Live financial news intelligence

Track market-moving stories before they get noisy

Real-time pulse of financial headlines curated from 5 premium feeds.

Latest market signal Czech Filtered by asset SAND
Coverage 166,043 Raw stories ingested 21,810 rewritten in CS_CZ • 3 to rewrite (last 2 days).
Agents 7 Live Pipeline agents
  • FMP Stock News Fetch every minute 23s ago
  • FMP Forex News Fetch every 5 min 3m ago
  • CoinGecko News Fetch every 5 min running now
  • FIO Stock News Fetch every 10 min 8m ago
  • Patria Stock News Fetch every 10 min 8m ago
  • Editorial rewrite Rewrite every minute 1m ago
  • Asset sync Assets every 1 hour 17m ago

Latest coverage

Market News Feed

Scan headlines quickly, then expand any story for source context.

View
Language
Relevance
Clear
Details Date Content Source Relevance
2026-08-30 20:35 9d ago
2026-08-28 06:40 12d ago
The Sandbox nahradí SAND po bridge exploitu
SAND The Sandbox
CoinGecko News 92
Original source text
The Sandbox has pledged to reimburse eligible SAND holders 1:1 after an Aug. 21 bridge exploit drained about 14.7 million tokens worth roughly $700,000 from an Ethereum vault.

Summary

The Sandbox will repay eligible SAND holders 1:1 after an Aug. 21 bridge exploit drained about 14.7 million tokens worth $700,000. Compensation will come from The Sandbox treasury without minting new SAND, with claims expected to open within two weeks. The attacker exploited a configuration flaw in the Base and BNB Chain contracts to mint more than 339 trillion unbacked SAND. The compromised bridge contracts will be permanently retired, while SAND on Ethereum and Polygon was unaffected. According to The Sandbox’s Aug. 27 post-mortem, users who legitimately held bridged SAND on Base or BNB Smart Chain before the attack will receive an equivalent amount of Ethereum-based SAND. The project plans to cover the payments from its treasury without minting new tokens.

Claims are expected to open within two weeks and remain available for another two weeks. Two centralized exchanges account for more than 72% of the eligible SAND balances, and The Sandbox said the exchanges will distribute replacement tokens directly to affected customers.

The Sandbox will repay SAND holders from its treasury The repayment plan covers legitimate bridged SAND balances that existed on Base and BNB Smart Chain before the exploit. Eligible users will receive SAND issued on Ethereum, replacing the tokens affected by the compromised bridge infrastructure.

The Sandbox said its treasury already holds the tokens required for the process, meaning the compensation will not increase SAND’s circulating or maximum supply. Users who held eligible balances through the two centralized exchanges handling most of the affected tokens will not need to submit individual claims.

For other holders, the project plans to launch a claims portal once the required infrastructure is ready. The two-week submission period is expected to begin within two weeks of the post-mortem, though the project did not provide a specific opening date.

The compensation plan follows an attack that targeted the contracts responsible for moving SAND between Ethereum and Base and BNB Smart Chain. While the exploiter was able to create an enormous quantity of unbacked SAND on the destination networks, the project said the damage to assets backing legitimate bridged tokens amounted to about 14.7 million SAND.

The stolen amount represented roughly 0.5% of SAND’s maximum supply of 3 billion tokens.

Configuration flaw gave the attacker control of bridge verification The Sandbox traced the incident to a configuration problem in the SAND contracts deployed on Base and BNB Smart Chain. The flaw allowed the attacker to become the sole verifier for incoming bridge messages, giving the address the ability to approve fraudulent messages without the authorization normally required by the bridge.

With control of that verification process, the attacker could mint SAND on the destination chains even though corresponding tokens had not been legitimately locked on Ethereum.

More than 339 trillion unbacked SAND tokens were eventually minted across Base and BNB Smart Chain, according to the post-mortem. The Sandbox said the fraudulent supply has since been isolated and cannot be bridged back to Ethereum or redeemed against legitimate SAND reserves.

SAND deployed directly on Ethereum and Polygon was not affected by the configuration flaw.

The distinction between legitimate and unbacked tokens is central to the reimbursement process because bridge systems commonly depend on assets being locked on one network before a corresponding representation is issued elsewhere. A crypto.news explainer published Aug. 3 detailed how lock-and-mint and related bridge designs rely on verification mechanisms to ensure destination-chain assets remain backed by value held elsewhere.

Crypto.news previously reported that bridge exploits have resulted in more than $4 billion in losses since 2021, with failures involving validator credentials, message verification and smart contracts among the methods attackers have used to compromise cross-chain infrastructure.

Compromised SAND bridges will be permanently retired Following the Aug. 21 attack, The Sandbox decided not to restore the affected Base and BNB Smart Chain bridge contracts. Both will instead be permanently retired.

Any future bridge connecting SAND with either network would require newly deployed contracts, according to the project. The Sandbox did not provide a timetable for restoring bridge access to Base or BNB Smart Chain.

Similar decisions to isolate or replace compromised bridge infrastructure have followed several attacks this year. In June, Humanity Protocol disclosed losses exceeding $36 million after attackers obtained administrative keys and took control of bridge systems spanning Ethereum and BNB Smart Chain.

The attackers in that incident were able to drain tokens from the Ethereum bridge and mint additional H tokens on BNB Smart Chain. A subsequent forensic investigation traced the compromised keys to a malware-infected developer machine that contained backups for seven private keys.

Another bridge incident in July hit Wanchain infrastructure connecting Cardano and BNB Chain. Blockchain security firm BlockSec said roughly 515 million NIGHT tokens were removed from the Cardano-side treasury in the Wanchain bridge exploit, worth about $9 million at the time. Midnight said its core network remained secure and described the incident as isolated to the bridge infrastructure.

Bridge exploits have continued through 2026 Cross-chain infrastructure has faced a series of attacks during 2026 involving different verification and security failures.

Axelar disabled bridge connections with Secret Network in June after an exploit resulted in approximately $4.7 million in losses. The incident affected Axelar-bridged assets on Secret Network while Axelar said its core protocol remained unaffected.

A month later, AFX suffered a $24.15 million USDC loss through a bridge operated by the trading protocol. The affected infrastructure was separate from Arbitrum’s native bridge, and the attacker subsequently moved the stolen USDC to Ethereum before converting it into about 12,467.5 ETH.

AFX later prepared a goodwill plan for users after its investigation linked the attack to a social engineering campaign that compromised internal development infrastructure. The protocol said it rebuilt key infrastructure and introduced new security measures following the incident.

The Sandbox’s reimbursement process is expected to begin once its claims system is ready. Eligible balances held through the two centralized exchanges will be handled directly by those platforms, while remaining holders will have two weeks to submit claims after the portal opens.

SAND was trading near $0.04 at the time of the post-mortem, down about 10.4% over the previous seven days.
2026-08-24 16:18 16d ago
2026-08-24 08:00 16d ago
Upbit a Bithumb zařadily SAND mezi varovné investiční produkty
SAND The Sandbox
CoinGecko News 86
Original source text
South Korean crypto exchanges Upbit and Bithumb have designated The Sandbox’s SAND token as an investment caution asset after security concerns linked to the project remained unresolved following a cross-chain bridge incident.

Summary

Upbit and Bithumb designated SAND as an investment caution asset over unresolved security concerns. The Sandbox said a bridge vulnerability allowed unbacked SAND to be minted on Base and BNB Smart Chain. Upbit will review SAND through late September and could remove, extend or escalate the warning. The Sandbox said Ethereum and Polygon SAND balances and user wallets were unaffected. According to Upbit’s Aug. 24 announcement, the exchange placed SAND under its trading caution framework after determining that an unexplained or unresolved security incident involving a virtual asset wallet or distributed ledger could expose users to potential losses.

The designation applies to SAND’s Korean won and Bitcoin markets, while deposits and withdrawals have already been suspended since Aug. 22 at 11:12 a.m. KST. Trading remains available during the review period.

Bithumb issued a separate designation at 3 p.m. KST on Aug. 24, citing confirmed security incidents such as hacking involving virtual asset wallets or distributed ledgers where the cause has not been identified or the problem has not been fully resolved. The exchange had halted SAND deposits and withdrawals at 11:11 a.m. KST on Aug. 22 after detecting signs of a possible security problem.

SAND warning follows abnormal token minting Two days before the formal caution designations, Bithumb said it had detected abnormal token minting activity involving the SAND smart contract on Base and warned users that the incident could increase price volatility.

The Sandbox later said it had identified and contained a vulnerability affecting its SAND cross-chain bridge on Base and BNB Smart Chain. According to the project, an attacker had been able to mint unbacked SAND on the two networks, prompting the team to disable bridging to and from both chains.

The project estimated the actual impact at less than 0.01% of SAND’s total supply and said SAND held on Ethereum and Polygon was unaffected. It also said no user wallets had been compromised and that the SAND locked on Ethereum to back legitimate bridged tokens remained secure.

With bridging disabled, The Sandbox said SAND on Base and BNB Smart Chain had been isolated and could not be moved or redeemed through the affected bridge. The team advised users against buying, selling or trading SAND on the two networks while liquidity remained affected.

Security firm Blockaid separately said attackers had hijacked LayerZero delegate permissions through the approveAndCall function used by SAND’s omnichain token setup. The firm reported that a large nominal amount of unbacked SAND had been minted across hundreds of transactions, although the face value of newly created tokens did not represent the project’s reported financial loss.

The Sandbox has also taken a snapshot of balances from before the incident and is preparing a compensation plan for eligible liquidity providers affected on Base and BNB Smart Chain. A full incident report and technical post-mortem are expected after the investigation is completed.

Upbit could end SAND trading support if concerns remain Upbit has scheduled its initial SAND review period from Aug. 24 at 3 p.m. KST through the fifth week of September, running from Sept. 28 to Oct. 4.

During that period, the exchange will review the reasons behind the caution designation under its digital asset trading support termination policy. Depending on the findings, Upbit can remove the warning, extend the review or decide to terminate trading support.

A security concern that has not been completely resolved can result in trading support being withdrawn, according to the exchange. Any extension or termination decision will be published separately with the applicable schedule.

SAND deposits made after the caution notice was published will not be credited to user accounts and will instead qualify for return processing. The token has also been removed from assets available for new borrowing applications under Upbit’s coin lending service, although existing loans can remain active until their original maturity dates.

Upbit said SAND withdrawals will be the first transfer service restored when the current suspension ends. Deposits will not automatically reopen at the same time and will instead be handled under the procedure applicable to assets already designated for trading caution.

Bithumb is working on a slightly different review schedule. Its notice said a decision on extending or removing the designation, or ending trading support, is expected during the first week of October, specifically between Sept. 28 and Oct. 2. The schedule can change depending on the exchange’s internal review.

Bithumb also said the caution status can be removed before the review period ends if the underlying reasons are resolved.

Korean exchanges have used similar reviews after exploits The SAND action follows previous cases in which South Korean exchanges placed tokens under caution while assessing a project’s response to a security breach.

In July, crypto.news reported that Upbit removed its warning on Taiko after reviewing information supplied by the layer-2 project about a June bridge exploit and the security measures introduced afterward.

TAIKO had initially been placed under warning on June 22 after Upbit identified a security incident involving systems used to issue, transfer or store the asset. Deposits were blocked during the review while existing balances could still be traded.

After a 32-day review, Upbit said the project had provided information covering the cause of the breach and subsequent security measures, allowing the exchange to determine that the reason for the warning had been resolved. Bithumb removed its TAIKO warning on the same day and prepared to restore deposits.

Security incidents have also led to more severe outcomes when Korean exchanges were not satisfied with a project’s remediation.

Earlier this year, Flow Foundation and Dapper Labs sought a court order after Upbit, Bithumb and Coinone moved to end FLOW trading support following a December 2025 exploit.

The Flow incident involved a protocol-level vulnerability that allowed an attacker to create duplicated tokens and extract about $3.9 million in value. Flow later said user balances were not affected, while validators and exchange partners took emergency measures to contain the incident and recover funds.

Despite the later remediation work, the Korean exchanges moved toward delisting FLOW, prompting the foundation and Dapper Labs to ask the Seoul Central District Court to suspend the trading termination while additional evidence was reviewed.

Security controls remain under regulatory scrutiny Security incidents at South Korean trading platforms have also drawn attention from domestic regulators under the country’s Virtual Asset User Protection Act.

South Korea’s Financial Supervisory Service began a formal sanctions process against Upbit operator Dunamu in July over a November 2025 wallet breach that affected Solana-based assets.

The FSS action followed an inspection into whether the exchange had met its obligations under the user protection law. Korean reports cited in the July coverage put the affected amount at 44.5 billion won, while Upbit said after the incident that customer losses would be covered with company funds.

Following the breach, Upbit moved assets into cold wallets, suspended deposits and withdrawals and began tracing the stolen funds. Regulators subsequently examined both the security failure and how the exchange disclosed the incident to users.
2026-08-24 08:38 16d ago
2026-08-24 06:58 16d ago
The Sandbox exploit bridge mintoval 329,24 bilionu nekrytých SAND
SAND The Sandbox
CoinGecko News 92
Original source text
An attacker weaponized a single ERC-20 function to hijack LayerZero delegate permissions and mint 329 trillion unbacked SAND on Base, yet the actual reserve drain totaled just $675,000, exposing both the fragility and the hidden safeguards of cross-chain token architecture.

Summary

An attacker exploited the approveAndCall function on The Sandbox\u2019s SAND omnichain fungible token contract on Base, hijacking LayerZero delegate permissions and minting 329.24 trillion unbacked SAND across 703 events over five hours on Aug. 21 and 22, 2026. Blockchain security firm Blockaid flagged $49 billion in face-value SAND minted across more than 400 transactions, while PeckShield counted 14.9 billion SAND directed to two attacker-controlled addresses. The actual financial extraction was far smaller: roughly 14.75 million SAND drained from the Ethereum OFT Adapter in under 60 seconds, yielding approximately 80 ETH (around $675,000 at the time of the transactions). The Sandbox disabled bridging on Base and BNB Smart Chain, removed LayerZero peer settings via multisig, and confirmed that SAND on Ethereum and Polygon was unaffected; Korean exchanges Upbit and Bithumb halted deposits and withdrawals, and Coinbase delisted SAND futures. The incident marks the third major LayerZero-related bridge exploit in five months, following the $292 million Kelp DAO attack in April and the Stake DAO breach in May, accelerating a $15 billion migration wave from LayerZero to Chainlink CCIP. On the night of Aug. 21, 2026, an address that had been dormant for 313 days routed a crafted payload through The Sandbox\u2019s SAND token contract on Base. Within five hours, blockchain explorers showed trillions of freshly minted SAND tokens spreading across 173 wallets. The face value, calculated by multiplying inflated balances against the live market price, briefly crossed $49 billion. That number exceeded the market capitalization of all but a handful of crypto projects. It also had almost no relationship to the money the attacker actually took.

The gap between the headline figure and the real extraction ($675,000, roughly the price of a modest house) reveals something important about how cross-chain token systems work and how they fail. It also reveals how crypto security reporting can amplify panic through numbers that are technically accurate but practically meaningless. Understanding why the attacker could mint a number larger than the gross domestic product of several small nations, yet walk away with a fraction of a fraction of that sum, requires examining the architecture that made the exploit possible and the constraints that limited its damage.

The Sandbox is one of the most recognizable names in Web3 gaming, with its SAND token powering a virtual world where users create, own, and monetize gaming experiences. The project was expanding its cross-chain presence to Base and BNB Smart Chain through LayerZero\u2019s OFT framework when the vulnerability was exploited. That expansion, intended to improve accessibility and reduce transaction costs for users, instead became the vector for the largest nominal-value bridge exploit in crypto history.

What happened on the night of Aug. 21 The first on-chain signal appeared at 23:42:05 UTC on Aug. 21. An externally owned account, later tagged by PeckShield as attacker-controlled address 0x638C, began submitting transactions to the SAND OFT contract deployed on Base. Each transaction invoked the approveAndCall function, a standard ERC-20 extension designed as a user-experience shortcut that combines a token approval and a follow-on contract call in a single transaction.

In this case, the follow-on call was anything but routine. The crafted payload routed through the token contract into the LayerZero endpoint, granting the attacker\u2019s helper contract the effective standing of a delegate with administrative rights over endpoint configuration. Once that delegate status was secured, the attacker could mint SAND on Base without any corresponding lock of tokens on the Ethereum side.

BREAKING: Curve Finance halts LayerZero infrastructure out of precaution after rsETH LayerZero hack, affecting CRV bridging on multiple chains and crvUSD fast bridge pic.twitter.com/UwNvfxBew9

— crypto.news (@cryptodotnews) April 19, 2026 Over the next five hours, 703 distinct minting events distributed newly created SAND to 173 addresses. The minting stopped organically at 04:45:21 UTC on Aug. 22. Twenty-four minutes later, at 05:09:19 UTC, The Sandbox\u2019s multisig wallet zeroed out the trusted peer settings for Base and BNB Smart Chain, severing the cross-chain link that the attacker had exploited.

How approveAndCall became an attack vector The approveAndCall function exists in many ERC-20 token implementations. It was originally conceived to solve a genuine usability problem: standard ERC-20 transfers require two separate transactions (approve, then transferFrom), costing users extra gas and extra time. By bundling both steps, approveAndCall lets a user approve a spender and trigger an action in a single transaction.

The vulnerability in the SAND implementation was not in the approval mechanism itself but in what the function allowed as the \u201ccall\u201d portion. When the SAND OFT contract on Base processed an approveAndCall transaction, it forwarded the embedded calldata to the target contract specified by the caller. If that target was the LayerZero endpoint, the call arrived with the token contract as the msg.sender, not the original external caller.

This distinction matters because LayerZero\u2019s endpoint checks permissions based on msg.sender. The SAND OFT contract held delegate authority over its own endpoint configuration. By routing through approveAndCall, the attacker effectively borrowed that authority. The result was a privilege escalation: an unauthorized external account gained the ability to reconfigure the endpoint and authorize arbitrary minting.

Security researchers from Blockaid described the root cause as \u201cthe takeover of LayerZero delegate permissions through an approveAndCall function.\u201d It was not a flaw in the LayerZero protocol itself but an application-level configuration failure in how The Sandbox\u2019s OFT contract interacted with the endpoint.

The $49 billion that never existed The face-value figure that circulated in the hours after the exploit deserves careful scrutiny. Blockchain explorers calculate token values by multiplying balances against the last traded price. When an attacker mints 329.24 trillion SAND and the token trades at fractions of a cent, the resulting number is mathematically enormous but economically hollow.

SAND has a legitimate maximum supply of 3 billion tokens on Ethereum. The attacker\u2019s 329 trillion minted tokens exceeded that supply by a factor of roughly 110,000. No market on any exchange, centralized or decentralized, could absorb even a tiny fraction of that volume at the quoted price. The moment any significant sell pressure materialized, the price on affected venues would collapse toward zero.

The actual extraction followed a different, far more constrained path. Within the first 60 seconds of the exploit, 14.75 million SAND was withdrawn from the Ethereum OFT Adapter, the contract that holds locked SAND backing cross-chain transfers. That withdrawal happened across 15 transactions, with 14,095,483 SAND routed to a single externally owned account in six transactions over 24 seconds. The total proceeds converted to approximately 79.74 ETH, worth roughly $675,000.

The Sandbox put the impact at \u201cless than 0.01% of the total SAND token supply.\u201d While critics noted the percentage framing downplayed the absolute dollar figure, the math is straightforward: 14.75 million tokens divided by 3 billion equals 0.49% of supply, with the actual value extracted representing a small fraction of the project\u2019s market capitalization.

The bridge architecture that limited the damage Understanding why the attacker could not convert trillions of phantom tokens into billions of real dollars requires examining LayerZero\u2019s OFT adapter model and the structural constraints that turned a theoretically catastrophic exploit into a contained incident.

When a project like The Sandbox deploys across multiple chains using LayerZero\u2019s OFT framework, the original tokens remain on the home chain (in this case, Ethereum). The Ethereum-side OFT Adapter locks genuine SAND tokens when a user bridges them outbound. On the destination chain, the OFT contract mints an equivalent amount. When a user bridges back, the destination chain burns the tokens and the adapter releases the locked originals.

The critical constraint is that the Ethereum adapter only holds as many tokens as users have previously bridged. On the night of Aug. 21, the adapter held a limited amount of SAND. Once the attacker drained those reserves, no additional backed SAND existed to extract, regardless of how many unbacked tokens the attacker continued to mint on Base.

This design means the exploit\u2019s blast radius was structurally bounded by the adapter\u2019s balance, not by the attacker\u2019s minting capacity. The trillions of tokens on Base became what one analyst called \u201caccounting ghosts,\u201d visible on explorers but redeemable against nothing. An attacker\u2019s fabricated balance becomes someone else\u2019s loss only when it reaches a pool containing genuine SAND, ETH, stablecoins, or other assets with real liquidity. With most of the legitimate reserves already drained in the first minute, the remaining minted tokens had nowhere to go.

There is a secondary channel of damage worth noting. Any decentralized exchange liquidity pools on Base that held genuine SAND paired against ETH or stablecoins were also vulnerable. If the attacker swapped unbacked SAND into those pools before liquidity providers could withdraw, the LPs absorbed losses beyond the Ethereum adapter drain. The Sandbox\u2019s decision to take a pre-incident snapshot and compensate eligible LPs suggests this secondary damage was not trivial, even if the team has not disclosed exact figures.

The Sandbox\u2019s response reinforced the primary containment. By zeroing the trusted peers via multisig, the team severed the cross-chain messaging channel. SAND on Base and BNB Smart Chain became isolated, unable to bridge back to Ethereum. The team then advised users not to buy, sell, or trade SAND on either affected chain. The Ethereum-side maximum supply cap of 3 billion SAND remained intact, and the Polygon deployment was unaffected.

A pattern across three incidents in five months The Sandbox exploit did not occur in isolation. It was the third significant LayerZero-related bridge incident in five months, a pattern that has reshaped how the industry evaluates cross-chain infrastructure risk.

On April 18, 2026, attackers drained 116,500 rsETH worth approximately $292 million from a LayerZero-powered bridge operated by Kelp DAO. That attack was traced to a social engineering campaign that compromised a LayerZero Labs developer on March 6, giving the attacker access to the company\u2019s RPC cloud environment. The Kelp bridge used a 1-of-1 DVN (Decentralized Verifier Network) configuration, meaning a single compromised verifier could authorize fraudulent cross-chain messages.

In May, Stake DAO suffered a separate breach when a compromised deployer key reset a trusted peer setting, leading to 5.4 trillion vsdCRV minted for roughly $91,000 in extractable value.

The Sandbox incident followed a similar logic: application-level misconfiguration of cross-chain permissions created an opening for unauthorized minting. The mechanisms differed (approveAndCall versus social engineering versus key compromise), but the target was the same: the delegate or peer authority that controls who can trigger cross-chain token operations.

The $15 billion migration that followed The cumulative effect of three LayerZero-related incidents in five months triggered a structural shift in how protocols choose their cross-chain infrastructure. By August 2026, publicly announced migrations from LayerZero to Chainlink\u2019s Cross-Chain Interoperability Protocol totaled approximately $15 billion in secured value.

BitGo led the migration wave by moving $7.4 billion in WBTC. Mantle shifted its $2.5 billion Super Portal. Lombard transferred over $1 billion in bitcoin-backed assets. Solv Protocol moved $700 million in tokenized bitcoin reserves. Kraken replaced LayerZero with Chainlink CCIP for its kBTC wrapped asset. On Aug. 18, just days before the Sandbox exploit, the Wyoming Stable Token Commission migrated its Frontier Stable Token to Chainlink CCIP across eight chains following a state-level security review.

LayerZero Labs acknowledged the earlier Kelp incident, with the company publicly stating it \u201cmade a mistake\u201d in the DVN configuration that Kelp used. The Sandbox exploit adds a new vector to the conversation: even when the underlying messaging protocol functions as designed, application-level integrations can create exploitable seams.

Chainlink\u2019s CCIP uses a different verification model that relies on a decentralized oracle network and a separate risk management network that independently validates every cross-chain transaction. The risk management network operates as an independent watchdog: even if the primary oracle network is compromised, the secondary layer can halt suspicious messages before they execute. This two-layer approach directly addresses the single-point-of-failure problem that enabled the Kelp DAO exploit, where a 1-of-1 DVN configuration meant one compromised verifier was sufficient to authorize fraud.

Whether that architecture proves more resilient over time remains an open question. Chainlink\u2019s model introduces its own trust assumptions, and no cross-chain system has proven immune to sophisticated attacks over a multi-year period. But the market has voted with its capital: $15 billion in migration announcements represents a level of institutional confidence shift that is difficult to reverse. When a state government (Wyoming) and major custodians (BitGo, Kraken) independently reach the same conclusion about infrastructure risk, the signal carries weight beyond any single incident.

What the market priced in The market response to the Sandbox exploit contradicted what a casual observer might expect. Despite the $49 billion headline, SAND traded up 4.76% to $0.0476 in the 24 hours following the incident, with trading volume surging more than 400%.

Several factors may explain the counterintuitive price action. First, the rapid containment and transparent communication from The Sandbox team reassured holders that the Ethereum-side supply was intact. Second, Korean exchanges halting deposits and withdrawals under South Korea\u2019s Virtual Asset User Protection Act signaled regulatory seriousness about protecting traders. Third, some market participants may have interpreted the small actual extraction as evidence that the OFT adapter model worked as a structural safety net, even if the application-level permissions failed.

JUST IN: Coldcard wallets affected by security issue with reported losses

Roughly 594 $BTC valued at $38 million has been stolen from certain dormant single sig wallets pic.twitter.com/f3fk7kYXzM

— crypto.news (@cryptodotnews) August 1, 2026 Coinbase delisted SAND perpetual futures, a precautionary move that reduced leverage exposure. The Sandbox announced it would take a pre-incident snapshot and compensate eligible liquidity providers on Base and BNB Smart Chain, though the timeline and mechanism for compensation were not immediately disclosed.

The price resilience should not be mistaken for absolution. The exploit exposed a configuration vulnerability that existed for at least 313 days, the dormancy period of the attacker\u2019s wallet, which was pre-positioned on Oct. 13, 2025. That one of the most recognizable names in Web3 gaming carried this exposure without detection raises questions about audit coverage for cross-chain deployments. The wallet\u2019s extended dormancy also suggests the attacker either discovered the vulnerability months before acting or acquired the wallet from someone who did.

DefiLlama logged 17 separate exploits in August 2026 alone, with bridges again emerging as the recurring weak point. Q2 2026 was described as \u201cthe most hacked quarter in DeFi history,\u201d with 99 exploits draining $746 million. Cumulative DeFi losses for the year exceeded $840 million by the end of May, and the Sandbox incident pushes the running total higher still. The question facing the industry is no longer whether bridges can be secured, but whether the current generation of bridge architectures should be trusted with significant capital at all.

What to watch Post-mortem publication: The Sandbox promised a full post-mortem. Its depth, particularly around how the approveAndCall pathway was missed in prior audits, will signal how seriously the project treats the configuration gap.

Liquidity provider compensation: The snapshot-based compensation plan needs a timeline and token source. Watch whether affected LPs receive full restitution or a haircut.

LayerZero protocol-level mitigations: Whether LayerZero introduces guardrails to prevent delegate hijacking through token contract callbacks will indicate if the protocol views this as a systemic risk or a one-off configuration error.

Further migration announcements: If additional projects accelerate departures from LayerZero following this third incident, the migration wave could reshape the cross-chain infrastructure market before year-end.

Regulatory response in South Korea: Upbit and Bithumb acted under the Virtual Asset User Protection Act. Whether Korean regulators pursue further action against The Sandbox or LayerZero could set precedent for how bridge exploits are treated under consumer protection frameworks.

What is the approveAndCall function? The approveAndCall function is an ERC-20 extension that lets a user approve a token spender and execute a follow-on contract call in a single transaction. It was designed to save gas and simplify multi-step interactions. In the Sandbox exploit, the attacker used this function to route a crafted payload through the SAND token contract into the LayerZero endpoint, effectively borrowing the token contract’s delegate authority over endpoint configuration.

How much money did the attacker actually steal? The attacker extracted approximately 14.75 million SAND from the Ethereum OFT Adapter, converting the tokens to roughly 79.74 ETH, worth approximately $675,000 at the time of the transactions. While the face value of minted tokens reached $49 billion, that figure is an arithmetic artifact that could never have been realized as actual value.

Were SAND tokens on Ethereum and Polygon affected? No. The exploit targeted the SAND OFT contract on Base and BNB Smart Chain. The Ethereum-side adapter contract and the Polygon deployment were not compromised. The maximum supply cap of 3 billion SAND on Ethereum remains intact.

Why did the attacker mint trillions of tokens if they could only extract $675,000? The minting was automated across 703 events and 173 wallets over five hours. The attacker likely aimed to drain as much backed value as possible from the Ethereum adapter, but the adapter balance was limited. The excess minting beyond what the adapter held produced unbacked tokens with no redemption path.

Is this a flaw in LayerZero’s protocol? Security researchers described the vulnerability as an application-level configuration failure, not a flaw in the LayerZero protocol itself. The issue was specific to how The Sandbox’s OFT contract on Base handled approveAndCall interactions with the LayerZero endpoint. However, the fact that three LayerZero-integrated bridges have been exploited in five months has intensified scrutiny of the protocol’s overall security model.

What did Korean exchanges do in response? Upbit and Bithumb halted SAND deposits and withdrawals, citing suspected security incidents under South Korea’s Virtual Asset User Protection Act. Coinbase separately delisted SAND perpetual futures contracts.

Will affected liquidity providers be compensated? The Sandbox announced plans to compensate eligible liquidity providers based on a pre-incident snapshot of balances on Base and BNB Smart Chain. The payment schedule and token source had not been disclosed as of Aug. 23, 2026.

How does this compare to other bridge exploits? By nominal value, the $49 billion face-value figure would make this the largest bridge exploit in crypto history. By actual extraction, the $675,000 loss ranks among the smallest. The key difference is that earlier exploits like Ronin ($625 million) and Wormhole ($326 million) had sufficient bridge liquidity for attackers to drain backed assets at scale, while the Sandbox adapter held only a fraction of the total SAND supply, structurally limiting losses.

Disclaimer: This article is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency investments carry significant risk. Always conduct your own research before making any financial decisions. Published Aug. 23, 2026.
2026-08-22 08:13 18d ago
2026-08-22 02:23 18d ago
The Sandbox pozastavil cross-chain bridge SAND po útoku
SAND The Sandbox
CoinGecko News 78
Original source text
US Treasury repurchase operations unexpectedly pushed Bitcoin’s price up 25%, triggering $4 billion in short-position liquidations.

After the U.S. Treasury expanded its long-term U.S. Treasury bond repurchase operations, the 30-year U.S. Treasury yield fell from a 19-year high of 5.34% to around 5.19%, while Bitcoin rose roughly 25% in several days, briefly topping $79,000. Around $4 billion in cryptocurrency short positions were liquidated during this period, further amplifying the rally. The U.S. Treasury had earlier announced it would raise the size of its longest-dated Treasury repurchase operations from $2 billion per operation to $4 billion. Analysts noted that this operation is not equivalent to the Federal Reserve’s quantitative easing (QE); its main function is to improve the liquidity of older bonds and optimize the debt structure, but the market views it as a policy support signal for long-term U.S. Treasury yields. Analysts believe the key driver of Bitcoin’s recent rally is not the repurchase operation itself, but the market’s prior over-concentration of short positions. As long-term U.S. Treasury yields fell, short sellers were forced to cover their positions, triggering a powerful short squeeze. Meanwhile, U.S. spot Bitcoin ETFs saw a net inflow of around $650 million this week, and Trump once again urged Congress to advance the CLARITY Act, further boosting market risk appetite. Jeff Ko, chief analyst at CoinEx, said the key now is whether Bitcoin can hold its 200-day moving average around $69,000 and turn it from resistance into support. Market participants also warned that if the 10-year U.S. Treasury yield re-breaks above 4.7% and the 30-year yield approaches 5.3%, Bitcoin’s current breakout could face renewed tests. Bitcoin has now broken above its 200-day moving average and continues to rise; the next phase of the market will focus on whether it can sustain its rally in a high-yield environment.

6 minutes ago

Strategy's Bitcoin holdings have generated an unrealized profit of $1.7187 billion.

Strategy currently holds 840,447 Bitcoin, with a total cost of $63.36 billion and an average entry price of $75,385. At Bitcoin’s current price of $77,430, the company’s Bitcoin holdings now have an unrealized profit of $1.7187 billion.

6 minutes ago

The Sandbox confirms SAND cross-chain bridge vulnerability; Base and BSC networks affected, cross-chain functionality suspended.

The Sandbox officials announced that the team has confirmed and fully contained the recent SAND cross-chain bridge vulnerability incident, which involved the Base and BNB Smart Chain (BSC) networks. The incident’s impact is limited, with the number of tokens involved accounting for less than 0.01% of SAND’s total supply. SAND on Ethereum and Polygon remains unaffected; user wallets were not compromised, and no action is required for affected token holders or liquidity providers. Attackers minted unbacked SAND tokens on Base and BSC networks via the vulnerability, per disclosures. Currently, The Sandbox has shut down SAND cross-chain functionality on both networks. SAND on Base and BSC has been isolated and is temporarily non-transferable or non-exchangeable. The Sandbox reminds users not to buy, sell, or trade SAND on Base and BSC, as liquidity on these networks has been impacted. The team has completed a pre-incident snapshot, is developing a compensation plan for affected liquidity pool (LP) users, and continues to investigate the full scope of the vulnerability. A full incident report and technical post-mortem will be released later.

6 minutes ago

A crypto whale opened a 4x long position worth $10.7 million on HYPE, with a liquidation price of $64.47.

According to monitoring by TradingBeats (formerly Hyperinsight), a crypto whale recently deposited approximately $4 million in USDC into Hyperliquid and opened a long position on HYPE. The wallet address established a 134,930 HYPE long position with 4x leverage, valued at around $10.7 million. Its entry price was $81.64, liquidation price stands at $64.47, and the current unrealized loss amounts to $315,000. The whale’s address is 0xa9d1c0fe2aa58038bac208ad390f69e7ce0c29a2.

6 minutes ago

Tesla has set the date for the press conference of its self-driving electric Cybercab.

Tesla has announced on social platforms that it will hold the Cybercab launch event on September 3, 2026, in Austin, Texas, United States. The automaker’s self-driving electric Cybercab officially entered production in North America this April, and the vehicle is AI-powered, with no steering wheel, pedals, or rearview mirrors.

6 minutes ago

Tencent's chip division head Gao Jianlin has resigned to found a startup, targeting the high-performance AI CPU track in the RISC-V space.

According to MaxForAI's disclosure, Gao Jianlin, a core lead in Tencent's chip research and development, recently left the tech giant to launch a startup focused on high-performance AI servers and Agentic AI, with plans to develop high-performance CPUs based on the RISC-V architecture. Gao is widely regarded as one of the early core drivers of Tencent's in-house chip ecosystem. Public records show he formed Tencent's FPGA hardware team in 2013, began laying the groundwork for AI chip R&D in 2018, established Penglai Lab in 2020, and spearheaded the development and data center deployment of multiple AI chips for Tencent. Unlike the currently fiercely competitive AI GPU market, Gao's new venture will center on CPUs. Gao believes that as Agentic AI advances rapidly, AI inference processes will involve model calls, tool execution, searches, database interactions, and extensive task scheduling, making CPUs take on a more critical scheduling and control role in AI systems. Reportedly, Gao was already involved in RISC-V-related R&D during his tenure at Tencent, contributing to multiple technical areas including chip architecture, verification, and backend development. His new company plans to build high-performance server CPUs based on the open RISC-V instruction set to enter the AI infrastructure market. To date, the startup's name, financing details, and specific product launch timeline have not been made public. The market is closely watching whether it will emerge as another key player in China's AI chip space targeting server CPUs and agent infrastructure.

6 minutes ago
2026-08-12 20:14 27d ago
2026-08-12 15:22 28d ago
Coinbase pozastaví perpetuální kontrakty pro 10 tokenů
AXS Axie Infinity BLUR Blur MEME Memecoin SAND The Sandbox SPX6900 SPX6900 ZRO LayerZero
CoinGecko News 78
Original source text
Coinbase will suspend perpetual contract trading for the following assets around 21:00 on August 26: Memecoin (MEME-PERP), The Sandbox (SAND-PERP), Moonbirds (BIRB-PERP), Blur (BLUR-PERP), Katana (KAT-PERP), SPX6900 (SPX-PERP), ZORA (ZORA-PERP), Axie Infinity (AXS-PERP), Gensyn (AI-PERP), and LayerZero (ZRO-PERP). Remaining open positions will be automatically settled, with the final settlement price based on the average index price of the 60 minutes prior to the trading suspension. The funding rate for the last cycle will be set to zero.

Relevant content

Mitsubishi UFJ Financial Group plans to launch an instant settlement service for Japanese government bonds using blockchain technology.

Japan’s largest banking group Mitsubishi UFJ Financial Group (MUFG) plans to leverage blockchain technology to offer instant settlement services for certain Japanese Government Bond (JGB) transactions. According to reports, MUFG will carry out blockchain-based JGB repurchase transactions using tokenized money market funds and stablecoins, with the goal of shortening the settlement process for traditional securities trades. (Nikkei)

4 hours ago

Goldman Sachs forecasts core PCE at 0.23%, slightly above core CPI and market consensus.

Following the release of CPI data, market focus has shifted to the July core PCE figures set to be published on August 26. Goldman Sachs projects July core PCE to rise 0.23% month-over-month, a slight uptick from core CPI and market consensus. Specifically, portfolio management fees are forecast to climb 8 basis points, reflecting second-quarter stock market gains. The investment bank notes that upcoming methodological adjustments may trigger volatility in PCE readings and drag down the annual core inflation rate. Goldman Sachs expects August core inflation to hold near 0.2%, and anticipates the Federal Reserve will maintain interest rates stable through the end of the year.

4 hours ago

Bank of America announces $250 billion infrastructure investment plan

Bank of America announced a $250 billion infrastructure investment plan on Wednesday, pledging to invest in key U.S. infrastructure sectors over the next year. The plan covers multiple areas including data centers and computing power, renewable energy generation, energy storage, natural gas, power transmission networks, and critical minerals and mining, aiming to support energy security, job growth, and economic competitiveness.

4 hours ago

The USDC Treasury has minted 250 million new USDC on Solana.

According to on-chain data, the USDC Treasury minted 250 million new USDC tokens on Solana 10 minutes ago.

4 hours ago

Morgan Stanley maintains its overweight rating on SpaceX, with a target price of $600 under a bull market scenario.

Morgan Stanley reaffirmed its overweight rating on SPCX, setting a target price of $300, and a $600 target in a bull case scenario. Analyst Adam Jonas believes the market is underestimating SpaceX’s broader AI platform, including its computing, connectivity, and real-time data capabilities. The upcoming Grok model could help narrow this valuation gap. Jonas views the approaching lock-up expiration as an opportunity rather than a risk, offering a potential entry point for investors.

4 hours ago

SpaceXAI launches Grok 4.6

According to official announcements, SpaceXAI has officially launched Grok 4.6. The official statement notes that Grok 4.6 prioritizes enhancing the capabilities of long-running agents, as well as boosting performance in more complex interactive and visualization tasks. It can sustain work on multi-step complex tasks, including researching topics, analyzing information, collaborating across codebases, or translating ideas into complete applications or work deliverables. Grok 4.6 has achieved leading performance across multiple agent coding and knowledge work benchmarks, with its Artificial Analysis Intelligence Index score matching that of GPT-5.6 Sol.

4 hours ago
2026-06-25 03:00 2mo ago
2026-06-10 19:18 2mo ago
Americká vláda přesunula LINK na Coinbase Prime
ARKM Arkham ETH Ethereum FTT FTX Token LINK Chainlink RNDR Render Token SAND The Sandbox UNI Uniswap
CoinGecko News 78
Original source text
A wallet tied to US government seized FTX Chainlink holdings moved 98,590 Chainlink (LINK) tokens, worth about $768,000, to Coinbase Prime on Wednesday, reviving speculation over a potential sale.

Blockchain trackers flagged the deposit within minutes. However, on-chain data alone does not confirm that the tokens are headed for the open market.

US government wallet transferring seized FTX Chainlink (LINK) to Coinbase Prime, Source: ArkhamWhy the Seized FTX Chainlink Transfer MattersOn-chain tracker Lookonchain first reported the movement, and tracking account Solid Intel flagged the same deposit.

Arkham labels the sending address under its US government entity and has documented earlier movements from the same cluster.

The US Government just moved $800K of Alameda’s funds.

Many Alameda/FTX assets that were seized by the DOJ will be returned to FTX estate creditors and those who lost assets in FTX’s collapse.

Another $800K has been reclaimed for crypto users. pic.twitter.com/jW7PAcF1p4

— Arkham (@arkham) May 29, 2026 Follow us on X to get the latest news as it happens

The funds originate from assets confiscated after FTX and Alameda Research collapsed in November 2022.

A federal judge later ordered Sam Bankman-Fried to forfeit $11 billion after his fraud conviction, with recovered funds directed toward victim compensation.

The US Marshals Service selected Coinbase Prime in July 2024 to custody and trade its large-cap digital assets.

“After a comprehensive process, the U.S. Marshals Service (USMS), a division of the U.S. Department of Justice, selected Coinbase Prime as its partner to safeguard and trade its “Class 1” (large cap) digital assets,” read an excerpt in a 2024 Coinbase blog.

Therefore, deposits to the platform often precede custody changes, over-the-counter deals, or liquidations.

The agency has managed seized crypto sales for over a decade, beginning with its auction of 30,000 Silk Road bitcoins in 2014.

Historically, it has favored structured sales over open-market dumps.

The transaction also extends a pattern of earlier seized altcoin transfers involving Uniswap (UNI), Render (RNDR), Ethereum (ETH), and The Sandbox (SAND), plus stablecoins.

Meanwhile, the FTX estate keeps repaying customers, with its fourth creditor distribution round delivering $2.2 billion in March.

Analysts See Limited Risk of a LINK Sell-OffChainlink’s current price sits near $7.66, down 2% over the past 24 hours. The token holds a $5.57 billion market cap and ranks 21st among cryptocurrencies.

Chainlink (LINK) Price Performance. Source: BeInCryptoThe transferred amount equals less than 0.4% of LINK’s $225 million daily trading volume. It also represents roughly 0.01% of the 727 million tokens in circulation.

Consequently, even an outright sale would barely move market liquidity.

Sentiment around the token remains cautious after a 27% slide over the past 30 days. LINK has also shed 49% over the past year, leaving holders alert to new supply signals.

In contrast, Chainlink’s ETF inflow outlook suggests institutional demand could absorb modest government supply over time.

Whether the tokens move to an over-the-counter desk or stay in custody should become clearer in the coming days.

The wallet’s next transaction will reveal whether the deposit marks routine management or the start of a liquidation.

Until then, the sell-off fears look larger than the numbers behind them.