Sandbox Bridge Hack Mints 14.9B SAND as Coinbase Delists Futures This Week

Sandbox Bridge Hack Mints 14.9B SAND as Coinbase Delists Futures This Week

Last updated: August 23, 2026

Quick Answer: On August 22, 2026, an attacker exploited a vulnerability in The Sandbox’s cross-chain bridge on Base and BNB Smart Chain, minting approximately 14.9 billion unbacked SAND tokens across two addresses. Despite the enormous nominal figure, the actual extractable loss is estimated at roughly 14.75 million SAND (about $675,000), because most minted tokens cannot be redeemed. Separately, Coinbase announced the delisting of SAND-PERP futures on August 26, 2026, as part of a broader 10-contract removal unrelated to the hack.

Key Takeaways

  • An attacker hijacked LayerZero delegate and admin permissions on The Sandbox’s Omnichain Fungible Token (OFT) bridge on Base, enabling effectively unlimited SAND minting.
  • Blockchain security firm PeckShield confirmed approximately 14.9 billion unbacked SAND tokens were minted across two attacker addresses.
  • The real economic loss is far smaller than headlines suggest: roughly $675,000 worth of SAND was actually extractable, not the face-value figure.
  • The Sandbox confirmed that SAND on Ethereum and Polygon remains fully backed and unaffected, and no user wallets were compromised.
  • Cross-chain bridging on Base and BSC has been suspended; a snapshot and compensation plan for affected liquidity providers is in preparation.
  • Coinbase’s SAND-PERP delisting on August 26, 2026, is part of a 10-contract removal affecting assets including AXS-PERP, BLUR-PERP, and MEME-PERP, not a SAND-specific action.
  • The incident is another example of cross-chain bridge infrastructure risk, particularly around privileged roles in OFT contracts.
  • Investors holding SAND on Ethereum or Polygon face no direct token loss from the exploit itself.

What Is the Sandbox Bridge Hack Explained

The Sandbox bridge hack refers to a security exploit disclosed on August 22, 2026, in which a malicious actor abused a flaw in The Sandbox’s cross-chain bridge infrastructure to mint billions of SAND tokens without any corresponding backing on Ethereum. [1][4]

The Sandbox is a leading blockchain-based metaverse platform where users buy virtual land, create experiences, and trade digital assets using SAND as the native currency. Its bridge allows SAND to move between Ethereum, Base, and BNB Smart Chain (BSC). The attacker targeted the bridge’s Omnichain Fungible Token (OFT) implementation on Base, hijacking LayerZero delegate and admin permissions to gain what amounted to an infinite mint capability on Base and BSC. [5][10]

The Sandbox and security firm Blockaid estimate that more than 400 transactions were used to create tokens with a nominal face value of roughly $49 billion, though those tokens are now isolated, non-transferable, and non-redeemable. [3][4]

What Is the Sandbox Bridge Hack Explained

Key technical facts:

  • Exploit vector: LayerZero OFT delegate/admin permission hijack on Base
  • Networks affected: Base and BNB Smart Chain
  • Networks unaffected: Ethereum and Polygon
  • Transactions involved: More than 400
  • Response: Immediate suspension of cross-chain bridging on Base and BSC [1][4][10]

How Did Hackers Mint 14.9 Billion SAND Tokens

The attacker minted 14.9 billion SAND by exploiting The Sandbox’s OFT contract on Base, which is the mechanism that manages token representation across multiple chains. [5]

In a standard OFT setup, a trusted admin or delegate role controls minting and burning to keep token supplies balanced across chains. The attacker gained control of these privileged roles, effectively becoming the administrator of the Base-side SAND contract. With those permissions, the attacker could call the mint function without any Ethereum-backed collateral, creating tokens from nothing. PeckShield confirmed the minted tokens were distributed across two attacker-controlled addresses. [1][2][5]

SAND’s legitimate maximum supply on Ethereum sits at approximately 3 billion tokens. The 14.9 billion minted figure is therefore roughly five times the entire legitimate supply, which is why the headline numbers appear so alarming. However, because the unbacked tokens exist only on Base and BSC and cannot be bridged back to Ethereum to be redeemed against real reserves, most of the nominal value was never accessible. [2][5]

The actual extractable loss, the amount the attacker could realistically convert to value, is estimated at about 14.75 million SAND, worth approximately $675,000 (roughly 80 ETH) at the time of the exploit. [4][7]

What Caused the Sandbox Bridge Vulnerability

The root cause was insufficient access control over privileged roles in the OFT bridge contract. [5][10]

OFT bridges built on LayerZero use delegate and admin roles to authorize minting and burning across chains. If those roles are compromised or inadequately protected, an attacker can issue tokens freely. In this case, the attacker appears to have taken control of the delegate/admin permissions on the Base deployment, bypassing the checks that would normally require equivalent token locking or burning on Ethereum. [5][10][12]

Industry analysts point to two systemic issues this exploit highlights:

  • Minimizing privileged roles: Bridge contracts with broad admin permissions create single points of failure. Reducing or time-locking those permissions limits the blast radius of any compromise.
  • On-chain monitoring and circuit breakers: Automated alerts and supply-cap circuit breakers could detect and halt anomalous minting before hundreds of transactions occur.

This is not the first time OFT or LayerZero-adjacent bridge configurations have been targeted. The pattern of attacking admin/delegate keys rather than core protocol code is increasingly common across cross-chain infrastructure. [3][5]

SAND Token Price and Supply After the Bridge Hack

Despite the enormous nominal mint, the SAND price did not collapse, because the market quickly understood that the unbacked tokens are isolated and non-redeemable. [2][4]

The Sandbox confirmed that the impact represents less than 0.01% of the total SAND token supply when measured against legitimate, backed tokens. [1][4] The 14.9 billion minted tokens cannot be transferred or redeemed on Ethereum, so they do not dilute the real circulating supply in any practical sense.

Market reaction was cautious but not catastrophic. Exchanges and platforms temporarily suspended SAND deposits and withdrawals on Base and BSC networks while the exploit was being contained, which created short-term friction for traders. [1][10] The broader SAND supply on Ethereum and Polygon remained fully intact and backed.

What this means for holders:

  • SAND on Ethereum: unaffected, fully backed
  • SAND on Polygon: unaffected, fully backed
  • SAND on Base/BSC: bridging suspended, deposits and withdrawals paused on affected networks
  • Unbacked minted tokens: isolated, non-transferable, non-redeemable [1][4][10]

Why Is Coinbase Delisting SAND Futures

Coinbase’s decision to delist SAND-PERP is part of a broader strategic adjustment to its derivatives offering, not a direct response to the bridge hack. [6][11]

On August 12, 2026, Coinbase announced the suspension and delisting of 10 perpetual futures contracts, with trading set to halt on August 26, 2026, at approximately 13:00 UTC. [6][8] The full list of delisted contracts includes:

ContractAsset
SAND-PERPThe Sandbox
AXS-PERPAxie Infinity
MEME-PERPMemecoin
BLUR-PERPBlur
BIRB-PERPMoonbirds
KAT-PERPKatana
SPX-PERPSPX6900
ZORA-PERPZORA
AI-PERPGensyn
ZRO-PERPLayerZero

The breadth of this list, spanning metaverse tokens, NFT-related assets, memecoins, and infrastructure tokens, indicates a portfolio-level review of lower-liquidity or lower-demand perpetual contracts rather than a targeted response to the SAND exploit. [6][11][14][15]

Why Is Coinbase Delisting SAND Futures

The timing is coincidental but significant for SAND holders who use futures for hedging. Losing access to SAND-PERP during a period of market uncertainty removes one tool for managing downside risk.

How to Withdraw SAND from Coinbase Before the Futures Delisting

SAND spot holdings on Coinbase are not affected by the futures delisting; only the SAND-PERP perpetual futures contract is being removed. [6][11]

For users with open SAND-PERP positions, the key deadline is August 26, 2026, at approximately 13:00 UTC. After that point, trading halts and positions will be settled according to Coinbase’s standard delisting procedures. Users should:

  1. Close any open SAND-PERP positions before August 26, 2026, at 13:00 UTC.
  2. Review margin balances and ensure no unintended exposure remains.
  3. For spot SAND holdings, check which network (Ethereum, Polygon, Base, or BSC) the tokens are on before initiating any withdrawal, given that Base and BSC withdrawals are currently suspended due to the bridge exploit.
  4. Withdraw spot SAND via Ethereum or Polygon networks, which remain fully operational. [1][4]

Avoid withdrawing to Base or BSC addresses until The Sandbox officially restores bridge functionality and exchanges lift network-specific suspensions. [10][13]

Will The Sandbox Compensate Users Affected by the Hack

The Sandbox has stated it is preparing a snapshot and compensation plan specifically for eligible liquidity providers who may have been indirectly impacted by the exploit. [4][10][12]

The company confirmed that no user wallets were directly compromised and that the exploit affected only the bridge contracts on Base and BSC, not individual user holdings. [1][2][4] The compensation plan is therefore targeted at liquidity providers who had funds in affected bridge pools, not general SAND holders.

A formal timeline for the compensation process has not been publicly confirmed as of August 23, 2026. The Sandbox is working with security partners to complete a full post-mortem before finalizing the plan. Users who provided liquidity to the Base or BSC SAND bridge pools should monitor official Sandbox channels for snapshot eligibility criteria. [4][12][13]

Is Sandbox Coin Safe to Hold After the Hack

For holders of SAND on Ethereum or Polygon, the token remains fully backed and the exploit does not affect their holdings. [1][4]

The risk for current holders is not direct token loss from the hack, but rather market sentiment and the operational disruption caused by bridge suspension. The combination of the hack and the Coinbase futures delisting creates short-term negative pressure on SAND’s perceived stability.

Decision framework for SAND holders:

  • Hold if: Tokens are on Ethereum or Polygon, investment thesis is long-term, and the metaverse platform’s fundamentals remain intact.
  • Review if: Tokens are on Base or BSC and access is currently restricted due to bridge suspension.
  • Sell if: Exposure was primarily through SAND-PERP futures on Coinbase, which will be delisted August 26, 2026.

The broader concern is reputational: repeated bridge exploits across the industry erode trust in cross-chain metaverse infrastructure, and The Sandbox will need to demonstrate a credible security overhaul to restore confidence. [3][5][10]

Sandbox Bridge Hack Recovery Plan and Timeline

The Sandbox has not published a specific date for restoring bridge functionality on Base and BSC as of August 23, 2026. [4][10][12]

The recovery steps underway include: suspending all cross-chain transfers on the affected networks, freezing SAND token functionality on Base and BSC, working with security firms to audit the OFT contract and close the permission vulnerability, and preparing a snapshot for liquidity provider compensation. [4][10][12][13]

Industry precedent for similar bridge exploits suggests a recovery timeline of several weeks to months before full bridge restoration, depending on audit completion and the complexity of redeployment. Users should treat Base and BSC bridge access as unavailable for the near term and plan token movements through Ethereum or Polygon in the meantime.

Other Metaverse Coins Affected by Bridge Hacks

The Sandbox bridge hack fits a well-established pattern of cross-chain bridge exploits targeting metaverse and gaming tokens. [3][5]

Bridge attacks have historically been among the most damaging in the crypto space because bridges hold large reserves and often rely on complex multi-chain permission structures. Notable past incidents include the Ronin Network hack (affecting Axie Infinity’s ecosystem), the Wormhole exploit, and the Nomad bridge attack. Each involved some form of privileged role compromise or smart contract vulnerability.

The Coinbase delisting of AXS-PERP alongside SAND-PERP is a reminder that Axie Infinity’s token has also faced ecosystem-level security events in the past. [6][11] Metaverse tokens in general carry elevated bridge risk because their ecosystems depend on multi-chain asset movement for gameplay and trading.

Common bridge attack vectors across metaverse tokens:

  • Admin/delegate key compromise (as in the Sandbox case)
  • Smart contract logic flaws in mint/burn accounting
  • Oracle manipulation affecting cross-chain price feeds
  • Validator collusion in proof-of-authority bridge designs

Conclusion

The Sandbox Bridge Hack Mints 14.9B SAND as Coinbase Delists Futures This Week represents a convergence of two separate but market-moving events. The bridge exploit is technically severe in nominal terms but economically contained, with real losses estimated at roughly $675,000 rather than the face-value figure. SAND on Ethereum and Polygon is unaffected and fully backed.

Actionable steps for SAND holders and traders:

  1. Verify which network your SAND is on. Ethereum and Polygon holdings are safe; Base and BSC bridging is suspended.
  2. Close any SAND-PERP positions on Coinbase before August 26, 2026, at 13:00 UTC to avoid forced settlement.
  3. Do not attempt to withdraw SAND via Base or BSC networks until The Sandbox officially restores bridge functionality.
  4. Monitor The Sandbox’s official channels for the liquidity provider compensation snapshot announcement.
  5. Treat this incident as a reminder to audit any cross-chain bridge exposure in a portfolio, particularly for assets using OFT or LayerZero-based infrastructure.

The broader lesson for the industry is clear: cross-chain bridge security, specifically the management of privileged admin roles, remains one of the most critical and underprotected areas in decentralized finance. Stronger access controls, time-locked permissions, and real-time supply monitoring are not optional features; they are baseline requirements for any bridge handling significant value.

FAQ

What exactly happened in the Sandbox bridge hack? An attacker hijacked LayerZero delegate and admin permissions on The Sandbox’s OFT bridge contract on Base, enabling unlimited SAND minting without Ethereum-backed collateral. Approximately 14.9 billion unbacked SAND tokens were minted across two attacker addresses. [1][5]

How much money was actually stolen in the Sandbox bridge exploit? The actual extractable loss is estimated at approximately 14.75 million SAND, worth roughly $675,000 (about 80 ETH), because most of the minted tokens are trapped and non-redeemable. [4][7]

Is my SAND on Ethereum safe after the hack? Yes. The Sandbox confirmed that SAND on Ethereum and Polygon remains fully backed and unaffected by the exploit. [1][4]

When does Coinbase delist SAND-PERP futures? Trading halts on August 26, 2026, at approximately 13:00 UTC. Users with open SAND-PERP positions should close them before that deadline. [6][8]

Is the Coinbase SAND futures delisting related to the hack? No. Coinbase announced the delisting on August 12, 2026, as part of a 10-contract removal covering multiple assets. The timing is coincidental. [6][11]

Can I still withdraw SAND from Coinbase? Spot SAND withdrawals via Ethereum or Polygon are unaffected. Withdrawals on Base and BSC networks are currently suspended due to the bridge exploit. [1][10]

Will The Sandbox compensate affected users? The Sandbox is preparing a compensation plan for eligible liquidity providers in the affected bridge pools. General SAND holders whose wallets were not directly compromised are not part of the current compensation scope. [4][12]

How long will the Sandbox bridge remain suspended? No official restoration date has been announced as of August 23, 2026. Bridge recovery typically takes weeks to months following a security audit and contract redeployment. [4][10]

What is an OFT bridge and why is it vulnerable? An Omnichain Fungible Token (OFT) bridge manages token representation across multiple blockchains using mint and burn mechanics. Vulnerabilities arise when admin or delegate roles are inadequately protected, allowing an attacker to mint tokens without corresponding collateral. [5][10]

Are other metaverse tokens at risk from similar bridge hacks? Yes. Metaverse tokens that rely on cross-chain bridges for multi-network gameplay and trading face similar risks, particularly those using OFT or LayerZero-based infrastructure with broad admin permissions. [3][5]

References

[1] Sandbox Sand Bridge Exploit Unbacked Tokens – https://news.bitcoin.com/security/sandbox-sand-bridge-exploit-unbacked-tokens/

[2] Sandbox Exploit 14 9b Sand – https://yellow.com/news/sandbox-exploit-14-9b-sand

[3] Sandbox Bridge Exploit Minimal Data Tells a Very Different Story – https://stocktwits.com/news-articles/markets/cryptocurrency/sandbox-bridge-exploit-minimal-data-tells-a-very-different-story/cZYQ2zPRJVN

[4] Sandbox Halts Bridging Sand Exploit – https://cryptobriefing.com/sandbox-halts-bridging-sand-exploit/

[5] The Sandbox Sand Bridge Exploit Attacker Mints 14 9b Unbacked Tokens On Base Network – https://blockonomi.com/the-sandbox-sand-bridge-exploit-attacker-mints-14-9b-unbacked-tokens-on-base-network/

[6] Coinbase Delists 10 Perpetual Futures – https://coinalertnews.com/news/2026/08/12/coinbase-delists-10-perpetual-futures

[7] Sandbox Hentikan Jembatan Base Dan Bnb Chain Setelah Eksploitasi Token Sand – https://pluang.com/en/news-feed/sandbox-hentikan-jembatan-base-dan-bnb-chain-setelah-eksploitasi-token-sand

[8] Latest Updates – https://coinmarketcap.com/cmc-ai/the-sandbox/latest-updates/

[10] The Sandbox Contains Cross Chain Bridge Exploit After Attacker Mints Unbacked Sand On Base And Bnb Smart Chain – https://whale-alert.io/stories/9ede0153686d4c/The-Sandbox-contains-cross-chain-bridge-exploit-after-attacker-mints-unbacked-SAND-on-Base-and-BNB-Smart-Chain

[11] Coinbase Delists 10 Perpetual Futures – https://coinalertnews.com/news/2026/08/12/coinbase-delists-10-perpetual-futures