The security breach involved the compromise of bridge permissions, which the attacker exploited to generate tokens without the corresponding collateral locked on Ethereum. Although on-chain researchers initially flagged the creation of billions of unbacked tokens, the project clarified that these assets could not alter the fixed 3-billion supply of the primary Ethereum token. Blockchain forensics indicate the attacker successfully drained approximately 14.75 million SAND from the Ethereum adapter, resulting in an estimated loss of 80 ETH, or roughly $675,000.
In response, The Sandbox disabled bridging operations for Base and BNB Smart Chain to isolate the affected contracts and prevent further redemptions. The project has initiated a snapshot of liquidity provider balances to facilitate future compensation, though a timeline for these payments remains pending. Security firm Blockaid attributed the incident to a takeover of LayerZero delegate permissions via an approveAndCall function, a claim The Sandbox has yet to formally confirm in a full postmortem.
Major South Korean exchanges including Upbit and Bithumb responded by suspending SAND deposits and withdrawals to mitigate potential market volatility. Users have been cautioned against trading or providing liquidity for SAND on the affected networks while the bridge remains offline. The Sandbox emphasized that tokens held on Ethereum and Polygon remain secure, as the vulnerability was confined to specific cross-chain deployments rather than the core Ethereum contract.
:quality(80)/2024-07-04/71893F46201B55576726C47288B38358.jpg)
Comments (0)
No comments yet. Be the first!