Control — CoinDesk","source_url":"https://www.coindesk.com/business/2025/08/28/the-sandbox-cuts-50-staff-restructures-as-animoca-brands-take-control"},{"date":"2026-04-18","event":"KelpDAO rsETH OFT bridge exploited for approximately $292 million via forged LayerZero cross-chain message; LayerZero Labs later acknowledges it made a mistake. First major LayerZero OFT exploit of 2026.","source":"LayerZero says it 'made a mistake' in $292 Million Kelp exploit — CoinDesk","source_url":"https://www.coindesk.com/tech/2026/05/09/layerzero-says-it-made-a-mistake-in-usd292-million-kelp-exploit"},{"date":"2026-08-21","event":"SAND bridge exploit begins at approximately 23:42:05 UTC. Attacker exploits approveAndCall function on The Sandbox's SAND OFT contract on Base, hijacking LayerZero delegate permissions and initiating unauthorized minting.","source":"Sandbox SAND Hacked: Attackers Mint 329 Trillion Tokens on Base in 5-Hour Rampage — CryptoTimes","source_url":"https://www.cryptotimes.io/2026/08/22/sandbox-sand-hacked-attackers-mint-329-trillion-tokens-on-base-in-5-hour-rampage/"},{"date":"2026-08-22","event":"Minting activity ceases at approximately 04:45:21 UTC after 329.24 trillion SAND minted across 703 events over five hours. Approximately 14.75 million SAND (~80 ETH, ~$675,000) drained from the Ethereum OFT Adapter in six transactions within 24 seconds. The Sandbox multisig zeros out LayerZero trusted peer settings at approximately 05:09:19 UTC, containing the exploit. Blockaid and PeckShield flag the incident publicly. The Sandbox disables bridging on Base and BNB Smart Chain and issues public disclosure. Upbit and Bithumb suspend SAND deposits and withdrawals.","source":"The Sandbox's $49 billion phantom mint: how a bridge exploit created unbacked SAND tokens — Crypto.news","source_url":"https://crypto.news/sandbox-bridge-exploit-49-billion-phantom-sand-mint/"},{"date":"2026-08-26","event":"Coinbase scheduled to delist SAND perpetual futures contracts, announced in connection with the exploit period.","source":"Sandbox Bridge Hack Mints 14.9B SAND While Coinbase Delists Futures — Bitcoin.com News","source_url":"https://news.bitcoin.com/security/sandbox-sand-bridge-exploit-unbacked-tokens/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 1e393732-9f1d-42aa-8888-8c69dc13c428
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.