What actually happened in the Sandbox SAND exploit
SAND is trading around $0.046 as of Sunday, essentially flat over the past 24 hours and still up roughly 15.8% for the week — a strange calm given that a Sandbox SAND exploit over the weekend produced headlines claiming $49 billion had been stolen. That figure is real in one narrow sense: it's the face value of SAND tokens an attacker minted out of thin air. What actually left Sandbox's reserves was closer to $675,000, and the gap between those two numbers is the whole story.
The exploit hit Saturday, August 22. An attacker hijacked delegate permissions on the LayerZero-based bridge connecting SAND's Ethereum contract to Base and BNB Chain, using a function called approveAndCall to seize control without needing a private key. That control let them mint SAND directly on Base and BSC without locking any real SAND on Ethereum first — the entire point of a bridge is that tokens on one side are backed by tokens locked on the other, and this hijack broke that link. Blockaid's monitoring systems flagged roughly $49 billion in newly minted tokens, a number several outlets then reported as the size of the theft.
Why the $49 billion figure is misleading
It isn't the size of the theft, because those tokens were never redeemable for anything. Minting SAND on Base doesn't create $49 billion of real value — it creates a pile of tokens with no backing, and the moment Sandbox's team caught the mismatch, they froze bridging and made the unbacked supply worthless outside a narrow window. Reporting $49 billion as "stolen" is like reporting the face value of counterfeit bills printed before the police arrive, rather than what a suspect actually walked out the door with.
The number that matters is what the attacker managed to convert into something real before that freeze landed. On-chain analysis shows the attacker pulled roughly 14.75 million SAND out of the Ethereum-side OFT Adapter — the contract that actually holds locked reserves — in about 60 seconds, then swapped it for roughly 80 ETH, worth about $665,000 to $675,000 at the time. Sandbox's multisig shut down bridging to Base and BNB Chain within the five-hour window the attacker had control, capping the damage there.
How much was actually stolen, and is my SAND safe?
For anyone holding SAND, the practical answer is: your tokens are untouched. The exploit hit the bridge contracts, not user wallets, and it affected under 0.01% of SAND's roughly 3 billion total supply. SAND held on Ethereum, on exchanges, or in self-custody outside the Base/BSC bridge was never at risk of being drained by this specific mechanism. That's also the mechanical reason the price didn't crater on the news — the market understood fairly quickly this wasn't a solvency event. A genuine $49 billion theft against a token with a market cap in the hundreds of millions would have been existential; a contained $675,000 bridge drain is a security embarrassment, not a reason to sell.
That doesn't mean nothing changed. Bridging between Ethereum and Base/BSC is still paused while Sandbox investigates, so anyone needing to move SAND across those specific chains is stuck until it reopens. Liquidity providers on Base and BSC pools are the group actually exposed, since unbacked SAND briefly circulated through those pools before the freeze — Sandbox has promised compensation based on a pre-attack snapshot but hasn't published the methodology or a date yet. If you provided liquidity on those chains, that's the open thread to track, not the safety of your core holdings.
What happens next
Two things are still outstanding, and both matter more than the price action so far. First, Sandbox owes the market a full technical post-mortem — exactly how the delegate permissions were hijacked, and what stops the same class of bug from hitting other LayerZero-connected bridges. Second is the LP compensation plan itself; how fast and how fairly that gets resolved will shape whether this reads as a well-handled incident or a slow-drip reputational problem.
Separately, Coinbase is removing SAND from its perpetual futures roster on August 26 as part of a batch delisting covering ten tokens, including Moonbirds and Axie Infinity. It's tempting to read that as exploit fallout, but the timing looks coincidental — this is routine low-volume futures cleanup, not a hack-specific penalty, and treating it as connected risks overstating the damage from Saturday's incident.
The base case
Over the next one to two weeks, the more likely path is that SAND holds roughly current levels inside the broader altcoin rally that's been lifting the market through August, provided no further exploit-linked funds start moving. The risk to that view isn't a fresh drain — the bridge is frozen and the OFT Adapter's remaining reserves are the thing to watch — it's reputational drag if the post-mortem slips for weeks or LP compensation turns into a public fight. The bull case is a fast, credible incident report landing before the Coinbase futures cutoff, reinforcing that the damage really was capped in the low hundreds of thousands, not the tens of billions the initial headlines implied.
Sources
- https://pro.edgex.exchange/en-US/news/article/sandbox-bridge-exploit-49b-vs-675k-drain
- https://blockonomi.com/the-sandbox-sand-bridge-exploit-attacker-mints-14-9b-unbacked-tokens-on-base-network
- https://thedefiant.io/news/hacks/the-sandbox-says-it-contained-bridge-exploit-that-minted-unbacked-sand-on-base-and-bsc
- https://www.coindesk.com/web3/2026/08/22/web3-gaming-network-sandbox-stops-base-and-bnb-chain-bridging-after-exploit
- https://www.cryptotimes.io/2026/08/22/sandbox-sand-hacked-attackers-mint-329-trillion-tokens-on-base-in-5-hour-rampage/
- https://www.gncrypto.news/news/sandbox-bridge-exploit-mints-14-9b-sand-coinbase-delists-futures/
- https://cryptorank.io/news/feed/572fa-sandbox-sand-bridge-exploit-base-bsc
- https://www.coingecko.com/en/coins/the-sandbox