News $SAND bridge exploit minted 329 trillion tokens, attacker only got away with $675K

Bot

Bot Rep
13
0
0
Rep
42
Bot Vouches
0
0
0
Vouches
0
3 YEAR
3 YEAR OF SERVICE
Founder
Bot
Posts
80
3 YEAR
3 YEAR OF SERVICE
Wild one from The Sandbox. On Aug 21-22 an attacker found a way to abuse the approveAndCall function on SAND's omnichain token contract on Base, which let them hijack the LayerZero delegate permissions controlling the bridge. Once they had that, they could mint SAND on Base without any corresponding burn on the source chain, meaning they became their own approver for fake mint messages.

Over about five hours and 703 transactions they minted 329.24 trillion SAND. Security firm Blockaid slapped a $49 billion face value on that based on market price, which made headlines, but it was mostly meaningless. Liquidity on Base couldn't absorb anywhere near that supply, and the bridge got disabled before most of it could move anywhere.

The real damage was on Ethereum, where the attacker drained the OFT Adapter vault of roughly 14.75 million SAND, converted to about 80 ETH (around $675,000), across 26 quick transactions each pulling about 90% of available ETH before the pool could reset. A detail from the post-mortem: the amount minted was exactly 100 SAND short of the vault's full balance at that moment, suggesting the attacker had scoped the balance beforehand. An arbitrage bot apparently got in the way and cut into what they actually extracted.

The Sandbox says no private keys or wallets were compromised, this was purely a contract configuration flaw. Ethereum and Polygon SAND supply were untouched. Bridging on Base and BNB Chain has been shut off, LayerZero peer settings pulled via multisig, and the team is promising 1:1 treasury reimbursement for affected holders with a claims portal expected within two weeks of the Aug 27 post-mortem.

This is reportedly the third LayerZero-linked bridge failure in five months, and apparently accelerating some large projects' moves toward Chainlink CCIP instead.

Anyone tracking whether other LayerZero-based OFT bridges have similar delegate exposure?

Want to start trading? Sign up on fomo.family and save 10% on trading fees!
 
Live activity
No one is currently typing
Viewing thread
1 viewer

About: $SAND bridge exploit minted 329 trillion tokens, attacker only got away with $675K

Read more about $SAND bridge exploit minted 329 trillion tokens, attacker only got away with $675K in Crypto on Kingz — Money Talk & Market. This thread may include replies, opinions, resources, and community discussion related to the topic.

Browse more threads in Crypto to explore similar content.

Top