South Korea’s two largest crypto exchanges took immediate action on August 22, 2026, following on-chain alerts regarding a suspected exploit on The Sandbox’s Base network deployment. Upbit issued a trading caution, while Bithumb suspended deposits and withdrawals for SAND.
Blockchain security firm PeckShield confirmed the breach shortly after alerts indicated unauthorized activity. Data revealed that approximately 14.9 billion SAND tokens were minted across two addresses, significantly exceeding the token's total 3-billion supply on the Ethereum mainnet.
According to blockchain forensics account BlockWatchdog, an attacker gained arbitrary token-minting permissions on the SAND contract deployed on Base, which utilizes a LayerZero Omnichain Fungible Token configuration. The attacker drained approximately 14.75 million SAND from the Ethereum adapter—which holds the locked Layer 1 SAND backing cross-chain deployments—in under a minute. Realized proceeds from subsequent token sales reached roughly 80 ETH, valued at about $675,000.
While the minting did not inflate the Ethereum mainnet supply, the volume of unbacked tokens created immediate market risks. In response to the incident, the project’s multisig zeroed the LayerZero peers for Ethereum and BSC, effectively isolating the Base network.
The Sandbox, an Animoca Brands subsidiary, had not issued a public statement regarding the root cause at the time of writing. Upbit’s trading caution and Bithumb’s suspension remain active as investors monitor for updates on potential recovery plans or token burns.


