The Sandbox Hack
Incident Overview
On August 21–22, 2026, The Sandbox gaming platform experienced an exploit targeting its LayerZero-based Omnichain Fungible Token (OFT) bridge deployments on Base and BNB Smart Chain (BSC). By hijacking LayerZero delegate permissions via approveAndCall, the attacker minted massive quantities of unbacked SAND tokens on destination chains. The attacker then initiated cross-chain redemptions back to Ethereum L1, completely draining the ~14.75 million SAND (~14,753,431 SAND) backing escrow held in the Ethereum OFT adapter contract.
The attack exploited a permission configuration flaw in the LayerZero OFT delegate settings for the SAND token on Base and BSC. By leveraging approveAndCall, the attacker hijacked the protocol's delegate permissions and issued unauthorized minting calls across 700+ transactions to 173 addresses, generating trillions of face-value unbacked SAND tokens on Base.
While the majority of the unbacked L2 mints were hyper-inflated tokens isolated on destination chains, the attacker successfully submitted cross-chain redemption messages back to Ethereum mainnet. Between 00:32:11 and 01:22:11 UTC on August 22, the Ethereum OFT adapter escrow (0xac531eb2…002dcf) was drained from 14,769,723 SAND down to ~0.0056 SAND across 15 exit transactions (with ~14.1 million SAND transferred to a single EOA in 6 transactions). Total L1 supply remained unchanged at 3 billion SAND, but the mainnet bridge escrow backing L2 tokens was completely depleted (~14.75M SAND, representing
Ethereum SAND Token / OFT Contract: 0x3845bada…03a5d0
Ethereum OFT Adapter Escrow: 0xac531eb2…002dcf
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to The Sandbox, these are the critical security checks that could have prevented this incident (August 2026).
- Verify all logic paths related to Access Control are guarded by proper access controls and input validation - see the Access Control Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialRelated Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
- 01
- 02
- 03
-
04
Web Archive https://x.com/TheSandboxGame
Learn to Prevent the Next The Sandbox
The The Sandbox hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.