What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

The $49 billion figure was a notional estimate of unbacked SAND at a market price—not cash stolen or a demonstrated loss. Contemporaneous reports say an attacker exploited a permissions path in The Sandbox’s Base token deployment to mint tokens without matching backing. Those reports put the amount extracted from an Ethereum adapter at about $675,000 at the time.

What does the $49 billion figure represent?

Blockaid’s estimate, reported by Crypto Times and crypto.news in 2026, assigned a market price to unbacked SAND balances. It describes their theoretical face value, not a sum the attacker could redeem, sell, or withdraw. A very large token balance on-chain does not by itself mean an equivalent amount of liquid assets exists to pay it out.

That distinction matters here because coverage reported both an enormous quantity of newly minted tokens and a much smaller outflow from a bridge adapter. The figures measure different things: tokens created without corresponding backing, assets actually taken from a reserve, and a dollar estimate based on a market price.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What happened in the SAND exploit?

Contemporaneous reporting describes an attack on August 21–22, 2026, involving The Sandbox’s Base deployment of SAND, an omnichain fungible token. The reported exploit path used the SAND contract’s approveAndCall function to send crafted calldata to a LayerZero endpoint. According to the technical reconstruction in that coverage, the endpoint treated the token contract as the caller, allowing the attacker to obtain effective delegate permissions and authorize minting without matching source-chain backing.

#1 Best Overall

Crypto.news reported that the activity ran from 23:42:05 UTC on August 21 to 04:45:21 UTC on August 22. Its on-chain reconstruction counted 329.24 trillion unbacked SAND across 703 mint events and 173 addresses during that window. These are reported reconstruction figures, not an independently verified audit.

How much did the attacker actually take?

Crypto.news reported that about 14.75 million SAND was withdrawn from the Ethereum OFT Adapter and converted to approximately 79.74 ETH, valued at roughly $675,000 at the time of those transactions. PrimeXBT separately reported an approximately $675,000 extraction and described the conversion as about 80 ETH. The small difference in the ETH figures reflects separate reporting; neither figure should be confused with the much larger notional value assigned to the unbacked mints.

Measure Reported figure What it describes
Notional face value Approximately $49 billion Blockaid’s market-price estimate for unbacked balances, as reported by Crypto Times and crypto.news in 2026; not the realized loss.
Unbacked tokens minted 329.24 trillion SAND Crypto.news’s reconstruction across 703 mint events and 173 addresses during the reported August 21–22, 2026 incident window.
Adapter outflow About 14.75 million SAND Crypto.news’s reported amount taken from the Ethereum OFT Adapter.
Conversion and estimated value Approximately 79.74 ETH and $675,000 Crypto.news’s estimate at the time of the transactions; PrimeXBT also reported about $675,000 and described the conversion as about 80 ETH.

Was LayerZero itself breached?

The reporting characterizes this as an application-level integration or configuration failure in the SAND token path, not evidence that LayerZero’s messaging protocol itself was breached. In the described sequence, the flaw was how this integration routed a payload through the token contract to the endpoint, which reportedly caused the endpoint to see the token contract’s authority.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

approveAndCall combines setting an allowance with a follow-on contract call. Its presence alone does not make a token vulnerable, and the reported issue does not establish that every LayerZero application shares the same weakness. The relevant question is how a specific application handles the caller, calldata, and permissions at each step.

Which chains were affected, and what response was reported?

Coverage placed the unbacked minting on Base and said The Sandbox disabled bridging on Base and BNB Smart Chain, then removed LayerZero peer settings through a multisig. The same reports said Ethereum and Polygon SAND were unaffected.

The Crypto Times reproduced an August 22 statement from The Sandbox describing the impact as less than 0.01% of total SAND supply. Because that wording is available here through a reproduction rather than an accessible original post, it should be treated as a reported company statement, not an independently verified supply calculation.

What was reported about reimbursement?

Crypto.news reported that on August 27, 2026, The Sandbox announced a treasury-funded 1:1 reimbursement plan for eligible holders of bridged SAND, without minting additional supply. The reporting described a claims portal as forthcoming. It does not establish whether the portal has since opened, who qualifies, or whether any individual has been paid. Holders should check current official project channels for eligibility and claim status rather than relying on the announcement alone.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What does this incident show about bridge permissions?

In a typical lock-and-mint arrangement, tokens are locked on a home chain while corresponding tokens are created on another chain. If a destination-side permission path can authorize minting beyond properly backed amounts, the displayed token supply can grow far beyond assets available to withdraw. The reported adapter outflow illustrates why mint totals and realized extraction must be evaluated separately.

For bridge and token integrations, the incident points to several practical security questions. These are general controls to examine, not claims about which safeguards The Sandbox had in place:

  • Permission scope: Can a token or other intermediary obtain endpoint privileges that should belong only to a narrowly authorized administrator?
  • Call validation: Are caller identity and calldata checked against the intended function and destination, rather than trusted because a call arrived through an expected contract?
  • Administrative changes: Are delegate and peer-setting changes limited, reviewed, and subject to an appropriate multisig process?
  • Monitoring and response: Can unusual mint activity trigger rapid containment, and can operators clearly communicate which chains and token representations are affected?
  • Recovery planning: Is there a transparent process for determining affected holders and funding compensation without creating further unbacked supply?

The available contemporaneous accounts provide a useful reconstruction, but they do not establish final reimbursement totals, current bridge status, or a directly accessible official post-mortem. Those details require confirmation from current official project communications.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.