Sandbox SAND Hack: How Much Was Actually Stolen?

SAND is trading around $0.039 as of Wednesday, down roughly 2-3% over the past 24 hours and extending a broader slide — down about 7% for the week and nearly 19% for the month — with no fresh 24-hour reaction to a headline claiming a Sandbox SAND hack stolen anywhere from $718 million to $49 billion. The real figure is much smaller: The Sandbox says attackers actually extracted around $675,000 in value, not billions. The gap between those numbers is the whole story, and it's why the metaverse token's short-term price action has stayed muted even as the headlines have not — the multi-week downtrend predates the exploit and isn't the market's verdict on it.

What Happened, and When

On August 21-22, an attacker found a gap in access controls on SAND's omnichain token contract on Base, the Coinbase-built network SAND uses to bridge value across chains via LayerZero's cross-chain messaging system. By abusing a function called approveAndCall, the attacker hijacked a "delegate" permission that LayerZero contracts use to authorize actions — effectively tricking the contract into treating a dormant wallet, inactive for roughly 313 days, as if it had minting rights.

Over about five hours, that wallet triggered somewhere between 400 and 700-plus minting transactions, creating SAND tokens with no collateral behind them. Because Base and BNB Chain don't hold much SAND liquidity compared with Ethereum, the attacker could only convert a small slice of the fabricated tokens into real value before Sandbox spotted the activity and shut down bridging on both chains. Blockaid, the security firm that flagged the exploit in real time, later confirmed the face value of everything minted reached into the tens of billions of dollars — a number that measures what was created, not what anyone could actually spend.

Why the $49 Billion Headline Is Wrong

This is the detail that matters most for anyone worried about their SAND. The $49 billion figure — and the $718 million figure some outlets used instead — both price every minted token at SAND's market rate, as if the attacker could have sold all of it. They couldn't. Base and BNB Chain simply don't have the trading depth to absorb that kind of supply; any attempt to dump it would have collapsed the price on those specific liquidity pools long before the attacker got real money out.

What actually left the building was about 14.75 million SAND, worth roughly $675,000, plus 79.74 ETH. That's the number Sandbox has confirmed and the one that matters. It's a real loss and a real access-control failure worth taking seriously, but it's not a $49 billion event, and it's nowhere near the scale needed to threaten SAND's roughly $114 million total market capitalization.

Is Your SAND Safe Right Now?

For most holders, yes — with one specific exception. The attack targeted a smart-contract permission on Base's version of the SAND token, not user wallets, and Sandbox says no individual holder's funds were compromised. Ethereum, where SAND's actual reserves are locked and where the token first launched, was never touched. Polygon-based and Ethereum-held SAND are unaffected.

The real exposure is narrower: anyone holding or trying to move SAND specifically on Base or BNB Chain right now is dealing with disabled bridging, because Sandbox froze both routes to contain the fabricated tokens and prevent further extraction. The company says the fabricated supply amounts to under 0.01% of SAND's roughly 3 billion total supply — small enough that it shouldn't need to touch the broader token's economics once cleaned up. If you're not bridging SAND on those two chains, this incident doesn't change what you're holding.

When Does Bridging Reopen?

There's no date yet, and that's the honest answer as of Wednesday. Sandbox says it wants a full technical post-mortem and a third-party security audit completed before turning Base and BNB bridging back on, and neither has been published. Realistically, that points to a process measured in days to a couple of weeks rather than hours, though Sandbox hasn't committed to a timeline publicly.

Sandbox is also preparing a compensation plan for liquidity providers who had SAND parked on Base or BNB Chain when the exploit hit, based on a snapshot of balances taken before the attack began. No payout details have been released. Two exchanges have taken action: Bithumb suspended SAND deposits and withdrawals outright, while Upbit issued a caution warning without halting transfers. Neither has moved to delist it. Separately, Coinbase is removing SAND perpetual futures on Wednesday — but that's part of a wider ten-contract review that also includes Axie Infinity's AXS token, not a reaction to this specific exploit, so it shouldn't be read as an exchange verdict on the hack itself.

What Would Change the Picture

The base case here is a contained, low-loss incident: a narrow permission bug gets fixed, the audit clears, bridges reopen, LPs get made whole, and exchanges lift their caution flags once Sandbox publishes its findings. SAND's short-term price action is consistent with the market already treating it this way — the token's 24-hour move barely budged on news that would have crushed it if the exploit were anywhere near as large as the loudest headlines suggested, even though SAND remains in a broader multi-week downtrend that predates this incident and isn't a reaction to it.

The risk that would change this is structural rather than SAND-specific: LayerZero's delegate-permission model is used by other omnichain tokens beyond SAND, so if the post-mortem shows this bug is a pattern rather than a one-off misconfiguration, it becomes a bridge-security story for the sector, not just a Sandbox story. That would likely mean a longer bridge outage, more exchanges adding caution flags, and reputational drag that outlasts the actual dollar loss. Watch for the post-mortem and audit results — that's the next real catalyst, not the price chart.

Sources