The Sandbox apparently hit by ongoing exploit as hackers mint billions in SAND

The Sandbox apparently hit by ongoing exploit as hackers mint billions in SAND

According to on-chain analysts, the exploit allowed attackers to create billions of unauthorized SAND tokens.

An exploit targeting The Sandbox’s SAND OFT on Base has allowed attackers to hijack LayerZero delegate permissions and mint massive amounts of unauthorized SAND tokens out of thin air, blockchain security firm Blockaid reported Saturday.

According to Blockaid, attackers exploited approveAndCall to take control of LayerZero delegate permissions, enabling them to mint SAND without legitimate backing.

Blockaid said that roughly $49 billion in face-value SAND had been minted through more than 400 transactions.

Advertisement

The attack was still underway at the time of the alert, leaving open the possibility that the amount of unauthorized SAND could continue to increase.

The Sandbox confirmed the exploit after on-chain analysts flagged suspicious activity. In a statement, the project stated that its SAND cross-chain bridge on BSC was also affected.

https://twitter.com/TheSandboxGame/status/2091063415649251821?s=20

According to the team, the vulnerability has now been contained, and bridging between both Base and BSC has been halted to isolate the affected tokens and prevent further transfers or redemptions. The Sandbox has advised users to avoid trading SAND on Base and BSC.

The project said the incident affected less than 0.01% of SAND’s total supply, while SAND deployed on Ethereum and Polygon was unaffected. It also said that there was no compromise of user wallets and that the Ethereum reserves backing bridged SAND remain intact.

The team is now working on a snapshot of the affected pools and a compensation plan for eligible liquidity providers, and plans to release a full incident report and technical post-mortem after completing its investigation.

The incident sent SAND to $0.052 before a sell-off drove it down to $0.044. The token has since rebounded to around $0.048.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
The Sandbox apparently hit by ongoing exploit as hackers mint billions in SAND
The Sandbox apparently hit by ongoing exploit as hackers mint billions in SAND

According to on-chain analysts, the exploit allowed attackers to create billions of unauthorized SAND tokens.

Share

Add us on Google

An exploit targeting The Sandbox’s SAND OFT on Base has allowed attackers to hijack LayerZero delegate permissions and mint massive amounts of unauthorized SAND tokens out of thin air, blockchain security firm Blockaid reported Saturday.

According to Blockaid, attackers exploited approveAndCall to take control of LayerZero delegate permissions, enabling them to mint SAND without legitimate backing.

Blockaid said that roughly $49 billion in face-value SAND had been minted through more than 400 transactions.

Advertisement

The attack was still underway at the time of the alert, leaving open the possibility that the amount of unauthorized SAND could continue to increase.

The Sandbox confirmed the exploit after on-chain analysts flagged suspicious activity. In a statement, the project stated that its SAND cross-chain bridge on BSC was also affected.

https://twitter.com/TheSandboxGame/status/2091063415649251821?s=20

According to the team, the vulnerability has now been contained, and bridging between both Base and BSC has been halted to isolate the affected tokens and prevent further transfers or redemptions. The Sandbox has advised users to avoid trading SAND on Base and BSC.

The project said the incident affected less than 0.01% of SAND’s total supply, while SAND deployed on Ethereum and Polygon was unaffected. It also said that there was no compromise of user wallets and that the Ethereum reserves backing bridged SAND remain intact.

The team is now working on a snapshot of the affected pools and a compensation plan for eligible liquidity providers, and plans to release a full incident report and technical post-mortem after completing its investigation.

The incident sent SAND to $0.052 before a sell-off drove it down to $0.044. The token has since rebounded to around $0.048.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.