Sandbox SAND token hit by large-scale minting exploit on Base chain, with hackers leveraging LayerZero permissions to create 14.9B SAND tokens across hundreds of transactions.
Security & Exploits ·
Security researchers at Blockaid detected an ongoing exploit targeting The Sandbox's SAND token on the Base network, where attackers leveraged LayerZero delegate permissions to mint approximately 14.9 billion SAND tokens across hundreds of transactions. According to the initial report, the attack involved hijacking permissions through the approveAndCall function, allowing threat actors to forge lzReceive calls and trigger unauthorized minting of unbacked SAND.
The exploit mechanism exploited a flaw specific to The Sandbox's SAND OFT implementation on Base rather than a vulnerability in LayerZero's core protocol itself. The attackers used the approveAndCall function to call setDelegate and subsequently mint tokens without proper backing, with the attack distributed across multiple addresses and hundreds of individual transactions to obscure the activity.
The exploit remained active at the time of detection, with security researchers identifying several attacker addresses and example transactions. The precise scope of total damage and whether the protocol team has implemented mitigation measures have not been detailed in available reports.