An Attacker Minted Forty Nine Billion Dollars of SAND and Left With Six Hundred and Seventy Five Thousand
Roughly 329 trillion tokens appeared on Base and BNB Smart Chain across 703 mint events. The real theft was capped by how much SAND was actually locked on Ethereum, and the keys came from a developer's infected laptop.
Sunday, August 30, 2026/4 min read

Between 23:42 UTC on 21 August and 04:45 the following morning, an attacker minted about 329 trillion SAND tokens across 703 separate events on Base and BNB Smart Chain. At the market price, the face value of that was in the region of 49 billion dollars.
They got away with roughly 675,000 dollars.
The gap between those two numbers is the most instructive thing to happen in crypto security this month, and it is not a story about a clever attacker. It is a story about which design decision decided the size of the loss.
How it worked
The SAND token contract on Base exposed an approveAndCall function. That function could be used to route a crafted payload through to the LayerZero endpoint, and the payload handed the attacker's helper contract delegate authority over endpoint configuration.
With that authority, the attacker could mint SAND on Base and BNB Smart Chain without any corresponding tokens being locked on Ethereum. That is the entire trick. A bridge is a promise that a token on one chain is backed by a token held on another, and the delegate permission let somebody write the promise without keeping it.
The forensics on how the permissions were reachable in the first place are worse than the bug. Investigators traced compromised keys to a developer machine infected with malware, a machine which was holding backups for seven private keys. Not one key. Seven, in one place, on an endpoint.
Why the loss was not 49 billion
Because minting a token and selling it are different problems.
The attacker could create unlimited SAND on the destination chains. What they could not create was a buyer. To convert phantom tokens into money, they had to take real assets out of the pool holding real assets, and the only thing that mattered was how much was in it.
The actual drain took under sixty seconds: about 14.1 million SAND pulled from the Ethereum adapter across fifteen transactions, totalling around 14.75 million SAND, converted to roughly 80 ETH. The blast radius was bounded by the adapter's balance, not by the attacker's minting capacity.
Everything else, trillions of tokens sitting on Base, is what one analysis fairly called accounting ghosts: visible on a block explorer, redeemable against nothing.
The number that will be reported wrong
Expect to keep seeing 49 billion dollars in headlines, and treat it as meaningless.
Face value of minted supply is not a loss figure. It is the price of the last real trade multiplied by a quantity that could never have been sold at that price, or at any price. Using it makes an incident sound like the largest theft in history when the recovered facts describe a mid sized one.
This distinction matters beyond one project, because the same confusion appears every time an unlimited mint bug is found. The question to ask about any exploit is never how many tokens were created. It is how much collateral was reachable, which is usually a much smaller and much more boring number.
What The Sandbox did
Disabled bridging on both affected chains by multisig within 24 minutes, removed the LayerZero peer settings, took a snapshot of pre incident balances for compensation purposes, and told users not to trade the affected SAND.
Twenty four minutes is fast. It is fast enough that the response is the strongest part of this story, and worth saying plainly given how often the opposite happens.
The post mortem published on 27 August set out the compensation: holders who legitimately held bridged SAND on Base or BNB Smart Chain before the attack receive an equivalent amount of Ethereum based SAND, paid from the treasury rather than by minting new supply, with claims expected to open within about two weeks. The compromised bridge contracts are being retired permanently. SAND on Ethereum and Polygon was never affected.
Paying from treasury rather than minting is the right call and it is not the default one. Minting to cover a loss caused by unauthorised minting solves the balance sheet by doing the thing that caused the problem, and every holder pays for it through dilution.
The lesson that transfers
Bridges remain the weakest structural point in this industry, and the reason is not cryptography.
A bridge is a permission system wearing a token's clothes. Its security depends on who can change configuration, and configuration authority is the kind of thing that gets delegated during development and never audited afterwards. Almost every large bridge failure of the last four years has been a permissions failure rather than a maths failure.
The second lesson is duller and applies to anyone holding anything. Seven private key backups on one developer workstation is the incident. The contract bug was the mechanism. We set out how to think about key handling for individuals in the self custody practice guide, and the broader question of what happens when payment infrastructure inherits these assumptions in the piece on stablecoin rails.
For a holder of anything bridged, the practical question after reading this is simple. Do you know which contract holds the collateral behind the token in your wallet, and who is allowed to change its settings? If the answer is no, the position is a trust position, whatever the marketing says.
Published in The Outspoken Digest
Newsletter
The Digest, in your inbox
One edition, sent when it is ready. No noise, and your address is never passed on.
Read Next
More Crypto →
You Can Buy a House Without Selling Your Bitcoin Now, and the Collateral Terms Tell You What It Is Really Worth
Aug 28, 2026/4 min read

Bitcoin Is Having Its Best August Since 2017. It Is Also Still a Third Below Its Record.
Aug 25, 2026/3 min read

The SEC Has Asked 27 Questions About the Next Generation of Crypto Funds, and You Have Until 31 August to Answer
Aug 24, 2026/4 min read

The Rulebook for Stablecoins Missed Its Own Deadline, and the Compliance Date Did Not Move
Aug 24, 2026/4 min read