The Sandbox halted bridging on Aug 22 after an exploit minted a nominal $49B in unbacked SAND -- but only ~$675K actually left reserves.

The news: an attacker hijacked LayerZero delegate permissions on SAND's omnichain bridge via approveAndCall, minting unbacked SAND on Base and BNB Smart Chain that Blockaid flagged at a face value near $49B across 400+ transactions -- almost entirely phantom, since it's illegitimate mint volume times SAND's market price, not real money. The Sandbox disabled bridging on both chains and confirmed only ~14.75M SAND (~$675K) actually left reserves before containment, under 0.01% of supply. Ethereum and Polygon are unaffected, no wallets compromised, and Bithumb/Upbit suspended SAND deposits as a precaution.

The catch: Base and BNB Chain SAND markets are now frozen indefinitely with no restoration timeline -- a liquidity and reputational hit disproportionate to the dollar loss. Two Korean exchanges pausing deposits signals lingering doubt, and LP compensation is only "planned," not executed. This is also a LayerZero OFT-standard delegate-permission compromise, a bridge type used across dozens of major projects.

Our read: a contained exploit in dollar terms, but a real structural bridge-security question that isn't closed yet. Falsifiable watch-point: does bridging actually restore cleanly, and does LP compensation get executed, or does this drag on?

Does a $675K real loss dressed up as a "$49B exploit" headline change how you read bridge security risk, or does the actual number matter more than the scary one?

Not financial advice. DYOR.

$SAND #TheSandbox #BridgeSecurity #CryptoNews