U.S. EDITIONTHEWEEKLYOBSERVER.COM

HOME  /  BUSINESS  /  NEW YORK

CRYPTO

Hackers Mint $49 Billion in Fake Tokens on The Sandbox — Metaverse Game Scrambles to Contain the Damage

An attacker hijacked bridge permissions on The Sandbox's blockchain rails and conjured tens of billions of dollars in face-value SAND out of thin air. The real damage was far smaller — but the metaverse platform is still locking down two networks and compensating traders while it cleans up the mess.

ON

BY OBSERVER NEWSDESK

The Weekly Observer

AUG 23, 2026 · 4 MIN READ
fXinEMAIL
Hackers Mint $49 Billion in Fake Tokens on The Sandbox — Metaverse Game Scrambles to Contain the Damage
A physical Bitcoin token, used here as a generic illustration of cryptocurrency — not a photo of The Sandbox or the exploit itself. Photo by Gusture / Flickr (CC BY-SA 2.0).

The Sandbox, one of crypto's best-known virtual-world platforms, spent Saturday racing to contain a bridge exploit that let an attacker mint a jaw-dropping quantity of unbacked SAND tokens on two blockchain networks — a headline number that briefly made it look like one of the largest crypto heists ever recorded, before the real damage turned out to be a small fraction of that.

According to blockchain security firm Blockaid, the attacker compromised delegate permissions tied to the LayerZero cross-chain messaging system that connects SAND across networks, then used them to mint roughly $49 billion in face-value SAND across more than 400 transactions on the Base network. Rival security firm PeckShield pegged the mint at around 14.9 billion unbacked tokens sent to two addresses. Either way, it was a staggering figure for a token whose entire circulating supply sits at about 3 billion.

But face value and real-world loss are not the same thing. Because the newly minted tokens had no genuine collateral backing them on Ethereum, they could not simply be cashed out without crashing the market — and once The Sandbox's team spotted the anomaly, they moved fast. Per crypto.news, actual funds extracted from the bridge came to roughly 14.75 million SAND, worth about $675,000 and converted into roughly 80 ETH — a tiny sliver, under 0.01%, of total supply.

Two Networks Locked Down

The Sandbox immediately disabled all SAND bridging to and from Base and BNB Smart Chain, the two networks touched by the exploit, while confirming that Ethereum and Polygon were never affected. The company said the SAND collateral locked on Ethereum "remains entirely secure" and continues to back all legitimate bridged tokens elsewhere.

"All bridged SAND funds are backed by SAND locked on Ethereum, which remains entirely secure."

The team said no user wallets were compromised in the attack and pledged to compensate liquidity providers on the affected chains using a snapshot taken before the exploit began, though it has not yet published a timeline for payouts or a full technical postmortem. South Korean exchanges Bithumb and Upbit temporarily froze SAND deposits and withdrawals as a precaution under the country's Virtual Asset User Protection Act; Upbit later clarified that Ethereum-based SAND was never at risk.

The episode is the second notable crypto infrastructure scare in as many days: on Friday, Bitcoin-restaking platform BounceBit disclosed a separate $3 million exploit of its own layer-1 chain and announced it will shut the chain down entirely rather than patch it, migrating its BB token to BNB Chain instead. Together, the incidents underscore a recurring theme for crypto builders in 2026: the bridges and permission systems linking blockchains to one another remain a favorite target for attackers, even as the underlying base-layer chains grow more secure.

SAND's price dipped following news of the exploit but avoided a broader collapse, with traders largely shrugging off the eye-popping mint total once it became clear the tokens could not be redeemed for real value. The Sandbox has not said when bridging will resume on Base and BNB Smart Chain.

SHARE THIS STORY