Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
Top earner on the Meme coin 4Stock profit leaderboard continues reducing positions to lock in profits, still holds $196,000 worth of the token.
According to GMGN data, the BSC ecosystem meme coin 4Stock has dropped below $30 million in market capitalization, halving in value following CZ's retweet of a related BNC post. The top profit-making trader spent a total of $7,614 to build their position and is currently continuously reducing holdings to lock in gains. They still hold $196,300 worth of tokens, having sold $237,000 worth of tokens and transferred out $39,800 worth of tokens, for total profits exceeding $450,000. Note: 4Stock originated from the "stock meme" narrative launched by Four.meme. It first rolled out underlying assets for 4Stock linked to stock holdings, then allowed the community to issue meme coins using these assets as a liquidity pool. BNC4 is the first 4Stock coin-stock pair, pegged 1:1 to BNC stock of the corresponding BNB treasury company, with the meme coin "4Stock" tied to the BNC4 pool.
9 minutes ago
Strive adds 1,375 BTC to its holdings, lifting its total position to 24,531 BTC.
Strive CEO Matt Cole disclosed that the company added 1,375 Bitcoin (BTC) at an average price of $79,281 per coin, totaling approximately $109 million, bringing its total Bitcoin holdings to 24,531 coins.
9 minutes ago
Strategy did not increase its Bitcoin holdings last week, and repurchased $176 million in STRC stock.
According to official sources, Strategy did not add to its Bitcoin holdings last week. The firm has repurchased $176 million worth of STRC, and raised the size of its digital credit securities repurchase program from $1 billion to $2 billion. As of September 7, 2026, Strategy holds 845,050 BTC and approximately $6.5 billion in U.S. dollar assets.
9 minutes ago
Robinhood will launch prediction market contracts powered by Crypto.com.
According to The Wall Street Journal, Robinhood has reached an agreement with Crypto.com. Robinhood will add Crypto.com’s yes-or-no event contracts—part of Crypto.com’s prediction market business—to its trading platform. At the same time, Robinhood will acquire a minority stake in Crypto.com and its prediction market operations.
9 minutes ago
Garrett Jin continues to reduce his ZEC short positions, still facing an unrealized loss of over $19 million.
According to monitoring by TradingBeats (formerly Hyperinsight), Garrett Jin, the agent of the "1011 Insider Whale", has just reduced his ZEC short positions. As of press time, he has closed and reduced approximately 7,000 ZEC in short positions, bringing his 3x leveraged ZEC holdings down to 32,759.57 ZEC. His average entry price for the position is $576.2998, with current unrealized losses standing at $19.04 million.
9 minutes ago
Binance Alpha has listed PONS, CASHCAT, and Artificial Inu (AI).
According to its official website, Binance Alpha has listed PONS, CASHCAT, and Artificial Inu (AI).
PANews reported on September 3, based on SoSoValue data, that after several consecutive days of consolidation, the crypto market saw a slight rebound, with the GameFi sector performing strongly and rising 8.87% in 24 hours. Among them, Akedo (AKE) rose 82.95%, and The Sandbox (SAND) rose 4.65%. Meanwhile, Bitcoin (BTC) rose 0.65%, breaking through $77,000; however, Ethereum (ETH) fell 0.26% and remained below $2,400.
In other sectors, the Layer 2 sector rose 4.48% in 24 hours, with Arbitrum (ARB) up 12.97%; the AI sector rose 2.96%, with Kite (KITE) up 13.68%; the Meme sector rose 2.20%, with Pons (PONS) up 27.88%; the PayFi sector rose 1.55%, with Telcoin (TEL) up 4.06%; the Layer 1 sector rose 1.17%, with Aptos (APT) up 8.36%; and the CeFi sector rose 0.87%, with Aster (ASTER) up 5.07%.
In addition, the DeFi sector fell 0.05%, while Lighter (LIT) surged 14.31%, hitting a record high.
Following its listing on Binance derivatives, the token "牛来" extended its strong run, with its market capitalization surging past $140 million to reach a new all-time high.
According to GMGN market data, after launching on Binance Futures in the evening, BSC-based meme coin "Niu Lai" has shown strong performance, with its market cap briefly surging past $140 million to hit an all-time high. It is now trading at $130 million, up over 159% in the past 24 hours, with a 24-hour trading volume of $63.6 million. BlockBeats reminds users that most meme coins have no real use cases, experience significant price volatility, and caution is required for investments.
4 hours ago
Serenity intensifies its bullish stance on Macronix: DDR3 price hikes have far exceeded sell-side expectations, average selling price (ASP) revised up to double sequentially, and operating leverage is fully unlocked.
Serenity published a report analyzing the sell-side research on ESMT (Jinghao Ke, stock code 3006). In March, South China Securities projected ESMT’s Q2 DDR3 4Gb contract price would rise around 50% quarter-on-quarter, while Fubon Securities forecast DRAM prices would increase 40% quarter-on-quarter. By August, South China Securities had revised ESMT’s Q2 aggregate ASP upward to a 105% to 113% quarter-on-quarter rise, explicitly stating DDR3’s price increase was “significantly better than expected”. Serenity argues that the price hike in niche memory chips is no longer just a revenue story, but a major profit amplifier, with operating leverage stretched to an extreme. Powerchip’s wafer costs may double in the second half of the year, and customers’ willingness to absorb cost pass-through has far exceeded expectations. ESMT’s single-month net profit in July was around $109 million, far exceeding earlier model assumptions. Roughly annualized, this values the stock at as low as a 1.9x P/E ratio. DDR3 is mainly used in products like IP cameras and hard drives. Memory chips account for a very small share of customers’ total bill of materials (BOM), so even a few dollars more per chip is far cheaper than the cost of redesigning and re-certifying products, making demand relatively inelastic. The consensus view is that peers are shifting production capacity to high-value products like HBM and DDR5, leading to structural tightening in DDR3 and DDR2 supply.
4 hours ago
Analysis: BTC marks the third time in history of significant underperformance relative to the Nasdaq, with both prior instances seeing strong, independent rallies.
Analyst Rekt Fencer has published a 3-day ratio chart of Bitcoin (BTC) and the Nasdaq, marking three major drawdowns: roughly -84.9% in 2018, -80.7% in 2022, and the current -54.3% in 2026. The analyst pointed out that after Bitcoin underperformed the Nasdaq by such wide margins in the prior two instances, it went on to post very strong independent rallies, with prices surging sharply thereafter. With the current ratio dropping significantly again, history may repeat for the third time: the bottom is approaching, and BTC will regain strength going forward.
4 hours ago
Perspective: On-chain retail Bitcoin (BTC) activity has hit a two-year high, and the minor pullback appears more like position rotation rather than a market top.
CryptoQuant analyst Darkfost stated that on-chain retail Bitcoin activity has reached a two-year high. The current slight pullback from the $80,000 level is more of a rotation than a market top, Bitcoin’s medium-term demand remains strong, and investor demand for the cryptocurrency has increased by 17.4% over the past 30 days.
4 hours ago
Trump: Will Fill U.S. National Strategic Petroleum Reserve With Venezuelan Oil
US President Trump announced that the United States will fill its national strategic reserve with Venezuelan oil, and the process to replenish the reserve to full capacity will begin soon.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
Blockchain gaming platform The Sandbox has pledged to repay eligible SAND holders 1:1 after an Aug. 21 bridge exploit drained 14.744 SAND, worth about $700,000, from an Ethereum vault.
On Thursday, the company published a post-mortem, saying users who legitimately held bridged SAND on Base or BNB Smart Chain before the attack will receive an equal amount of Ethereum-based SAND. Compensation will come from The Sandbox treasury, with no new tokens minted.
The claims process is expected to open within two weeks and remain open for another two weeks. Two centralized exchanges hold more than 72% of eligible balances and will distribute compensation directly to their affected customers, according to The Sandbox.
The project said the attacker exploited a configuration flaw in SAND’s Base and BNB Chain contracts, allowing them to become the sole verifier of incoming bridge messages and mint unbacked tokens. The Sandbox confirmed that about 14.7 million SAND tokens were drained, equivalent to about 0.5% of the token’s 3 billion maximum supply.
Although more than 339 trillion unbacked SAND was minted on the two networks, those tokens have been isolated and cannot be bridged or redeemed. SAND on Ethereum and Polygon was unaffected.
The compromised bridge contracts will be permanently retired. The Sandbox said any future Base or BNB Chain bridges would use newly deployed contracts.
SAND traded at about $0.04 at the time of publication, down 10.4% over the previous seven days, according to CoinGecko.
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.
Blockchain gaming platform The Sandbox has pledged to repay eligible SAND holders 1:1 after an Aug. 21 bridge exploit drained 14.744 SAND, worth about $700,000, from an Ethereum vault.
On Thursday, the company published a post-mortem, saying users who legitimately held bridged SAND on Base or BNB Smart Chain before the attack will receive an equal amount of Ethereum-based SAND. Compensation will come from The Sandbox treasury, with no new tokens minted.
The claims process is expected to open within two weeks and remain open for another two weeks. Two centralized exchanges hold more than 72% of eligible balances and will distribute compensation directly to their affected customers, according to The Sandbox.
The project said the attacker exploited a configuration flaw in SAND’s Base and BNB Chain contracts, allowing them to become the sole verifier of incoming bridge messages and mint unbacked tokens. The Sandbox confirmed that about 14.7 million SAND tokens were drained, equivalent to about 0.5% of the token’s 3 billion maximum supply.
Although more than 339 trillion unbacked SAND was minted on the two networks, those tokens have been isolated and cannot be bridged or redeemed. SAND on Ethereum and Polygon was unaffected.
The compromised bridge contracts will be permanently retired. The Sandbox said any future Base or BNB Chain bridges would use newly deployed contracts.
SAND traded at about $0.04 at the time of publication, down 10.4% over the previous seven days, according to CoinGecko.
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.
The Sandbox has pledged to reimburse eligible SAND holders 1:1 after an Aug. 21 bridge exploit drained about 14.7 million tokens worth roughly $700,000 from an Ethereum vault.
Summary
The Sandbox will repay eligible SAND holders 1:1 after an Aug. 21 bridge exploit drained about 14.7 million tokens worth $700,000. Compensation will come from The Sandbox treasury without minting new SAND, with claims expected to open within two weeks. The attacker exploited a configuration flaw in the Base and BNB Chain contracts to mint more than 339 trillion unbacked SAND. The compromised bridge contracts will be permanently retired, while SAND on Ethereum and Polygon was unaffected. According to The Sandbox’s Aug. 27 post-mortem, users who legitimately held bridged SAND on Base or BNB Smart Chain before the attack will receive an equivalent amount of Ethereum-based SAND. The project plans to cover the payments from its treasury without minting new tokens.
Claims are expected to open within two weeks and remain available for another two weeks. Two centralized exchanges account for more than 72% of the eligible SAND balances, and The Sandbox said the exchanges will distribute replacement tokens directly to affected customers.
The Sandbox will repay SAND holders from its treasury The repayment plan covers legitimate bridged SAND balances that existed on Base and BNB Smart Chain before the exploit. Eligible users will receive SAND issued on Ethereum, replacing the tokens affected by the compromised bridge infrastructure.
The Sandbox said its treasury already holds the tokens required for the process, meaning the compensation will not increase SAND’s circulating or maximum supply. Users who held eligible balances through the two centralized exchanges handling most of the affected tokens will not need to submit individual claims.
For other holders, the project plans to launch a claims portal once the required infrastructure is ready. The two-week submission period is expected to begin within two weeks of the post-mortem, though the project did not provide a specific opening date.
The compensation plan follows an attack that targeted the contracts responsible for moving SAND between Ethereum and Base and BNB Smart Chain. While the exploiter was able to create an enormous quantity of unbacked SAND on the destination networks, the project said the damage to assets backing legitimate bridged tokens amounted to about 14.7 million SAND.
The stolen amount represented roughly 0.5% of SAND’s maximum supply of 3 billion tokens.
Configuration flaw gave the attacker control of bridge verification The Sandbox traced the incident to a configuration problem in the SAND contracts deployed on Base and BNB Smart Chain. The flaw allowed the attacker to become the sole verifier for incoming bridge messages, giving the address the ability to approve fraudulent messages without the authorization normally required by the bridge.
With control of that verification process, the attacker could mint SAND on the destination chains even though corresponding tokens had not been legitimately locked on Ethereum.
More than 339 trillion unbacked SAND tokens were eventually minted across Base and BNB Smart Chain, according to the post-mortem. The Sandbox said the fraudulent supply has since been isolated and cannot be bridged back to Ethereum or redeemed against legitimate SAND reserves.
SAND deployed directly on Ethereum and Polygon was not affected by the configuration flaw.
The distinction between legitimate and unbacked tokens is central to the reimbursement process because bridge systems commonly depend on assets being locked on one network before a corresponding representation is issued elsewhere. A crypto.news explainer published Aug. 3 detailed how lock-and-mint and related bridge designs rely on verification mechanisms to ensure destination-chain assets remain backed by value held elsewhere.
Crypto.news previously reported that bridge exploits have resulted in more than $4 billion in losses since 2021, with failures involving validator credentials, message verification and smart contracts among the methods attackers have used to compromise cross-chain infrastructure.
Compromised SAND bridges will be permanently retired Following the Aug. 21 attack, The Sandbox decided not to restore the affected Base and BNB Smart Chain bridge contracts. Both will instead be permanently retired.
Any future bridge connecting SAND with either network would require newly deployed contracts, according to the project. The Sandbox did not provide a timetable for restoring bridge access to Base or BNB Smart Chain.
Similar decisions to isolate or replace compromised bridge infrastructure have followed several attacks this year. In June, Humanity Protocol disclosed losses exceeding $36 million after attackers obtained administrative keys and took control of bridge systems spanning Ethereum and BNB Smart Chain.
The attackers in that incident were able to drain tokens from the Ethereum bridge and mint additional H tokens on BNB Smart Chain. A subsequent forensic investigation traced the compromised keys to a malware-infected developer machine that contained backups for seven private keys.
Another bridge incident in July hit Wanchain infrastructure connecting Cardano and BNB Chain. Blockchain security firm BlockSec said roughly 515 million NIGHT tokens were removed from the Cardano-side treasury in the Wanchain bridge exploit, worth about $9 million at the time. Midnight said its core network remained secure and described the incident as isolated to the bridge infrastructure.
Bridge exploits have continued through 2026 Cross-chain infrastructure has faced a series of attacks during 2026 involving different verification and security failures.
Axelar disabled bridge connections with Secret Network in June after an exploit resulted in approximately $4.7 million in losses. The incident affected Axelar-bridged assets on Secret Network while Axelar said its core protocol remained unaffected.
A month later, AFX suffered a $24.15 million USDC loss through a bridge operated by the trading protocol. The affected infrastructure was separate from Arbitrum’s native bridge, and the attacker subsequently moved the stolen USDC to Ethereum before converting it into about 12,467.5 ETH.
AFX later prepared a goodwill plan for users after its investigation linked the attack to a social engineering campaign that compromised internal development infrastructure. The protocol said it rebuilt key infrastructure and introduced new security measures following the incident.
The Sandbox’s reimbursement process is expected to begin once its claims system is ready. Eligible balances held through the two centralized exchanges will be handled directly by those platforms, while remaining holders will have two weeks to submit claims after the portal opens.
SAND was trading near $0.04 at the time of the post-mortem, down about 10.4% over the previous seven days.
TLDR The Sandbox will repay eligible SAND holders 1:1 after an Aug. 21 bridge exploit drained about 14.7 million tokens worth roughly $700,000. Payments will come from The Sandbox treasury, and no new SAND will be minted to cover the loss. Claims are expected to open within two weeks and stay open for another two weeks after that. An attacker exploited a configuration flaw in the Base and BNB Chain contracts to mint more than 339 trillion unbacked SAND. The compromised bridge contracts will be permanently retired, and SAND on Ethereum and Polygon was not affected. The Sandbox has told SAND holders they will be made whole after a bridge exploit hit the token on Aug. 21. The attack drained about 14.7 million SAND, worth close to $700,000, from an Ethereum vault.
The company shared the details in a post-mortem published Aug. 27. Users who held bridged SAND on Base or BNB Smart Chain before the attack will get an equal amount of SAND on Ethereum.
The Sandbox said its treasury already holds enough tokens to cover the payments. That means the fix will not raise SAND’s circulating or maximum supply.
Claims are expected to open within two weeks of the post-mortem and stay open for two more weeks after that. Two centralized exchanges hold more than 72% of the affected balances, and those platforms will send replacement tokens straight to their customers.
Other holders will need to use a claims portal once it is ready. The Sandbox did not give an exact date for when that portal will launch.
How the Exploit Happened The Sandbox traced the attack to a configuration flaw in its SAND contracts on Base and BNB Smart Chain. The flaw let the attacker become the only verifier for incoming bridge messages.
That control let the attacker approve fake messages without normal checks. As a result, they minted SAND on Base and BNB Smart Chain even though no matching tokens were locked on Ethereum.
More than 339 trillion unbacked SAND ended up in circulation across the two networks. The Sandbox said this fake supply has been isolated and cannot be bridged back or swapped for real SAND.
SAND issued directly on Ethereum and Polygon was not touched by the flaw. The stolen 14.7 million tokens equal about 0.5% of SAND’s 3 billion token maximum supply.
Bridge Exploits Continue Across Crypto The Sandbox will not restore the affected Base and BNB Smart Chain bridges. Both will be shut down for good, and any new bridge to those networks will need fresh contracts.
This is not the first bridge hack of the year. In June, Humanity Protocol lost more than $36 million after attackers got hold of administrative keys tied to a malware-infected developer computer.
In July, a bridge exploit tied to Wanchain hit Cardano and BNB Chain infrastructure. Security firm BlockSec said about 515 million NIGHT tokens, worth roughly $9 million at the time, were pulled from the Cardano side.
Axelar also disabled its bridge with Secret Network in June after a hack cost about $4.7 million. The company said its main protocol was not affected.
AFX lost $24.15 million in USDC through a bridge exploit in July. That attacker later converted the stolen funds into roughly 12,467.5 ETH before AFX rolled out a plan to help affected users.
Bridge attacks across crypto have caused more than $4 billion in losses since 2021, according to past crypto.news reporting. SAND was trading near $0.04 at the time of the post-mortem, down about 10.4% over the previous seven days.
The Sandbox announced it will fully reimburse SAND holders whose tokens were affected by an August 21 bridge exploit on Base and BNB Smart Chain. The attack drained approximately 14.7 million SAND, valued at around $700,000, from an Ethereum vault.
Compensation Plan and Claims ProcessAccording to a post-mortem published on August 27, The Sandbox stated that users who held bridged SAND on Base or BNB Smart Chain before the incident will receive an equivalent amount of SAND on Ethereum. The company clarified that its treasury holds sufficient SAND to cover all affected balances, so there will be no increase in the token’s circulating or maximum supply.
Two major centralized exchanges were identified as holding over 72% of the impacted SAND. These platforms plan to distribute replacement SAND directly to their customers. Meanwhile, other eligible holders will need to use a claims portal once it is launched. The Sandbox has not specified an exact release date for the portal but expects claims to open within two weeks of the post-mortem’s publication and remain open for an additional two weeks.
The Sandbox confirmed that all payments will come from its treasury and that no new SAND tokens will be minted, ensuring the total supply remains unchanged. Claims can be made through exchanges or a forthcoming portal within a limited window.
Vulnerability and Exploit DetailsThe exploit was traced to a configuration issue in the SAND bridge contracts on Base and BNB Smart Chain, which allowed an attacker to act as the sole verifier for incoming bridge messages. With this authority, the attacker approved fraudulent messages, circumventing standard security checks. This permitted the minting of unbacked SAND on both Base and BNB Smart Chain, even though no tokens were locked on Ethereum as collateral.
The attacker ultimately created over 339 trillion unbacked SAND across these networks. The Sandbox reported that these illegitimate tokens have been isolated and cannot be exchanged for real SAND or transferred back to Ethereum.
SAND on Ethereum and Polygon was not impacted. The company said the 14.7 million SAND stolen in the attack represent approximately 0.5% of SAND’s 3 billion token maximum supply.
Mini dictionary: The Sandbox is a blockchain-based virtual world platform where users can create, own, and monetize digital assets and experiences using SAND, its native token.
NetworkSAND ImpactedStatus after AttackEthereumNoneNot affectedPolygonNoneNot affectedBaseOver 339 trillion unbacked mintedBridge shut down, unbacked SAND isolatedBNB Smart ChainOver 339 trillion unbacked mintedBridge shut down, unbacked SAND isolatedBridge Security Risks RemainThe Sandbox will permanently retire the compromised Base and BNB Smart Chain bridge contracts. Any future bridges to these networks will require completely new contracts.
Bridge-related exploits have continued to be a persistent issue for the crypto industry. In June, Humanity Protocol suffered losses exceeding $36 million after attackers gained access to admin keys on a compromised developer computer. A similar event in July impacted Cardano’s infrastructure via a Wanchain bridge, with BlockSec reporting a loss of about 515 million NIGHT tokens, valued at $9 million at the time.
Also in June, Axelar shut down its bridge to Secret Network after a breach cost $4.7 million, though the main protocol was not affected. In July, AFX lost $24.15 million in USDC through a bridge attack before the funds were converted to nearly 12,468 ETH. The company initiated a recovery plan for affected users soon after.
Cumulatively, cross-chain bridge attacks have resulted in more than $4 billion in losses since 2021. Following the exploit, SAND traded near $0.04, reflecting a 10.4% decline over the previous week.
Treasury-funded compensation will use pre-incident balances on Base and BNB Chain without increasing SAND’s fixed 3 billion maximum supply.
The Sandbox will repay eligible holders of bridged SAND on Base and BNB Chain 1:1 in Ethereum-based SAND after an Aug. 22 exploit drained 14,742,341.84 SAND from its Ethereum vault, the project said in an Aug. 27 post-mortem.
The plan covers legitimately bridged balances recorded in a pre-incident snapshot, rather than tokens created through the unauthorized mint. The Sandbox will fund the replacements from its treasury and said no new SAND will be minted, leaving the token’s fixed 3 billion maximum supply unchanged.
Two centralized exchanges hold more than 72% of eligible balances and are expected to distribute replacement tokens directly to affected customers. Other qualifying holders will use a claims portal that The Sandbox expects to open within two weeks of the post-mortem and keep open for a further two weeks.
Configuration Flaw On Base and BNB Chain, the SAND token contract also acted as the LayerZero bridge integration, according to The Sandbox. A configuration function allowed the attacker to register as the sole verifier of incoming bridge messages, enabling fraudulent messages to mint unbacked SAND on both networks.
The 14.74 million SAND taken from the Ethereum vault represented about 0.5% of the token’s maximum supply. The final figure was materially higher than The Sandbox’s initial estimate of less than 0.01%, which the project said reflected only what it could observe during the first hours of containment.
The company said SAND on Ethereum and Polygon was unaffected. The additional unbacked tokens minted on Base and BNB Chain were isolated and cannot be bridged to Ethereum or redeemed against the vault, while bridging on the two affected networks remains disabled.
For the attacker’s funds, The Sandbox said it had reported the wallet to TRM Labs and Chainalysis for stolen-funds tagging and worked with centralized exchanges to disable deposits and withdrawals on the affected networks.
The compromised Base and BNB Chain bridge contracts will be permanently retired. Any future bridge to either network would require newly deployed contracts.
A bridge configuration flaw on Base and BNB Smart Chain let attackers hijack LayerZero delegate permissions, mint trillions of phantom SAND tokens, and drain roughly $675,000 from the Ethereum vault before the team shut everything down. The $49 billion face value headline masked the real story: structural constraints meant the attacker could never have cashed out more than a fraction of what was created.
Summary
An attacker exploited the `approveAndCall` function on The Sandbox’s SAND omnichain fungible token contract on Base, hijacking LayerZero delegate permissions and minting 329.24 trillion unbacked SAND across 703 events over five hours on Aug. 21 and 22, 2026. The face value of minted tokens reached approximately $49 billion according to security firm Blockaid, but the actual extraction totaled roughly 14.75 million SAND (about 80 ETH, or $675,000) drained from the Ethereum OFT Adapter in under 60 seconds. The Sandbox disabled bridging on Base and BNB Smart Chain, removed LayerZero peer settings via multisig governance, and confirmed that SAND on Ethereum and Polygon remained untouched throughout the incident. The project announced a 1:1 reimbursement plan from its treasury for eligible holders, with no new SAND tokens to be minted and a claims portal expected within two weeks of the Aug. 27 post-mortem. The exploit marked the third major LayerZero-related bridge failure in five months, accelerating a $15 billion migration wave from LayerZero to Chainlink CCIP led by BitGo, Mantle, and Lombard. On the night of Aug. 21, 2026, an address that had been dormant for 313 days routed a crafted payload through The Sandbox’s SAND token contract on Base. Within five hours, blockchain explorers showed trillions of freshly minted SAND tokens spreading across 173 wallets. Security firm PeckShield flagged the activity first, and by the time The Sandbox team responded, the attacker had already extracted what they could and moved on. The headline numbers were staggering, but the actual financial damage told a very different story.
The gap between the face value of minted tokens and the real amount stolen reveals something important about how bridge exploits actually work. It also exposes a recurring pattern in cross-chain infrastructure: the same design choices that make bridges useful also make them fragile, and a single misconfiguration can open a door that costs millions to close.
How the approveAndCall exploit worked The technical root of the attack sat inside a function called `approveAndCall` on The Sandbox’s SAND omnichain fungible token contract deployed on Base. In a standard OFT setup built on LayerZero, a delegate address on the destination chain holds administrative rights over the endpoint configuration. Those rights include the ability to set trusted peers, update security stacks, and authorize privileged calls into the token contract.
The attacker discovered that the `approveAndCall` function could be weaponized to hijack those delegate permissions. By routing a crafted payload through the SAND token contract, the attacker manipulated the delegation mechanism and assumed control over the minting process on Base. Once the delegate was compromised, the OFT no longer required a legitimate burn on the source chain to authorize a mint on the destination chain. The attacker essentially became the sole verifier for incoming bridge messages, gaining the ability to approve fraudulent messages without the authorization normally required by the bridge.
The Sandbox’s post-mortem stressed that no private keys were compromised and no unauthorized access to wallets took place. The vulnerability stemmed entirely from design flaws in the operational contract structure itself. That distinction matters because it means the flaw was not a case of stolen credentials or social engineering. It was a configuration problem baked into the bridge architecture from deployment.
BREAKING: Curve Finance halts LayerZero infrastructure out of precaution after rsETH LayerZero hack, affecting CRV bridging on multiple chains and crvUSD fast bridge pic.twitter.com/UwNvfxBew9
— crypto.news (@cryptodotnews) April 19, 2026 The attacker minted 329.24 trillion SAND across 703 separate events over approximately five hours on Aug. 21 and 22. The minting happened on Base first, with secondary exposure on BNB Smart Chain. Ethereum and Polygon, where the vast majority of SAND’s legitimate supply resides, were never affected.
The $49 billion illusion versus $675,000 reality The most misleading number in the entire incident was the $49 billion face value that Blockaid attached to the minted tokens. That figure came from multiplying the number of minted tokens by SAND’s market price at the time, a calculation that ignored every practical constraint on actually selling those tokens.
The reality was far smaller. The attacker drained approximately 14.75 million SAND from the Ethereum OFT Adapter in under 60 seconds. That extraction generated about 80 ETH, worth roughly $675,000 at the time of the transactions. The attacker sold tokens across 26 separate transactions, each sized to extract approximately 90 percent of available ether from the liquidity pool before it could recover.
One detail from the EGamers post-mortem stood out: the attacker minted exactly 14,743,364.21 SAND, which was precisely 100 tokens below the vault’s holdings at that moment. The precision suggested careful reconnaissance of the vault balance before execution. However, an unforeseen arbitrage bot disrupted the plan, leaving the attacker with 14,095,483.66 SAND instead of the intended amount.
The trillions of additional tokens minted on Base were essentially worthless. They could not be redeemed through the official bridge because The Sandbox disabled bridging before any meaningful redemption could occur. They could not be sold on decentralized exchanges because liquidity pools on Base did not hold anywhere near enough paired assets to absorb even a tiny fraction of the supply. The tokens existed on chain but had no path to value extraction.
This dynamic is important for understanding bridge exploits more broadly. The “total tokens minted” headline dramatically overstates the actual damage. The constraint is always liquidity, not the number on screen. An attacker can print any number of tokens on a destination chain, but the tokens are only worth what someone will pay for them, and in a bridge exploit scenario, the available liquidity evaporates almost instantly.
The Sandbox response and bridge shutdown The Sandbox team moved relatively quickly once the exploit was identified. Hours after PeckShield’s initial alert, the team disabled all bridging to and from Base and BNB Smart Chain. The shutdown was executed at the contract level on both chains, and the team removed LayerZero peer settings via multisig governance to prevent any further cross-chain messages from being processed.
The project issued a statement confirming that SAND tokens on Ethereum and Polygon were not affected. No user wallets were compromised. The SAND locked on Ethereum, which backs all legitimately bridged SAND, remained fully intact throughout the incident. The team estimated the impact at less than 0.01 percent of the total SAND token supply when measured against the 3 billion maximum supply.
Korean exchanges Upbit and Bithumb suspended SAND deposits and withdrawals on Aug. 22, citing a suspected security incident and South Korea’s Virtual Asset User Protection Act. Upbit went further and froze SAND transfers on Ethereum, the chain The Sandbox said was not affected, suggesting the exchange was taking a cautious approach regardless of the project’s assurances. Coinbase separately delisted SAND perpetual futures contracts.
SAND’s price saw a near 10 percent intraday plunge after the incident was disclosed but recovered most of the loss within 24 hours, trading down just 0.8 percent over the full day. The muted price impact reflected the market’s relatively quick understanding that the actual financial damage was small and that the inflated token count could not be converted to real value.
Bridge security remains the weakest link The Sandbox exploit did not happen in isolation. It was the third major LayerZero-related bridge failure in five months, following the $292 million Kelp DAO attack in April and the Stake DAO breach in May. Each exploit targeted different aspects of LayerZero’s architecture, but all three shared a common thread: insufficient verification redundancy.
JUST IN: Coldcard wallets affected by security issue with reported losses
Roughly 594 $BTC valued at $38 million has been stolen from certain dormant single sig wallets pic.twitter.com/f3fk7kYXzM
— crypto.news (@cryptodotnews) August 1, 2026 The Kelp DAO attack was the most damaging. On April 18, 2026, attackers linked to North Korea’s Lazarus Group drained 116,500 rsETH, worth approximately $292 million, from KelpDAO’s LayerZero-powered bridge. The attack began six weeks earlier when an attacker socially engineered a LayerZero Labs developer, harvesting session keys and pivoting into LayerZero’s internal RPC environment. The attackers then poisoned internal RPC nodes and launched a DDoS attack against external providers, feeding false data to a single verifier that was the only checkpoint standing between the attacker and $292 million.
The KelpDAO hack wiped $13 billion from DeFi within 48 hours as users rushed to exit protocols they perceived as vulnerable. Curve Finance halted LayerZero infrastructure as a precaution after the attack, affecting CRV bridging on multiple chains.
LayerZero’s Decentralized Verifier Network allows applications to select as few as one verifier to validate cross-chain messages. Chainlink CCIP, by contrast, requires a minimum of 16 independent node operators per lane plus a separate Risk Management Network. That architectural difference explains why the industry response to these exploits has been a massive migration away from LayerZero.
By August 2026, publicly announced migrations from LayerZero to Chainlink CCIP totaled approximately $15 billion in secured value. BitGo led the wave by moving $7.4 billion in WBTC. Mantle shifted its $2.5 billion Super Portal. Lombard transferred over $1 billion in bitcoin-backed assets. Solv Protocol moved $700 million in tokenized bitcoin reserves. Kraken replaced LayerZero with Chainlink CCIP for its kBTC wrapped asset. Even Wyoming’s Stable Token Commission selected Chainlink CCIP for its Frontier Stable Token.
LayerZero’s ZRO token fell to approximately $302 million in market capitalization from an all-time high near $7.47. Nethermind, a former LayerZero verifier operator, exited to join Chainlink as a node operator.
The reimbursement plan The Sandbox announced on Aug. 27 that it would reimburse affected SAND holders at a 1:1 ratio from its treasury. The total loss stood at 14.7 million SAND tokens, worth approximately $700,000. No new tokens would be minted for the compensation, meaning the reimbursement would not increase SAND’s circulating or maximum supply.
Eligible users were those who legitimately held bridged SAND on Base or BNB Smart Chain before the Aug. 21 attack. The project planned a snapshot-based compensation system using pre-attack balances. The two largest centralized exchanges holding over 72 percent of affected balances agreed to distribute replacement tokens directly to their customers without requiring individual claims. Other holders would need to submit claims through a dedicated portal expected to open within two weeks of the post-mortem.
The treasury-funded approach was a relatively clean resolution. Unlike some exploit responses that involve emergency token mints, governance votes on inflation, or protracted recovery processes, The Sandbox had sufficient reserves to absorb the loss directly. The $700,000 price tag, while not trivial, was manageable for a project with a treasury of its size.
The history of bridge exploits in numbers Cross-chain bridges have consistently been the most attacked category of smart contracts since the technology emerged. The cumulative damage tells a sobering story about the structural risks of moving assets between blockchains.
Bridges have leaked more than $4 billion to hackers since 2021, according to data compiled across Chainalysis, DeFiLlama, and independent security researchers. The list of individual disasters includes the $624 million Ronin exploit in March 2022, the $326 million Wormhole theft in February 2022, the $190 million Nomad hack in August 2022, and the $292 million Kelp DAO breach in April 2026.
In 2024, bridges and cross-chain messaging protocols accounted for $1.19 billion of total crypto losses despite representing fewer than 5 percent of monitored protocols by count. That disproportionate figure reflects the concentrated risk that bridges carry: they hold or control large pools of assets across chains, and a small flaw can drain a fortune in minutes.
The year 2025 was worse. Over $3 billion was stolen across 119 hacks in just the first half of the year, a 50 percent jump over all of 2024’s losses. More than $1.5 billion of that total funneled through cross-chain bridges. The $1.5 billion Bybit compromise drove much of the annual total.
In 2026, bridge exploits have already accounted for $329 million from eight separate attacks through August. April 2026 was identified as the single worst month in DeFi’s history by number of attacks, with more than 30 separate incidents netting attackers almost $635 million in total. Q2 2026 saw 99 exploits draining $746 million, with cumulative DeFi losses for the year exceeding $840 million by the end of May.
The pattern is clear: despite years of audits, bug bounties, and architectural improvements, bridges remain the soft underbelly of cross-chain infrastructure. Each year brings new attack vectors and new headlines, but the fundamental vulnerability persists because bridges must hold concentrated pools of value and rely on verification mechanisms that can be compromised.
JUST IN: Bill Gates said the world “crossed the threshold of danger” on AI last year
He said he expected society to step in when the line was crossed, and instead the industry is arguing with itself pic.twitter.com/Bdrw9oCjWI
— crypto.news (@cryptodotnews) August 29, 2026 The OFT architecture problem The Sandbox exploit raised uncomfortable questions about the omnichain fungible token standard itself. OFTs are designed to allow tokens to move freely across multiple blockchains by burning on one chain and minting on another, with a locked pool on the home chain serving as the ultimate backing. The architecture is elegant in theory, but each destination chain introduces a new attack surface.
In The Sandbox’s case, the SAND contract on Base inherited the `approveAndCall` function from earlier ERC-20 implementations. That function was designed for a different era of token standards, one where tokens lived on a single chain and delegate permissions carried less weight. When combined with LayerZero’s OFT framework, the function became a vector for hijacking cross-chain minting authority. The interaction between legacy token functions and modern cross-chain messaging created a vulnerability that neither system would have had in isolation.
The problem extends beyond The Sandbox. Any OFT deployment that includes `approveAndCall` or similar callback functions on destination chains could be vulnerable to the same class of attack. The Sandbox’s post-mortem did not disclose how many other OFT deployments share this pattern, but security researchers have noted that the function is common in older token contracts that were later wrapped in OFT adapters.
The broader lesson is that cross-chain token standards must account for the full surface area of the underlying token contracts they wrap. An audit that examines only the bridge logic without scrutinizing legacy functions on the token itself can miss exactly the kind of flaw that enabled the SAND exploit. Projects that deployed OFT bridges on top of existing token contracts face a particular risk because the original contracts were designed without cross-chain minting authority in mind.
This architectural concern is separate from the LayerZero verifier discussion. Even with multiple verifiers, a delegate hijack through `approveAndCall` could bypass the verification layer entirely because the attacker would already hold the keys to the minting function. The fix requires changes at the token contract level, not just the messaging protocol level.
Lessons from the phantom mint The Sandbox incident crystallized several lessons that apply far beyond a single gaming token.
First, face-value calculations are misleading and potentially dangerous for market participants. When Blockaid reported $49 billion in minted tokens, that number traveled through headlines and social media without context. Traders who sold SAND based on a $49 billion figure were reacting to a phantom number. The actual extraction was $675,000. The gap between those two numbers is the difference between a catastrophic failure and a manageable incident. Media outlets that reported the $49 billion number without qualifying it as a notional figure contributed to unnecessary panic selling and distorted the market’s initial reaction to the incident.
Second, the approveAndCall vulnerability was a configuration flaw, not a novel zero-day exploit. The function existed in the deployed contract from the beginning. The delegate permissions structure was part of the standard OFT architecture. The attacker did not need to discover a previously unknown cryptographic weakness or break any encryption. They needed to understand how the pieces fit together and find the point where a crafted payload could hijack existing permissions. That kind of composability risk, where two individually safe systems become dangerous when combined, is one of the hardest categories of vulnerability to catch in standard security audits.
Third, the dormant wallet pattern is worth watching. The attacker’s address had been inactive for 313 days before the exploit. That kind of operational patience suggests either a sophisticated actor who prepared the exploit well in advance or someone who acquired access to a previously funded wallet specifically for this purpose. Either way, the long dormancy period meant the address would not have triggered activity-based monitoring until it was too late. On-chain surveillance systems that rely on recent activity patterns would have classified the wallet as inactive and deprioritized it from alerting systems.
Fourth, the arbitrage bot interference highlighted an underappreciated dynamic in DeFi exploits. The attacker planned their extraction with precision, minting exactly 100 tokens below the vault’s holdings. An automated trading bot disrupted that plan, reducing the attacker’s take by roughly 650,000 SAND. The interaction between exploit execution and automated market activity is a growing factor in how these incidents play out. In some cases, bots can accelerate an exploit by front-running the attacker’s swaps. In this case, the bot accidentally served as an unintentional defense mechanism by consuming liquidity the attacker needed.
Fifth, the speed of the actual extraction deserves attention. The attacker drained 14.75 million SAND from the Ethereum OFT Adapter in under 60 seconds. The five-hour minting spree on Base was essentially noise. The real damage happened in a single minute on Ethereum. That timeline underscores why bridge monitoring systems need to focus on vault drain velocity rather than destination-chain minting volume. A system that alerted on unusual minting activity on Base would have fired hours before the actual theft, but the theft itself was over before any human could have intervened.
What to watch Bridge audit disclosures: Whether The Sandbox publishes a full technical post-mortem with contract-level details, or limits disclosure to high-level summaries, will signal how transparent the project intends to be about the root cause
LayerZero configuration changes: LayerZero said it will stop signing messages for applications using single-DVN configurations; watch whether existing integrators upgrade or migrate to alternatives
Reimbursement portal launch: The claims portal for non-exchange holders is expected within two weeks of the Aug. 27 post-mortem; delays or complications could erode holder confidence
Korean exchange relisting: Upbit and Bithumb suspended SAND trading; their timeline for restoring deposits and withdrawals will indicate how regulators view the incident severity
CCIP migration pace: The $15 billion migration from LayerZero to Chainlink CCIP is accelerating; further bridge incidents could push total migration volume past $20 billion by year-end
How many SAND tokens were actually minted in the exploit? The attacker minted 329.24 trillion unbacked SAND tokens across 703 separate events over approximately five hours on Aug. 21 and 22, 2026. Security firm PeckShield initially flagged roughly 14.9 billion SAND created across two wallet addresses, while Blockaid put the face value near $49 billion across more than 400 transactions.
How much money was actually stolen from The Sandbox? The actual financial extraction was approximately 14.75 million SAND drained from the Ethereum OFT Adapter in under 60 seconds. The attacker converted those tokens into roughly 80 ETH, worth about $675,000 at the time. The EGamers post-mortem estimated total economic damage at approximately $1.5 million when including broader market impact and slippage losses across affected liquidity pools.
What was the approveAndCall vulnerability? The `approveAndCall` function on The Sandbox’s SAND omnichain fungible token contract on Base allowed the attacker to route a crafted payload that hijacked LayerZero delegate permissions. Once the attacker controlled the delegate, they could authorize minting on the destination chain without a corresponding burn or deposit on the source chain. No private keys were compromised; the vulnerability was a design flaw in the contract structure.
Will The Sandbox reimburse affected holders? Yes. The Sandbox announced a 1:1 reimbursement plan funded from its treasury. No new SAND tokens will be minted. The two largest exchanges holding over 72 percent of affected balances will distribute replacement tokens directly to customers. Other holders must submit claims through a portal expected within two weeks of the Aug. 27 post-mortem.
Were SAND tokens on Ethereum and Polygon affected? No. The exploit targeted only the bridge contracts on Base and BNB Smart Chain. SAND on Ethereum and Polygon was not affected. The SAND locked on Ethereum that backs all legitimately bridged SAND remained fully secure throughout the incident. No user wallets on any chain were compromised.
Why did Korean exchanges suspend SAND trading? Upbit and Bithumb suspended SAND deposits and withdrawals on Aug. 22 under South Korea’s Virtual Asset User Protection Act after detecting abnormal on-chain activity. Upbit froze SAND transfers on Ethereum despite The Sandbox confirming that chain was unaffected, suggesting the exchange adopted a cautious approach. Coinbase also delisted SAND perpetual futures contracts.
What is the connection between this exploit and the Kelp DAO hack? Both exploits targeted LayerZero-powered bridge infrastructure. The Kelp DAO hack in April 2026 drained $292 million through a compromised single-verifier configuration. The Sandbox exploit in August used a different attack vector (approveAndCall function hijacking) but exploited a similar weakness: insufficient verification redundancy in LayerZero’s architecture. Together with the Stake DAO breach in May, these three incidents accelerated a $15 billion migration from LayerZero to Chainlink CCIP.
How do phantom token mints differ from real theft in bridge exploits? A phantom mint creates tokens on a destination chain without a corresponding deposit or burn on the source chain. While the face value can reach astronomical numbers, the tokens are only worth what available liquidity allows them to be sold for. In The Sandbox case, 329 trillion tokens were minted with a notional value of $49 billion, but the attacker could only extract $675,000 because that was the extent of reachable liquidity. The distinction between minted face value and extractable value is critical for accurately assessing bridge exploit severity.
Disclaimer: This article is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency investments carry significant risk, and readers should conduct their own research and consult with qualified professionals before making any investment decisions. Published Aug. 29, 2026.
The Sandbox, the blockchain-based metaverse and gaming platform, faced a significant security incident involving its cross-chain bridging infrastructure. The vulnerability allowed an unauthorized party to generate large volumes of SAND tokens without proper collateral on the Base and BNB Smart Chain networks.
Security researchers first detected unusual activity around August 21–22, 2026.
Firms such as Blockaid and PeckShield reported that an attacker had compromised permissions tied to the project’s LayerZero-based Omnichain Fungible Token (OFT) setup.
By exploiting a function known as approveAndCall, the actor gained the ability to create tokens on the secondary chains without corresponding locked SAND on Ethereum.
The Sandbox team has identified and fully contained a recent vulnerability regarding the SAND cross-chain bridge on Base and BNB Smart Chain (BSC). The impact is minimal, representing less than 0.01% of the total SAND token supply.
SAND tokens on Ethereum and Polygon are NOT…
— The Sandbox (@TheSandboxGame) August 22, 2026
Early alerts noted hundreds of millions of tokens appearing, with subsequent tallies showing roughly 14.9 billion SAND directed to a pair of addresses linked to the activity.
Broader estimates placed the face-value total of newly created tokens in the tens of billions of dollars across hundreds of transactions.
Some analyses even described far higher nominal figures distributed over multiple addresses during a multi-hour window.
Despite the scale of the unauthorized minting, the real-world financial impact remained limited.
Investigators determined that only about 14.75 million legitimately backed SAND—valued at approximately $675,000 at the time—left the Ethereum-side bridge adapter, along with a modest amount of ETH.
The Sandbox itself assessed the overall effect at less than 0.01 percent of the token’s legitimate maximum supply of 3 billion.
The project responded swiftly.
Officials confirmed they had identified and fully contained the issue.
Bridging functions to and from Base and BNB Smart Chain were disabled, effectively isolating the unbacked tokens so they could not be moved or redeemed against the Ethereum collateral.
SAND held on Ethereum and Polygon remained completely unaffected.
No individual user wallets were compromised, and the SAND locked on Ethereum that underpins all bridged tokens stayed secure.
Major exchanges reacted cautiously. South Korean platforms Upbit and Bithumb suspended SAND deposits and withdrawals.
Users were strongly advised not to buy, sell, or trade the token on the affected networks while liquidity there remained compromised.
The Sandbox said it captured a pre-incident snapshot of balances and is preparing a compensation framework for eligible liquidity providers affected by the event.
The team pledged to release a full technical post-mortem once its investigation concludes.
Community members affected by liquidity pool disruptions were directed to contact official support channels.
The episode underscores ongoing challenges with cross-chain bridges and omnichain token designs in the broader cryptocurrency ecosystem.
While the rapid isolation of the affected networks prevented wider damage, it also highlighted how permission and delegate mechanisms can become points of failure.
For SAND holders on the primary chains, the incident appears to have been successfully limited, with core infrastructure and user assets preserved. This event serves as another reminder of the importance of security reviews for multi-chain deployments as blockchain projects continue expanding their interoperability features.
South Korean crypto exchanges Upbit and Bithumb have designated The Sandbox’s SAND token as an investment caution asset after security concerns linked to the project remained unresolved following a cross-chain bridge incident.
Summary
Upbit and Bithumb designated SAND as an investment caution asset over unresolved security concerns. The Sandbox said a bridge vulnerability allowed unbacked SAND to be minted on Base and BNB Smart Chain. Upbit will review SAND through late September and could remove, extend or escalate the warning. The Sandbox said Ethereum and Polygon SAND balances and user wallets were unaffected. According to Upbit’s Aug. 24 announcement, the exchange placed SAND under its trading caution framework after determining that an unexplained or unresolved security incident involving a virtual asset wallet or distributed ledger could expose users to potential losses.
The designation applies to SAND’s Korean won and Bitcoin markets, while deposits and withdrawals have already been suspended since Aug. 22 at 11:12 a.m. KST. Trading remains available during the review period.
Bithumb issued a separate designation at 3 p.m. KST on Aug. 24, citing confirmed security incidents such as hacking involving virtual asset wallets or distributed ledgers where the cause has not been identified or the problem has not been fully resolved. The exchange had halted SAND deposits and withdrawals at 11:11 a.m. KST on Aug. 22 after detecting signs of a possible security problem.
SAND warning follows abnormal token minting Two days before the formal caution designations, Bithumb said it had detected abnormal token minting activity involving the SAND smart contract on Base and warned users that the incident could increase price volatility.
The Sandbox later said it had identified and contained a vulnerability affecting its SAND cross-chain bridge on Base and BNB Smart Chain. According to the project, an attacker had been able to mint unbacked SAND on the two networks, prompting the team to disable bridging to and from both chains.
The project estimated the actual impact at less than 0.01% of SAND’s total supply and said SAND held on Ethereum and Polygon was unaffected. It also said no user wallets had been compromised and that the SAND locked on Ethereum to back legitimate bridged tokens remained secure.
With bridging disabled, The Sandbox said SAND on Base and BNB Smart Chain had been isolated and could not be moved or redeemed through the affected bridge. The team advised users against buying, selling or trading SAND on the two networks while liquidity remained affected.
Security firm Blockaid separately said attackers had hijacked LayerZero delegate permissions through the approveAndCall function used by SAND’s omnichain token setup. The firm reported that a large nominal amount of unbacked SAND had been minted across hundreds of transactions, although the face value of newly created tokens did not represent the project’s reported financial loss.
The Sandbox has also taken a snapshot of balances from before the incident and is preparing a compensation plan for eligible liquidity providers affected on Base and BNB Smart Chain. A full incident report and technical post-mortem are expected after the investigation is completed.
Upbit could end SAND trading support if concerns remain Upbit has scheduled its initial SAND review period from Aug. 24 at 3 p.m. KST through the fifth week of September, running from Sept. 28 to Oct. 4.
During that period, the exchange will review the reasons behind the caution designation under its digital asset trading support termination policy. Depending on the findings, Upbit can remove the warning, extend the review or decide to terminate trading support.
A security concern that has not been completely resolved can result in trading support being withdrawn, according to the exchange. Any extension or termination decision will be published separately with the applicable schedule.
SAND deposits made after the caution notice was published will not be credited to user accounts and will instead qualify for return processing. The token has also been removed from assets available for new borrowing applications under Upbit’s coin lending service, although existing loans can remain active until their original maturity dates.
Upbit said SAND withdrawals will be the first transfer service restored when the current suspension ends. Deposits will not automatically reopen at the same time and will instead be handled under the procedure applicable to assets already designated for trading caution.
Bithumb is working on a slightly different review schedule. Its notice said a decision on extending or removing the designation, or ending trading support, is expected during the first week of October, specifically between Sept. 28 and Oct. 2. The schedule can change depending on the exchange’s internal review.
Bithumb also said the caution status can be removed before the review period ends if the underlying reasons are resolved.
Korean exchanges have used similar reviews after exploits The SAND action follows previous cases in which South Korean exchanges placed tokens under caution while assessing a project’s response to a security breach.
In July, crypto.news reported that Upbit removed its warning on Taiko after reviewing information supplied by the layer-2 project about a June bridge exploit and the security measures introduced afterward.
TAIKO had initially been placed under warning on June 22 after Upbit identified a security incident involving systems used to issue, transfer or store the asset. Deposits were blocked during the review while existing balances could still be traded.
After a 32-day review, Upbit said the project had provided information covering the cause of the breach and subsequent security measures, allowing the exchange to determine that the reason for the warning had been resolved. Bithumb removed its TAIKO warning on the same day and prepared to restore deposits.
Security incidents have also led to more severe outcomes when Korean exchanges were not satisfied with a project’s remediation.
Earlier this year, Flow Foundation and Dapper Labs sought a court order after Upbit, Bithumb and Coinone moved to end FLOW trading support following a December 2025 exploit.
The Flow incident involved a protocol-level vulnerability that allowed an attacker to create duplicated tokens and extract about $3.9 million in value. Flow later said user balances were not affected, while validators and exchange partners took emergency measures to contain the incident and recover funds.
Despite the later remediation work, the Korean exchanges moved toward delisting FLOW, prompting the foundation and Dapper Labs to ask the Seoul Central District Court to suspend the trading termination while additional evidence was reviewed.
Security controls remain under regulatory scrutiny Security incidents at South Korean trading platforms have also drawn attention from domestic regulators under the country’s Virtual Asset User Protection Act.
South Korea’s Financial Supervisory Service began a formal sanctions process against Upbit operator Dunamu in July over a November 2025 wallet breach that affected Solana-based assets.
The FSS action followed an inspection into whether the exchange had met its obligations under the user protection law. Korean reports cited in the July coverage put the affected amount at 44.5 billion won, while Upbit said after the incident that customer losses would be covered with company funds.
Following the breach, Upbit moved assets into cold wallets, suspended deposits and withdrawals and began tracing the stolen funds. Regulators subsequently examined both the security failure and how the exchange disclosed the incident to users.
An attacker weaponized a single ERC-20 function to hijack LayerZero delegate permissions and mint 329 trillion unbacked SAND on Base, yet the actual reserve drain totaled just $675,000, exposing both the fragility and the hidden safeguards of cross-chain token architecture.
Summary
An attacker exploited the approveAndCall function on The Sandbox\u2019s SAND omnichain fungible token contract on Base, hijacking LayerZero delegate permissions and minting 329.24 trillion unbacked SAND across 703 events over five hours on Aug. 21 and 22, 2026. Blockchain security firm Blockaid flagged $49 billion in face-value SAND minted across more than 400 transactions, while PeckShield counted 14.9 billion SAND directed to two attacker-controlled addresses. The actual financial extraction was far smaller: roughly 14.75 million SAND drained from the Ethereum OFT Adapter in under 60 seconds, yielding approximately 80 ETH (around $675,000 at the time of the transactions). The Sandbox disabled bridging on Base and BNB Smart Chain, removed LayerZero peer settings via multisig, and confirmed that SAND on Ethereum and Polygon was unaffected; Korean exchanges Upbit and Bithumb halted deposits and withdrawals, and Coinbase delisted SAND futures. The incident marks the third major LayerZero-related bridge exploit in five months, following the $292 million Kelp DAO attack in April and the Stake DAO breach in May, accelerating a $15 billion migration wave from LayerZero to Chainlink CCIP. On the night of Aug. 21, 2026, an address that had been dormant for 313 days routed a crafted payload through The Sandbox\u2019s SAND token contract on Base. Within five hours, blockchain explorers showed trillions of freshly minted SAND tokens spreading across 173 wallets. The face value, calculated by multiplying inflated balances against the live market price, briefly crossed $49 billion. That number exceeded the market capitalization of all but a handful of crypto projects. It also had almost no relationship to the money the attacker actually took.
The gap between the headline figure and the real extraction ($675,000, roughly the price of a modest house) reveals something important about how cross-chain token systems work and how they fail. It also reveals how crypto security reporting can amplify panic through numbers that are technically accurate but practically meaningless. Understanding why the attacker could mint a number larger than the gross domestic product of several small nations, yet walk away with a fraction of a fraction of that sum, requires examining the architecture that made the exploit possible and the constraints that limited its damage.
The Sandbox is one of the most recognizable names in Web3 gaming, with its SAND token powering a virtual world where users create, own, and monetize gaming experiences. The project was expanding its cross-chain presence to Base and BNB Smart Chain through LayerZero\u2019s OFT framework when the vulnerability was exploited. That expansion, intended to improve accessibility and reduce transaction costs for users, instead became the vector for the largest nominal-value bridge exploit in crypto history.
What happened on the night of Aug. 21 The first on-chain signal appeared at 23:42:05 UTC on Aug. 21. An externally owned account, later tagged by PeckShield as attacker-controlled address 0x638C, began submitting transactions to the SAND OFT contract deployed on Base. Each transaction invoked the approveAndCall function, a standard ERC-20 extension designed as a user-experience shortcut that combines a token approval and a follow-on contract call in a single transaction.
In this case, the follow-on call was anything but routine. The crafted payload routed through the token contract into the LayerZero endpoint, granting the attacker\u2019s helper contract the effective standing of a delegate with administrative rights over endpoint configuration. Once that delegate status was secured, the attacker could mint SAND on Base without any corresponding lock of tokens on the Ethereum side.
BREAKING: Curve Finance halts LayerZero infrastructure out of precaution after rsETH LayerZero hack, affecting CRV bridging on multiple chains and crvUSD fast bridge pic.twitter.com/UwNvfxBew9
— crypto.news (@cryptodotnews) April 19, 2026 Over the next five hours, 703 distinct minting events distributed newly created SAND to 173 addresses. The minting stopped organically at 04:45:21 UTC on Aug. 22. Twenty-four minutes later, at 05:09:19 UTC, The Sandbox\u2019s multisig wallet zeroed out the trusted peer settings for Base and BNB Smart Chain, severing the cross-chain link that the attacker had exploited.
How approveAndCall became an attack vector The approveAndCall function exists in many ERC-20 token implementations. It was originally conceived to solve a genuine usability problem: standard ERC-20 transfers require two separate transactions (approve, then transferFrom), costing users extra gas and extra time. By bundling both steps, approveAndCall lets a user approve a spender and trigger an action in a single transaction.
The vulnerability in the SAND implementation was not in the approval mechanism itself but in what the function allowed as the \u201ccall\u201d portion. When the SAND OFT contract on Base processed an approveAndCall transaction, it forwarded the embedded calldata to the target contract specified by the caller. If that target was the LayerZero endpoint, the call arrived with the token contract as the msg.sender, not the original external caller.
This distinction matters because LayerZero\u2019s endpoint checks permissions based on msg.sender. The SAND OFT contract held delegate authority over its own endpoint configuration. By routing through approveAndCall, the attacker effectively borrowed that authority. The result was a privilege escalation: an unauthorized external account gained the ability to reconfigure the endpoint and authorize arbitrary minting.
Security researchers from Blockaid described the root cause as \u201cthe takeover of LayerZero delegate permissions through an approveAndCall function.\u201d It was not a flaw in the LayerZero protocol itself but an application-level configuration failure in how The Sandbox\u2019s OFT contract interacted with the endpoint.
The $49 billion that never existed The face-value figure that circulated in the hours after the exploit deserves careful scrutiny. Blockchain explorers calculate token values by multiplying balances against the last traded price. When an attacker mints 329.24 trillion SAND and the token trades at fractions of a cent, the resulting number is mathematically enormous but economically hollow.
SAND has a legitimate maximum supply of 3 billion tokens on Ethereum. The attacker\u2019s 329 trillion minted tokens exceeded that supply by a factor of roughly 110,000. No market on any exchange, centralized or decentralized, could absorb even a tiny fraction of that volume at the quoted price. The moment any significant sell pressure materialized, the price on affected venues would collapse toward zero.
The actual extraction followed a different, far more constrained path. Within the first 60 seconds of the exploit, 14.75 million SAND was withdrawn from the Ethereum OFT Adapter, the contract that holds locked SAND backing cross-chain transfers. That withdrawal happened across 15 transactions, with 14,095,483 SAND routed to a single externally owned account in six transactions over 24 seconds. The total proceeds converted to approximately 79.74 ETH, worth roughly $675,000.
The Sandbox put the impact at \u201cless than 0.01% of the total SAND token supply.\u201d While critics noted the percentage framing downplayed the absolute dollar figure, the math is straightforward: 14.75 million tokens divided by 3 billion equals 0.49% of supply, with the actual value extracted representing a small fraction of the project\u2019s market capitalization.
The bridge architecture that limited the damage Understanding why the attacker could not convert trillions of phantom tokens into billions of real dollars requires examining LayerZero\u2019s OFT adapter model and the structural constraints that turned a theoretically catastrophic exploit into a contained incident.
When a project like The Sandbox deploys across multiple chains using LayerZero\u2019s OFT framework, the original tokens remain on the home chain (in this case, Ethereum). The Ethereum-side OFT Adapter locks genuine SAND tokens when a user bridges them outbound. On the destination chain, the OFT contract mints an equivalent amount. When a user bridges back, the destination chain burns the tokens and the adapter releases the locked originals.
The critical constraint is that the Ethereum adapter only holds as many tokens as users have previously bridged. On the night of Aug. 21, the adapter held a limited amount of SAND. Once the attacker drained those reserves, no additional backed SAND existed to extract, regardless of how many unbacked tokens the attacker continued to mint on Base.
This design means the exploit\u2019s blast radius was structurally bounded by the adapter\u2019s balance, not by the attacker\u2019s minting capacity. The trillions of tokens on Base became what one analyst called \u201caccounting ghosts,\u201d visible on explorers but redeemable against nothing. An attacker\u2019s fabricated balance becomes someone else\u2019s loss only when it reaches a pool containing genuine SAND, ETH, stablecoins, or other assets with real liquidity. With most of the legitimate reserves already drained in the first minute, the remaining minted tokens had nowhere to go.
There is a secondary channel of damage worth noting. Any decentralized exchange liquidity pools on Base that held genuine SAND paired against ETH or stablecoins were also vulnerable. If the attacker swapped unbacked SAND into those pools before liquidity providers could withdraw, the LPs absorbed losses beyond the Ethereum adapter drain. The Sandbox\u2019s decision to take a pre-incident snapshot and compensate eligible LPs suggests this secondary damage was not trivial, even if the team has not disclosed exact figures.
The Sandbox\u2019s response reinforced the primary containment. By zeroing the trusted peers via multisig, the team severed the cross-chain messaging channel. SAND on Base and BNB Smart Chain became isolated, unable to bridge back to Ethereum. The team then advised users not to buy, sell, or trade SAND on either affected chain. The Ethereum-side maximum supply cap of 3 billion SAND remained intact, and the Polygon deployment was unaffected.
A pattern across three incidents in five months The Sandbox exploit did not occur in isolation. It was the third significant LayerZero-related bridge incident in five months, a pattern that has reshaped how the industry evaluates cross-chain infrastructure risk.
On April 18, 2026, attackers drained 116,500 rsETH worth approximately $292 million from a LayerZero-powered bridge operated by Kelp DAO. That attack was traced to a social engineering campaign that compromised a LayerZero Labs developer on March 6, giving the attacker access to the company\u2019s RPC cloud environment. The Kelp bridge used a 1-of-1 DVN (Decentralized Verifier Network) configuration, meaning a single compromised verifier could authorize fraudulent cross-chain messages.
In May, Stake DAO suffered a separate breach when a compromised deployer key reset a trusted peer setting, leading to 5.4 trillion vsdCRV minted for roughly $91,000 in extractable value.
The Sandbox incident followed a similar logic: application-level misconfiguration of cross-chain permissions created an opening for unauthorized minting. The mechanisms differed (approveAndCall versus social engineering versus key compromise), but the target was the same: the delegate or peer authority that controls who can trigger cross-chain token operations.
The $15 billion migration that followed The cumulative effect of three LayerZero-related incidents in five months triggered a structural shift in how protocols choose their cross-chain infrastructure. By August 2026, publicly announced migrations from LayerZero to Chainlink\u2019s Cross-Chain Interoperability Protocol totaled approximately $15 billion in secured value.
BitGo led the migration wave by moving $7.4 billion in WBTC. Mantle shifted its $2.5 billion Super Portal. Lombard transferred over $1 billion in bitcoin-backed assets. Solv Protocol moved $700 million in tokenized bitcoin reserves. Kraken replaced LayerZero with Chainlink CCIP for its kBTC wrapped asset. On Aug. 18, just days before the Sandbox exploit, the Wyoming Stable Token Commission migrated its Frontier Stable Token to Chainlink CCIP across eight chains following a state-level security review.
LayerZero Labs acknowledged the earlier Kelp incident, with the company publicly stating it \u201cmade a mistake\u201d in the DVN configuration that Kelp used. The Sandbox exploit adds a new vector to the conversation: even when the underlying messaging protocol functions as designed, application-level integrations can create exploitable seams.
Chainlink\u2019s CCIP uses a different verification model that relies on a decentralized oracle network and a separate risk management network that independently validates every cross-chain transaction. The risk management network operates as an independent watchdog: even if the primary oracle network is compromised, the secondary layer can halt suspicious messages before they execute. This two-layer approach directly addresses the single-point-of-failure problem that enabled the Kelp DAO exploit, where a 1-of-1 DVN configuration meant one compromised verifier was sufficient to authorize fraud.
Whether that architecture proves more resilient over time remains an open question. Chainlink\u2019s model introduces its own trust assumptions, and no cross-chain system has proven immune to sophisticated attacks over a multi-year period. But the market has voted with its capital: $15 billion in migration announcements represents a level of institutional confidence shift that is difficult to reverse. When a state government (Wyoming) and major custodians (BitGo, Kraken) independently reach the same conclusion about infrastructure risk, the signal carries weight beyond any single incident.
What the market priced in The market response to the Sandbox exploit contradicted what a casual observer might expect. Despite the $49 billion headline, SAND traded up 4.76% to $0.0476 in the 24 hours following the incident, with trading volume surging more than 400%.
Several factors may explain the counterintuitive price action. First, the rapid containment and transparent communication from The Sandbox team reassured holders that the Ethereum-side supply was intact. Second, Korean exchanges halting deposits and withdrawals under South Korea\u2019s Virtual Asset User Protection Act signaled regulatory seriousness about protecting traders. Third, some market participants may have interpreted the small actual extraction as evidence that the OFT adapter model worked as a structural safety net, even if the application-level permissions failed.
JUST IN: Coldcard wallets affected by security issue with reported losses
Roughly 594 $BTC valued at $38 million has been stolen from certain dormant single sig wallets pic.twitter.com/f3fk7kYXzM
— crypto.news (@cryptodotnews) August 1, 2026 Coinbase delisted SAND perpetual futures, a precautionary move that reduced leverage exposure. The Sandbox announced it would take a pre-incident snapshot and compensate eligible liquidity providers on Base and BNB Smart Chain, though the timeline and mechanism for compensation were not immediately disclosed.
The price resilience should not be mistaken for absolution. The exploit exposed a configuration vulnerability that existed for at least 313 days, the dormancy period of the attacker\u2019s wallet, which was pre-positioned on Oct. 13, 2025. That one of the most recognizable names in Web3 gaming carried this exposure without detection raises questions about audit coverage for cross-chain deployments. The wallet\u2019s extended dormancy also suggests the attacker either discovered the vulnerability months before acting or acquired the wallet from someone who did.
DefiLlama logged 17 separate exploits in August 2026 alone, with bridges again emerging as the recurring weak point. Q2 2026 was described as \u201cthe most hacked quarter in DeFi history,\u201d with 99 exploits draining $746 million. Cumulative DeFi losses for the year exceeded $840 million by the end of May, and the Sandbox incident pushes the running total higher still. The question facing the industry is no longer whether bridges can be secured, but whether the current generation of bridge architectures should be trusted with significant capital at all.
What to watch Post-mortem publication: The Sandbox promised a full post-mortem. Its depth, particularly around how the approveAndCall pathway was missed in prior audits, will signal how seriously the project treats the configuration gap.
Liquidity provider compensation: The snapshot-based compensation plan needs a timeline and token source. Watch whether affected LPs receive full restitution or a haircut.
LayerZero protocol-level mitigations: Whether LayerZero introduces guardrails to prevent delegate hijacking through token contract callbacks will indicate if the protocol views this as a systemic risk or a one-off configuration error.
Further migration announcements: If additional projects accelerate departures from LayerZero following this third incident, the migration wave could reshape the cross-chain infrastructure market before year-end.
Regulatory response in South Korea: Upbit and Bithumb acted under the Virtual Asset User Protection Act. Whether Korean regulators pursue further action against The Sandbox or LayerZero could set precedent for how bridge exploits are treated under consumer protection frameworks.
What is the approveAndCall function? The approveAndCall function is an ERC-20 extension that lets a user approve a token spender and execute a follow-on contract call in a single transaction. It was designed to save gas and simplify multi-step interactions. In the Sandbox exploit, the attacker used this function to route a crafted payload through the SAND token contract into the LayerZero endpoint, effectively borrowing the token contract’s delegate authority over endpoint configuration.
How much money did the attacker actually steal? The attacker extracted approximately 14.75 million SAND from the Ethereum OFT Adapter, converting the tokens to roughly 79.74 ETH, worth approximately $675,000 at the time of the transactions. While the face value of minted tokens reached $49 billion, that figure is an arithmetic artifact that could never have been realized as actual value.
Were SAND tokens on Ethereum and Polygon affected? No. The exploit targeted the SAND OFT contract on Base and BNB Smart Chain. The Ethereum-side adapter contract and the Polygon deployment were not compromised. The maximum supply cap of 3 billion SAND on Ethereum remains intact.
Why did the attacker mint trillions of tokens if they could only extract $675,000? The minting was automated across 703 events and 173 wallets over five hours. The attacker likely aimed to drain as much backed value as possible from the Ethereum adapter, but the adapter balance was limited. The excess minting beyond what the adapter held produced unbacked tokens with no redemption path.
Is this a flaw in LayerZero’s protocol? Security researchers described the vulnerability as an application-level configuration failure, not a flaw in the LayerZero protocol itself. The issue was specific to how The Sandbox’s OFT contract on Base handled approveAndCall interactions with the LayerZero endpoint. However, the fact that three LayerZero-integrated bridges have been exploited in five months has intensified scrutiny of the protocol’s overall security model.
What did Korean exchanges do in response? Upbit and Bithumb halted SAND deposits and withdrawals, citing suspected security incidents under South Korea’s Virtual Asset User Protection Act. Coinbase separately delisted SAND perpetual futures contracts.
Will affected liquidity providers be compensated? The Sandbox announced plans to compensate eligible liquidity providers based on a pre-incident snapshot of balances on Base and BNB Smart Chain. The payment schedule and token source had not been disclosed as of Aug. 23, 2026.
How does this compare to other bridge exploits? By nominal value, the $49 billion face-value figure would make this the largest bridge exploit in crypto history. By actual extraction, the $675,000 loss ranks among the smallest. The key difference is that earlier exploits like Ronin ($625 million) and Wormhole ($326 million) had sufficient bridge liquidity for attackers to drain backed assets at scale, while the Sandbox adapter held only a fraction of the total SAND supply, structurally limiting losses.
Disclaimer: This article is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency investments carry significant risk. Always conduct your own research before making any financial decisions. Published Aug. 23, 2026.
Upbit has placed The Sandbox (SAND) on its trading alert list, and deposit and withdrawal services for the token are currently suspended. On August 22, The Sandbox confirmed a cross-chain bridge vulnerability affecting the Base and BSC networks, with the project’s official team suspending cross-chain functions.
Relevant content
Alibaba’s share placement secures nearly 3x oversubscription, with sovereign and long-term funds accounting for over 40% of final subscriptions.
According to a report by Shanghai Securities News, Alibaba has finalized the pricing of its new share placement worth HK$80 billion (approximately US$10.2 billion). All net proceeds from the placement will be allocated to investments in full-stack AI capabilities and the enhancement of AI infrastructure. A source close to the transaction revealed that the offering was nearly three times oversubscribed, attracting over HK$200 billion in subscriptions. Sovereign wealth funds and long-term investors ultimately accounted for more than 40% of total subscriptions, indicating strong demand and high order quality. Alibaba’s clear return path for its AI investment has earned the trust of global long-term capital, with major sovereign funds from regions including the Middle East, Europe, and Asia actively participating in the subscription.
7 minutes ago
Japanese and South Korean stock markets closed lower, with South Korean stocks falling more than 3%.
According to Bitget market data, South Korea’s KOSPI index closed down 215.99 points, or 3.12%, at 6696.96 points on Monday, August 24. Japan’s Nikkei 225 index fell 488.27 points, a 0.74% decline, to 65528.09 points in the same session.
7 minutes ago
Alibaba’s massive share offering drags down Hong Kong’s stock market; Michael Burry says he will not consider buying again unless the share price is cut in half.
Alibaba announced Sunday that it plans to conduct a new share placement in Hong Kong. The company said the total size of the offering is HK$80 billion (US$10.2 billion), which will be the largest primary follow-on offering in the history of Hong Kong-listed firms. Following the news, Alibaba’s Hong Kong-listed shares opened lower and trended downward today, with the intraday maximum drop exceeding 10% and the current decline narrowing to 9% per Bitget market data. The Hang Seng Index was dragged down by the stock, falling 1.9% on the day, while the Hang Seng Tech Index dropped 3.58%. Separately, "Big Short" investor Michael Burry updated his views on Alibaba on X, revealing he had switched his Alibaba position to JD.com a few months ago. "Issuing stocks is now Alibaba's new normal. I won't consider it again unless the stock falls by half from here."
7 minutes ago
The total number of accounts on #TRON has officially surpassed 400,000,000!
The total number of accounts on #TRON has officially surpassed 400,000,000!
7 minutes ago
Preview: US Treasury Secretary Scott Bessent will unveil details on Iran sanctions at 2:00 tomorrow, which may trigger market volatility.
According to reports from authoritative outlets including Reuters, U.S. Treasury Secretary Scott Bessent will unveil details of new sanctions on Iran at 2 p.m. Eastern Time, equivalent to 2 a.m. Beijing time tomorrow. The crypto market has been rallying for several consecutive days ahead of these Iran sanctions, so if the details exceed market expectations, significant volatility is likely to hit both the stock market and crypto assets. Earlier, Bessent wrote in the Financial Times that the U.S. is entering a decisive phase, with an economic "D-Day" for Iran approaching at dawn—what he termed the largest financial offensive ever launched against an adversary. When elaborating on the related sanctions measures, Bessent specifically added that "no further 'large-scale' military operations are expected."
7 minutes ago
Bitcoin ETFs recorded inflows of $1.92 billion last week, marking the largest such inflow in nearly 10 months.
As Bitcoin prices surged, spot Bitcoin ETFs posted their strongest weekly net inflow in 10 months last week. Data indicates the 13 U.S.-listed funds attracted a net $1.92 billion, the highest such figure since October last year. The inflow came amid Bitcoin’s roughly 23% price jump last week, marking its largest weekly gain in over three years.
The first sign of trouble in a token exploit is often not the exploit itself, but the freeze that follows. The Sandbox moved quickly on August 22 to disable bridging on Base and BNB Chain, isolating SAND tokens after an exploit across those networks. The team also warned users not to trade SAND on Base and BNB, according to the original report. The immediate impact is small in supply terms, under 0.01% of SAND, but the operational response is larger than that number suggests.
Bridging creates multiple representations of the same asset, and each representation depends on the security of a separate bridge contract. If one side is compromised, the safest move is to stop movement while the project determines whether the affected tokens can be isolated or returned. For a gaming token that touches purchases, rewards and staking, even a marginal leak can distort price discovery and create a distressed market on the affected chains.
Containing the token leak The warning against trading SAND on Base and BNB Chain is not just an internal control. It is an attempt to prevent a secondary market from forming around compromised or potentially non-fungible tokens. Once a bridge is paused, a token can trade at different prices on different chains because arbitrage becomes difficult or impossible. Retail liquidity tends to thin out, while bots and speculative buyers may still pick up tokens in unofficial pools without understanding the risk.
The choice of networks complicates containment. BNB Chain remains one of the busiest ecosystems by developer activity, as shown in recent on-chain development data, and Base has become a default venue for lower-cost token experiments. The Sandbox now has to manage a situation where its branded asset is impaired on two chains with meaningful retail reach. Ethereum-based SAND will likely become the main reference point for price until the bridges are restored.
Why bridge risk keeps returning Bridges are among the most fragile components of multi-chain crypto. Even when a core protocol is sound, a bridge can fail through a contract flaw, a custody key compromise, or a mismatch in how two networks settle state. The Sandbox has not specified the exact attack vector, which leaves the public with a common but uncomfortable picture: a recognizable gaming brand, a token that exists on multiple chains, and infrastructure that had to be switched off after something moved that should not have.
For Web3 gaming, the incident lands at a difficult point. The sector depends on cross-chain utility but still relies on bridge infrastructure that has repeatedly shown weak spots. Sandbox operates in the same NFT and digital asset economy that regularly produces high-volume trading, a segment visible in weekly NFT sales performance. A small supply hit may be absorbable, but repeated bridge failures would make users less willing to hold assets across chains.
What the market still doesn’t know The disclosure does not include a timeline for reopening the Base and BNB Chain bridges, a technical post-mortem, or any statement on whether affected users will be compensated. The under 0.01% supply figure is small, but it does not confirm that the exploit is fully contained. The team may still be monitoring related contract addresses and deciding whether to reissue or burn tokens on the affected networks.
Until more detail emerges, the practical effect is that SAND markets on Base and BNB Chain should be viewed as impaired. The team’s decision to halt bridging was a reasonable containment step, but the real test is what happens when those bridges come back online. If the exploit was limited and the affected supply is small, the event could fade quickly. If the bridge contracts themselves require deeper fixes, cross-chain SAND liquidity could stay fragmented for longer than traders expect.
AUTHOR
Mysterious crypto writer with expertise in blockchain, offering deep insights that captivate and intrigue readers. With a unique ability to uncover hidden insights and trends, Samuel delivers in-depth analysis and thought-provoking content that keeps readers on the edge of their seats. His writing style is engaging and informative, blending technical knowledge with a sense of intrigue, making complex crypto topics accessible to both newcomers and seasoned industry professionals. Samuel’s work continues to capture the attention of the crypto community, solidifying his reputation as a trusted voice in the space.
South Korea’s two largest crypto exchanges moved first. On August 22, 2026, Upbit issued a trading caution, and Bithumb suspended SAND deposits and withdrawals after on-chain alerts flagged a suspected exploit.
The said exploit happened on The Sandbox’s Base network deployment. Minutes later, blockchain security firm PeckShield confirmed the scale of the breach.
According to data made public, approximately 14.9 billion SAND tokens were minted across two addresses. The figure dwarfed the token’s entire 3-billion supply on Ethereum mainnet.
From 500 Million to 14.9 Billion: How the SAND Exploit Unfolded on Base The first alerts showed more than 500 million SAND minted on Base. That number kept climbing.
An attacker had gained arbitrary token-minting permissions on the SAND contract deployed on Base, a LayerZero Omnichain Fungible Token (OFT) configuration that allows cross-chain token movement.
On Ethereum, the same contract address functions as an OFT Adapter, holding the real, locked L1 SAND that backs cross-chain deployments.
Blockchain forensics account BlockWatchdog later provided a detailed breakdown: the attacker drained approximately 14.75 million SAND from the Ethereum adapter in under a minute.
🔴 THE SANDBOX / SAND
PeckShield reported 14.9B SAND minted on Base. On-chain it is 329.24 trillion — 22,000x more.
But the mint was never the theft. Ethereum's adapter went from 14,769,723 SAND to 0.0056.
SAND on Base is a LayerZero OFT. The same address on Ethereum is the…
— BlockWatchdog (@BlockWatchdog) August 22, 2026
Realized proceeds from token sales came to roughly 80 ETH, or about $675,000.
The gap between the headline figure and the actual loss reflects the structure of the attack. Minting tokens on Base does not create new Ethereum-native SAND.
Still, the sheer volume of unbacked tokens flooding Base created immediate market risk. PeckShieldAlert confirmed the 14.9B figure via X.
#PeckShieldAlert Seems like The @TheSandboxGame ($SAND) got exploited. 14.9B $SAND minted across 2 addresses: 0xAbE0…4D22 & 0x638C…F296 pic.twitter.com/a5Jgym87gR
— PeckShieldAlert (@PeckShieldAlert) August 22, 2026
The Sandbox is a Animoca Brands subsidiary that raised $93 million in a 2021 funding round. The project has not yet issued a public statement on the root cause.
The project’s multisig subsequently zeroed the LayerZero peers for Ethereum and BSC, effectively isolating Base.
Ethereum mainnet supply remained capped at 3 billion SAND and was not inflated.
This kind of cross-chain token risk mirrors what recently hit another on-chain project, MANTRA’s RWA Chain Halts Network amid Attack Attempt, where a network halt and sharp price reaction followed a suspected security incident.
South Korea’s sharp response here also reflects the regulatory momentum building across Asia, including BitGo Korea Winning the First Foreign VASP License in South Korea.
What SAND Investors and Traders Should Watch Next Investors face two separate risks. First is secondary-market pressure: even unbacked minted tokens can reach exchanges and depress price.
Second is dilution uncertainty until The Sandbox officially confirms whether a burn or recovery plan is in place.
Upbit’s caution and Bithumb’s suspension remain active. Traders should monitor both exchanges for any update on trading resumption.
The Sandbox team’s official account, @TheSandboxGame, had not issued a statement at the time of writing.
This incident adds to a growing body of evidence that cross-chain token deployments carry structural risks.
Franklin Templeton’s SEC Clearance for Funds to Hold Tokenized Assets signals that institutional appetite for on-chain assets is rising.
Yet incidents like this remind the market that bridge and OFT infrastructure security must match that ambition.
Meanwhile, broader crypto markets have shown resilience. Bitcoin Hit $78K, Flipping Meta to Rank 13th Largest Global Asset, underscoring that token-specific shocks do not always translate into sector-wide selloffs.
Stay updated with our crypto ICOs calendar featuring the most popular initial coin offerings.
The Sandbox has contained a cross-chain bridge vulnerability that allowed an attacker to mint unbacked SAND on Base and BNB Smart Chain, with the project estimating the direct impact at less than 0.01% of the token’s 3 billion supply.
Summary
The attacker minted unbacked SAND on Base and BNB Smart Chain through compromised bridge permissions. The Sandbox disabled transfers involving both networks while keeping Ethereum and Polygon SAND unaffected. Upbit and Bithumb halted SAND deposits and withdrawals after detecting a possible security incident. On-chain researchers estimated that about 14.75 million Ethereum-backed SAND left the bridge adapter. The Sandbox plans to compensate eligible liquidity providers based on balances recorded before the attack. The Sandbox said it had fully contained the vulnerability affecting its SAND bridge on Base and BNB Smart Chain, adding that no user wallets were compromised and SAND held on Ethereum and Polygon remained secure.
The Sandbox team has identified and fully contained a recent vulnerability regarding the SAND cross-chain bridge on Base and BNB Smart Chain (BSC). The impact is minimal, representing less than 0.01% of the total SAND token supply.
SAND tokens on Ethereum and Polygon are NOT…
— The Sandbox (@TheSandboxGame) August 22, 2026 In an August 22 statement, the metaverse project said the attacker created tokens on Base and BNB Smart Chain without the SAND needed to back them on Ethereum. The team disabled bridging to and from both networks, isolating the affected tokens and preventing them from being redeemed through the official bridge.
“All bridged SAND funds are backed by SAND locked on Ethereum, which remains entirely secure,” the project said.
Users were told not to buy, sell, or provide liquidity for SAND on Base or BNB Smart Chain while the affected deployments remain isolated. The team is also taking a snapshot from before the attack and said eligible liquidity providers would receive compensation, although it did not give a payment schedule.
How the SAND bridge exploit created unbacked tokens Early on-chain alerts showed more than 500 million SAND minted on Base, but the reported figure climbed rapidly as the attacker continued interacting with the contract.
PeckShield later identified about 14.9 billion SAND created across two addresses. Other security researchers recorded hundreds of additional transactions, producing much larger estimates for the total number of unbacked tokens generated before the bridge was disabled.
The size of the minted amount did not represent the project’s direct financial loss. SAND created on Base or BNB Smart Chain could not increase the Ethereum token’s fixed maximum supply of 3 billion unless the attacker could use the cross-chain system to release genuine tokens locked in the Ethereum adapter.
According to blockchain forensics account BlockWatchdog, the attacker withdrew approximately 14.75 million SAND from the Ethereum adapter in less than one minute. Token sales generated about 80 ETH, valued at roughly $675,000 at the time of the transactions.
The figure helps explain why The Sandbox placed the impact below 0.01% of the total SAND supply even though the number of tokens minted on the affected networks appeared far larger. The project has not yet published a full technical report reconciling its loss estimate with the figures reported by individual on-chain researchers.
Blockaid attributed the incident to the takeover of LayerZero delegate permissions through a approveAndCall function. The security firm said the access allowed the attacker to mint tokens through the affected cross-chain contracts, though The Sandbox has not confirmed Blockaid’s proposed cause in a detailed postmortem.
Why Ethereum SAND supply has remained unchanged LayerZero’s Omnichain Fungible Token standard uses linked contracts to move assets between blockchains. Under its adapter model, an existing token is locked on its original network while an equivalent amount is minted at the destination.
For SAND, the Ethereum adapter holds the original tokens intended to support cross-chain balances. A legitimate transfer to Base should lock SAND on Ethereum before creating the corresponding amount on Base, preserving one supply across the connected networks.
Unauthorized minting broke the backing relationship on the affected chains, but it did not rewrite the Ethereum token contract or raise its maximum supply. CoinGecko continued to show a maximum supply of 3 billion SAND, with about 2.9 billion tokens in circulation.
To stop the affected contracts from communicating with other deployments, The Sandbox removed the LayerZero peer settings for Base and BNB Smart Chain. The action cut off the official route through which unbacked tokens might otherwise have been used to claim assets held by the Ethereum adapter.
A similar difference between a bridge failure and a problem with the underlying blockchain appeared during July’s Wanchain bridge exploit. About 515 million NIGHT left Wanchain’s Cardano-side treasury, while the Midnight Foundation said its core network, validators and consensus system remained unaffected.
In another July incident, an attacker used the Verus bridge’s import path to trigger unbacked asset payouts worth about $7.54 million. Blockaid linked the attack to the same bridge contract and apparent bug class involved in an earlier May breach.
Korean exchanges restrict SAND transfers Upbit issued a caution notice after finding signs of a possible security problem involving SAND, warning that the incident could produce sharp price movements. Bithumb separately suspended SAND deposits and withdrawals while it reviewed the issue.
Reports citing the exchange notices placed Bithumb’s suspension at 11:11 a.m. Korea Standard Time on August 22, followed by Upbit about one minute later. Trading restrictions and transfer suspensions can differ, so users must check each exchange’s notice before placing an order or attempting to move SAND.
The quick response is consistent with South Korean exchange procedures for assets facing suspected network faults, abnormal token issuance, or security incidents. Deposit restrictions can limit the chance that tokens created through a compromised network reach an exchange and are sold against unaffected balances.
SAND traded near $0.05 after the disclosure, while CoinGecko reported more than $66 million in 24-hour volume. The data provider placed the token’s market capitalization near $136 million and showed an increase of about 18% over seven days, though prices varied across trading venues.
Base users face isolated liquidity risk For U.S. users, the immediate connection comes through Base, the Ethereum layer-2 network developed by U.S.-listed exchange Coinbase. The reported vulnerability affected The Sandbox’s cross-chain contracts deployed on Base rather than Base’s underlying network, according to the available project and security disclosures.
The Sandbox’s warning applies to anyone holding or trading the isolated Base version of SAND, including U.S. users accessing decentralized exchanges through self-custody wallets. Tokens available in Base liquidity pools may not carry the same backing as Ethereum-native SAND while the official bridge remains disabled.
The incident follows an April attack involving another LayerZero-powered asset. As crypto.news reported, LayerZero’s KelpDAO incident report said attackers stole about 116,500 rsETH worth $292 million after compromising infrastructure used by a single-verifier cross-chain configuration.
Following the KelpDAO attack, LayerZero said its verification network would stop signing messages for applications using a one-of-one verifier setup and encourage projects to adopt multiple independent verifiers. The Sandbox has not said whether its SAND configuration used the same model or whether the latest vulnerability involved LayerZero’s verification network.
The Sandbox, an Animoca Brands subsidiary that raised $93 million in 2021, said it would publish further information as its investigation proceeds. Its latest notice did not provide a date for restoring Base and BNB Smart Chain transfers or specify when compensation claims for eligible liquidity providers would open.
Upbit and Bithumb froze SAND transfers under South Korea's user-protection law, with Upbit halting deposits and withdrawals on Ethereum — the chain the studio says was not affected.
The Sandbox said it has "identified and fully contained" a vulnerability in the SAND cross-chain bridge that let an attacker mint unbacked SAND on Base and BNB Smart Chain, and that it has switched off bridging to and from both networks, leaving the SAND on those chains isolated and unable to be moved or redeemed.
In a statement posted at 3:22 a.m. ET Saturday, the studio behind the virtual-world game told users not to buy, sell or trade SAND on Base or BSC because liquidity on those networks is compromised. It said no user wallets were compromised, that SAND on Ethereum and Polygon is unaffected, and that the SAND locked on Ethereum backing all bridged SAND is fully intact. It put the impact at "less than 0.01% of total SAND supply."
Security firm Blockaid described the mechanism hours earlier. Attackers hijacked LayerZero delegate permissions through a function called `approveAndCall` on SAND's omnichain fungible token contract on Base, the firm said. An omnichain fungible token, or OFT, is the cross-chain version of a token, and its delegate role governs who is authorized to mint new units on a given chain. Blockaid put the face value minted at about $49 billion across more than 400 transactions as of 12:14 a.m. ET, and said the attack was still going.
PeckShield, in an alert published at 1:40 a.m. ET, counted 14.9 billion SAND minted across two addresses, 0xAbE0...4D22 and 0x638C...F296. Block-explorer screenshots attached to the alert show the addresses holding 14.65 billion and 250 million SAND, credited in repeated transfers from the null address — the zero address newly created tokens are issued from — dated Aug. 22.
Those counts and the company's are hard to square. PeckShield's 14.9 billion tokens is several times SAND's entire circulating supply of about 2.94 billion, against a 3 billion maximum, according to CoinGecko. The Sandbox has not said what its "less than 0.01%" figure measures or published a loss figure in dollars. Blockaid's and PeckShield's totals were published an hour and a half apart while minting was described as ongoing, and neither firm has reconciled its number with the other's.
Two South Korean exchanges had already frozen SAND transfers. Upbit suspended SAND deposits and withdrawals on the Ethereum network in a notice registered at 10:12 p.m. ET Friday, or 11:12 a.m. KST Saturday, citing circumstances indicating a security incident at The Sandbox and invoking a user-protection provision of South Korea's Virtual Asset User Protection Act. The suspension runs until the exchange confirms deposit and withdrawal stability, it said, adding that it will work closely with the project team. Ethereum is the chain The Sandbox says was not affected.
Upbit followed with a trading caution at 10:45 p.m. ET, saying circumstances suspected to be a security problem on The Sandbox network were confirmed on Aug. 22 and warning that SAND's price volatility could widen. The notice pointed users to token transactions of the Base address 0x67624BFadee937c9281B4f98Ce18aF1bee01257e on BaseScan as the transactions related to the suspected problem.
Bithumb suspended SAND deposits and withdrawals from 11:11 a.m. KST Saturday, or 10:11 p.m. ET Friday, citing suspected security-problem circumstances and the same law, and said service would resume once network stability is confirmed. Trading remains available during the suspension, the exchange said, warning that sharp price swings may occur. The notice was read from a screenshot of Bithumb's notice page circulated by Wu Blockchain rather than from the exchange's own site.
Markets have priced none of it in. SAND changed hands at $0.0479 as of 4:12 a.m. ET Saturday, up about 4.6% over 24 hours and about 22% over seven days, for a market capitalization of roughly $140.8 million, according to CoinGecko.
The Sandbox said it is taking a snapshot of positions from before the incident and preparing a compensation plan for qualified users of the affected liquidity pools, and promised a full incident report and technical post-mortem. Neither Upbit nor Bithumb has said when transfers will reopen.
The Sandbox said it has contained a vulnerability in the SAND cross-chain bridge on Base and BNB Smart Chain after an attacker minted unbacked tokens on both networks.
The project put the impact at under 0.01% of the total SAND supply. It said that tokens on Ethereum (ETH) and Polygon (POL) are unaffected and that no user wallets were compromised.
Sandbox Becomes Latest Project Reportedly Hit by an ExploitBlockaid flagged the incident on Saturday. The firm said attackers hijacked LayerZero delegate permissions through the approveAndCall function.
“~$49B face-value SAND minted so far across ~400+ txs,” Blockaid said.
Follow us on X to get the latest news as it happens
The team said that it has disabled bridging to and from Base and BSC, cutting off any route to move or redeem the minted supply. It said the SAND locked on Ethereum, which backs all bridged tokens, remains intact.
“An attacker was able to mint unbacked SAND on Base and BSC. We have disabled bridging to and from both networks, so SAND on Base and BSC is currently isolated and cannot be moved or redeemed,” the post read.
The project told holders not to buy, sell, or trade SAND on either network, warning that liquidity there is compromised. It is taking a pre-incident snapshot and preparing compensation for qualifying liquidity providers, with a full post-mortem promised.
Korean Exchanges Halt SAND Transfers Meanwhile, Bithumb suspended SAND deposits and withdrawals at 11:11 a.m. KST, and Upbit followed one minute later. Both cited suspected security incidents under South Korea’s Virtual Asset User Protection Act.
Upbit imposed a halt on the Ethereum version of SAND, which the project has since said was never at risk.
The incident fits a wider pattern. DefiLlama has logged 17 separate exploits so far this month, most of them small, with bridges again the recurring weak point.
Subscribe to our YouTube channel to watch leaders and journalists provide expert insights
US Treasury repurchase operations unexpectedly pushed Bitcoin’s price up 25%, triggering $4 billion in short-position liquidations.
After the U.S. Treasury expanded its long-term U.S. Treasury bond repurchase operations, the 30-year U.S. Treasury yield fell from a 19-year high of 5.34% to around 5.19%, while Bitcoin rose roughly 25% in several days, briefly topping $79,000. Around $4 billion in cryptocurrency short positions were liquidated during this period, further amplifying the rally. The U.S. Treasury had earlier announced it would raise the size of its longest-dated Treasury repurchase operations from $2 billion per operation to $4 billion. Analysts noted that this operation is not equivalent to the Federal Reserve’s quantitative easing (QE); its main function is to improve the liquidity of older bonds and optimize the debt structure, but the market views it as a policy support signal for long-term U.S. Treasury yields. Analysts believe the key driver of Bitcoin’s recent rally is not the repurchase operation itself, but the market’s prior over-concentration of short positions. As long-term U.S. Treasury yields fell, short sellers were forced to cover their positions, triggering a powerful short squeeze. Meanwhile, U.S. spot Bitcoin ETFs saw a net inflow of around $650 million this week, and Trump once again urged Congress to advance the CLARITY Act, further boosting market risk appetite. Jeff Ko, chief analyst at CoinEx, said the key now is whether Bitcoin can hold its 200-day moving average around $69,000 and turn it from resistance into support. Market participants also warned that if the 10-year U.S. Treasury yield re-breaks above 4.7% and the 30-year yield approaches 5.3%, Bitcoin’s current breakout could face renewed tests. Bitcoin has now broken above its 200-day moving average and continues to rise; the next phase of the market will focus on whether it can sustain its rally in a high-yield environment.
6 minutes ago
Strategy's Bitcoin holdings have generated an unrealized profit of $1.7187 billion.
Strategy currently holds 840,447 Bitcoin, with a total cost of $63.36 billion and an average entry price of $75,385. At Bitcoin’s current price of $77,430, the company’s Bitcoin holdings now have an unrealized profit of $1.7187 billion.
6 minutes ago
The Sandbox confirms SAND cross-chain bridge vulnerability; Base and BSC networks affected, cross-chain functionality suspended.
The Sandbox officials announced that the team has confirmed and fully contained the recent SAND cross-chain bridge vulnerability incident, which involved the Base and BNB Smart Chain (BSC) networks. The incident’s impact is limited, with the number of tokens involved accounting for less than 0.01% of SAND’s total supply. SAND on Ethereum and Polygon remains unaffected; user wallets were not compromised, and no action is required for affected token holders or liquidity providers. Attackers minted unbacked SAND tokens on Base and BSC networks via the vulnerability, per disclosures. Currently, The Sandbox has shut down SAND cross-chain functionality on both networks. SAND on Base and BSC has been isolated and is temporarily non-transferable or non-exchangeable. The Sandbox reminds users not to buy, sell, or trade SAND on Base and BSC, as liquidity on these networks has been impacted. The team has completed a pre-incident snapshot, is developing a compensation plan for affected liquidity pool (LP) users, and continues to investigate the full scope of the vulnerability. A full incident report and technical post-mortem will be released later.
6 minutes ago
A crypto whale opened a 4x long position worth $10.7 million on HYPE, with a liquidation price of $64.47.
According to monitoring by TradingBeats (formerly Hyperinsight), a crypto whale recently deposited approximately $4 million in USDC into Hyperliquid and opened a long position on HYPE. The wallet address established a 134,930 HYPE long position with 4x leverage, valued at around $10.7 million. Its entry price was $81.64, liquidation price stands at $64.47, and the current unrealized loss amounts to $315,000. The whale’s address is 0xa9d1c0fe2aa58038bac208ad390f69e7ce0c29a2.
6 minutes ago
Tesla has set the date for the press conference of its self-driving electric Cybercab.
Tesla has announced on social platforms that it will hold the Cybercab launch event on September 3, 2026, in Austin, Texas, United States. The automaker’s self-driving electric Cybercab officially entered production in North America this April, and the vehicle is AI-powered, with no steering wheel, pedals, or rearview mirrors.
6 minutes ago
Tencent's chip division head Gao Jianlin has resigned to found a startup, targeting the high-performance AI CPU track in the RISC-V space.
According to MaxForAI's disclosure, Gao Jianlin, a core lead in Tencent's chip research and development, recently left the tech giant to launch a startup focused on high-performance AI servers and Agentic AI, with plans to develop high-performance CPUs based on the RISC-V architecture. Gao is widely regarded as one of the early core drivers of Tencent's in-house chip ecosystem. Public records show he formed Tencent's FPGA hardware team in 2013, began laying the groundwork for AI chip R&D in 2018, established Penglai Lab in 2020, and spearheaded the development and data center deployment of multiple AI chips for Tencent. Unlike the currently fiercely competitive AI GPU market, Gao's new venture will center on CPUs. Gao believes that as Agentic AI advances rapidly, AI inference processes will involve model calls, tool execution, searches, database interactions, and extensive task scheduling, making CPUs take on a more critical scheduling and control role in AI systems. Reportedly, Gao was already involved in RISC-V-related R&D during his tenure at Tencent, contributing to multiple technical areas including chip architecture, verification, and backend development. His new company plans to build high-performance server CPUs based on the open RISC-V instruction set to enter the AI infrastructure market. To date, the startup's name, financing details, and specific product launch timeline have not been made public. The market is closely watching whether it will emerge as another key player in China's AI chip space targeting server CPUs and agent infrastructure.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
An exploit targeting The Sandbox’s SAND OFT on Base has allowed attackers to hijack LayerZero delegate permissions and mint massive amounts of unauthorized SAND tokens out of thin air, blockchain security firm Blockaid reported Saturday.
According to Blockaid, attackers exploited approveAndCall to take control of LayerZero delegate permissions, enabling them to mint SAND without legitimate backing.
🚨 Blockaid detected an ongoing exploit on @TheSandboxGame SAND OFT on Base.
Attackers hijacked LayerZero delegate permissions via approveAndCall and minted unbacked SAND.
~$49B face-value SAND minted so far across ~400+ txs. Attack still ongoing.
More details in 🧵
— Blockaid (@blockaid_) August 22, 2026
Blockaid said that roughly $49 billion in face-value SAND had been minted through more than 400 transactions.
Advertisement
The attack was still underway at the time of the alert, leaving open the possibility that the amount of unauthorized SAND could continue to increase.
The Sandbox confirmed the exploit after on-chain analysts flagged suspicious activity. In a statement, the project stated that its SAND cross-chain bridge on BSC was also affected.
According to the team, the vulnerability has now been contained, and bridging between both Base and BSC has been halted to isolate the affected tokens and prevent further transfers or redemptions. The Sandbox has advised users to avoid trading SAND on Base and BSC.
The project said the incident affected less than 0.01% of SAND’s total supply, while SAND deployed on Ethereum and Polygon was unaffected. It also said that there was no compromise of user wallets and that the Ethereum reserves backing bridged SAND remain intact.
The team is now working on a snapshot of the affected pools and a compensation plan for eligible liquidity providers, and plans to release a full incident report and technical post-mortem after completing its investigation.
The incident sent SAND to $0.052 before a sell-off drove it down to $0.044. The token has since rebounded to around $0.048.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
US Treasury repurchase operations unexpectedly pushed Bitcoin’s price up 25%, triggering $4 billion in short-position liquidations.
After the U.S. Treasury expanded its long-term U.S. Treasury bond repurchase operations, the 30-year U.S. Treasury yield fell from a 19-year high of 5.34% to around 5.19%, while Bitcoin rose roughly 25% in several days, briefly topping $79,000. Around $4 billion in cryptocurrency short positions were liquidated during this period, further amplifying the rally. The U.S. Treasury had earlier announced it would raise the size of its longest-dated Treasury repurchase operations from $2 billion per operation to $4 billion. Analysts noted that this operation is not equivalent to the Federal Reserve’s quantitative easing (QE); its main function is to improve the liquidity of older bonds and optimize the debt structure, but the market views it as a policy support signal for long-term U.S. Treasury yields. Analysts believe the key driver of Bitcoin’s recent rally is not the repurchase operation itself, but the market’s prior over-concentration of short positions. As long-term U.S. Treasury yields fell, short sellers were forced to cover their positions, triggering a powerful short squeeze. Meanwhile, U.S. spot Bitcoin ETFs saw a net inflow of around $650 million this week, and Trump once again urged Congress to advance the CLARITY Act, further boosting market risk appetite. Jeff Ko, chief analyst at CoinEx, said the key now is whether Bitcoin can hold its 200-day moving average around $69,000 and turn it from resistance into support. Market participants also warned that if the 10-year U.S. Treasury yield re-breaks above 4.7% and the 30-year yield approaches 5.3%, Bitcoin’s current breakout could face renewed tests. Bitcoin has now broken above its 200-day moving average and continues to rise; the next phase of the market will focus on whether it can sustain its rally in a high-yield environment.
6 minutes ago
Strategy's Bitcoin holdings have generated an unrealized profit of $1.7187 billion.
Strategy currently holds 840,447 Bitcoin, with a total cost of $63.36 billion and an average entry price of $75,385. At Bitcoin’s current price of $77,430, the company’s Bitcoin holdings now have an unrealized profit of $1.7187 billion.
6 minutes ago
The Sandbox confirms SAND cross-chain bridge vulnerability; Base and BSC networks affected, cross-chain functionality suspended.
The Sandbox officials announced that the team has confirmed and fully contained the recent SAND cross-chain bridge vulnerability incident, which involved the Base and BNB Smart Chain (BSC) networks. The incident’s impact is limited, with the number of tokens involved accounting for less than 0.01% of SAND’s total supply. SAND on Ethereum and Polygon remains unaffected; user wallets were not compromised, and no action is required for affected token holders or liquidity providers. Attackers minted unbacked SAND tokens on Base and BSC networks via the vulnerability, per disclosures. Currently, The Sandbox has shut down SAND cross-chain functionality on both networks. SAND on Base and BSC has been isolated and is temporarily non-transferable or non-exchangeable. The Sandbox reminds users not to buy, sell, or trade SAND on Base and BSC, as liquidity on these networks has been impacted. The team has completed a pre-incident snapshot, is developing a compensation plan for affected liquidity pool (LP) users, and continues to investigate the full scope of the vulnerability. A full incident report and technical post-mortem will be released later.
6 minutes ago
A crypto whale opened a 4x long position worth $10.7 million on HYPE, with a liquidation price of $64.47.
According to monitoring by TradingBeats (formerly Hyperinsight), a crypto whale recently deposited approximately $4 million in USDC into Hyperliquid and opened a long position on HYPE. The wallet address established a 134,930 HYPE long position with 4x leverage, valued at around $10.7 million. Its entry price was $81.64, liquidation price stands at $64.47, and the current unrealized loss amounts to $315,000. The whale’s address is 0xa9d1c0fe2aa58038bac208ad390f69e7ce0c29a2.
6 minutes ago
Tesla has set the date for the press conference of its self-driving electric Cybercab.
Tesla has announced on social platforms that it will hold the Cybercab launch event on September 3, 2026, in Austin, Texas, United States. The automaker’s self-driving electric Cybercab officially entered production in North America this April, and the vehicle is AI-powered, with no steering wheel, pedals, or rearview mirrors.
6 minutes ago
Tencent's chip division head Gao Jianlin has resigned to found a startup, targeting the high-performance AI CPU track in the RISC-V space.
According to MaxForAI's disclosure, Gao Jianlin, a core lead in Tencent's chip research and development, recently left the tech giant to launch a startup focused on high-performance AI servers and Agentic AI, with plans to develop high-performance CPUs based on the RISC-V architecture. Gao is widely regarded as one of the early core drivers of Tencent's in-house chip ecosystem. Public records show he formed Tencent's FPGA hardware team in 2013, began laying the groundwork for AI chip R&D in 2018, established Penglai Lab in 2020, and spearheaded the development and data center deployment of multiple AI chips for Tencent. Unlike the currently fiercely competitive AI GPU market, Gao's new venture will center on CPUs. Gao believes that as Agentic AI advances rapidly, AI inference processes will involve model calls, tool execution, searches, database interactions, and extensive task scheduling, making CPUs take on a more critical scheduling and control role in AI systems. Reportedly, Gao was already involved in RISC-V-related R&D during his tenure at Tencent, contributing to multiple technical areas including chip architecture, verification, and backend development. His new company plans to build high-performance server CPUs based on the open RISC-V instruction set to enter the AI infrastructure market. To date, the startup's name, financing details, and specific product launch timeline have not been made public. The market is closely watching whether it will emerge as another key player in China's AI chip space targeting server CPUs and agent infrastructure.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
US Treasury repurchase operations unexpectedly pushed Bitcoin’s price up 25%, triggering $4 billion in short-position liquidations.
After the U.S. Treasury expanded its long-term U.S. Treasury bond repurchase operations, the 30-year U.S. Treasury yield fell from a 19-year high of 5.34% to around 5.19%, while Bitcoin rose roughly 25% in several days, briefly topping $79,000. Around $4 billion in cryptocurrency short positions were liquidated during this period, further amplifying the rally. The U.S. Treasury had earlier announced it would raise the size of its longest-dated Treasury repurchase operations from $2 billion per operation to $4 billion. Analysts noted that this operation is not equivalent to the Federal Reserve’s quantitative easing (QE); its main function is to improve the liquidity of older bonds and optimize the debt structure, but the market views it as a policy support signal for long-term U.S. Treasury yields. Analysts believe the key driver of Bitcoin’s recent rally is not the repurchase operation itself, but the market’s prior over-concentration of short positions. As long-term U.S. Treasury yields fell, short sellers were forced to cover their positions, triggering a powerful short squeeze. Meanwhile, U.S. spot Bitcoin ETFs saw a net inflow of around $650 million this week, and Trump once again urged Congress to advance the CLARITY Act, further boosting market risk appetite. Jeff Ko, chief analyst at CoinEx, said the key now is whether Bitcoin can hold its 200-day moving average around $69,000 and turn it from resistance into support. Market participants also warned that if the 10-year U.S. Treasury yield re-breaks above 4.7% and the 30-year yield approaches 5.3%, Bitcoin’s current breakout could face renewed tests. Bitcoin has now broken above its 200-day moving average and continues to rise; the next phase of the market will focus on whether it can sustain its rally in a high-yield environment.
6 minutes ago
Strategy's Bitcoin holdings have generated an unrealized profit of $1.7187 billion.
Strategy currently holds 840,447 Bitcoin, with a total cost of $63.36 billion and an average entry price of $75,385. At Bitcoin’s current price of $77,430, the company’s Bitcoin holdings now have an unrealized profit of $1.7187 billion.
6 minutes ago
The Sandbox confirms SAND cross-chain bridge vulnerability; Base and BSC networks affected, cross-chain functionality suspended.
The Sandbox officials announced that the team has confirmed and fully contained the recent SAND cross-chain bridge vulnerability incident, which involved the Base and BNB Smart Chain (BSC) networks. The incident’s impact is limited, with the number of tokens involved accounting for less than 0.01% of SAND’s total supply. SAND on Ethereum and Polygon remains unaffected; user wallets were not compromised, and no action is required for affected token holders or liquidity providers. Attackers minted unbacked SAND tokens on Base and BSC networks via the vulnerability, per disclosures. Currently, The Sandbox has shut down SAND cross-chain functionality on both networks. SAND on Base and BSC has been isolated and is temporarily non-transferable or non-exchangeable. The Sandbox reminds users not to buy, sell, or trade SAND on Base and BSC, as liquidity on these networks has been impacted. The team has completed a pre-incident snapshot, is developing a compensation plan for affected liquidity pool (LP) users, and continues to investigate the full scope of the vulnerability. A full incident report and technical post-mortem will be released later.
6 minutes ago
A crypto whale opened a 4x long position worth $10.7 million on HYPE, with a liquidation price of $64.47.
According to monitoring by TradingBeats (formerly Hyperinsight), a crypto whale recently deposited approximately $4 million in USDC into Hyperliquid and opened a long position on HYPE. The wallet address established a 134,930 HYPE long position with 4x leverage, valued at around $10.7 million. Its entry price was $81.64, liquidation price stands at $64.47, and the current unrealized loss amounts to $315,000. The whale’s address is 0xa9d1c0fe2aa58038bac208ad390f69e7ce0c29a2.
6 minutes ago
Tesla has set the date for the press conference of its self-driving electric Cybercab.
Tesla has announced on social platforms that it will hold the Cybercab launch event on September 3, 2026, in Austin, Texas, United States. The automaker’s self-driving electric Cybercab officially entered production in North America this April, and the vehicle is AI-powered, with no steering wheel, pedals, or rearview mirrors.
6 minutes ago
Tencent's chip division head Gao Jianlin has resigned to found a startup, targeting the high-performance AI CPU track in the RISC-V space.
According to MaxForAI's disclosure, Gao Jianlin, a core lead in Tencent's chip research and development, recently left the tech giant to launch a startup focused on high-performance AI servers and Agentic AI, with plans to develop high-performance CPUs based on the RISC-V architecture. Gao is widely regarded as one of the early core drivers of Tencent's in-house chip ecosystem. Public records show he formed Tencent's FPGA hardware team in 2013, began laying the groundwork for AI chip R&D in 2018, established Penglai Lab in 2020, and spearheaded the development and data center deployment of multiple AI chips for Tencent. Unlike the currently fiercely competitive AI GPU market, Gao's new venture will center on CPUs. Gao believes that as Agentic AI advances rapidly, AI inference processes will involve model calls, tool execution, searches, database interactions, and extensive task scheduling, making CPUs take on a more critical scheduling and control role in AI systems. Reportedly, Gao was already involved in RISC-V-related R&D during his tenure at Tencent, contributing to multiple technical areas including chip architecture, verification, and backend development. His new company plans to build high-performance server CPUs based on the open RISC-V instruction set to enter the AI infrastructure market. To date, the startup's name, financing details, and specific product launch timeline have not been made public. The market is closely watching whether it will emerge as another key player in China's AI chip space targeting server CPUs and agent infrastructure.
Metaverse project The Sandbox is facing a critical security breach after its SAND cross-chain OFT contract on the Base network was reportedly exploited, allowing an attacker to carry out an “infinite mint” attack.
Onchain data shows the attack is still active, with nearly $49 billion worth of SAND have been created through more than 400 transactions.
How Did the SAND Minting Attack Happen?According to security firm Blockaid, attackers gained control of LayerZero delegate permissions linked to SAND’s OFT system on Base.
The attackers appear to have used “approveAndCall” to bypass the normal controls and create new SAND without the required backing.
At one point, around 500 million SAND had been created, equal to nearly 17% of SAND’s 3 billion-token supply.
PeckShield later reported that about 14.9 billion SAND appeared across two addresses linked to the attack.
Meanwhile, Blockaid reported an even larger figure, saying nearly $49 billion worth of SAND had been created through more than 400 transactions.
🚨 Blockaid detected an ongoing exploit on @TheSandboxGame SAND OFT on Base.
Attackers hijacked LayerZero delegate permissions via approveAndCall and minted unbacked SAND.
~$49B face-value SAND minted so far across ~400+ txs. Attack still ongoing.
More details in 🧵
— Blockaid (@blockaid_) August 22, 2026 $49 Billion SAND Does Not Mean $49 Billion Was StolenThe $49 billion figure represents the market value of the newly created tokens, not money that attackers actually received.
Because these tokens were created without backing, they cannot simply be sold for $49 billion. Selling such a huge amount would likely crash SAND’s price.
The actual amount extracted appears much smaller.
The Ethereum OFT adapter reportedly lost around 14.75 million SAND, worth about $675,000 at the time. Around 79.74 ETH was reportedly converted from the stolen funds.
Quick Response From Bithumb & Upbit Exchanges The unusual activity has already triggered action from exchanges. Bithumb suspended SAND deposits and withdrawals, while Upbit issued an investor warning over the abnormal on-chain activity.
Security firms, including CertiK, have also flagged the incident, adding to concerns that the situation was still developing.
The Sandbox Confirms Base and BSC ImpactHours after the exploit, The Sandbox team responded on X by stating that it has fixed the security issue affecting SAND’s cross-chain bridge on Base and BNB Smart Chain (BSC). The impact is less than 0.01% of the total SAND supply. Ethereum and Polygon were not affected.
The Sandbox said no user wallets were hacked, and SAND locked on Ethereum remains safe. The attacker created SAND without proper backing on Base and BSC, so the team has stopped bridging on both networks.
The Sandbox team has identified and fully contained a recent vulnerability regarding the SAND cross-chain bridge on Base and BNB Smart Chain (BSC). The impact is minimal, representing less than 0.01% of the total SAND token supply.
SAND tokens on Ethereum and Polygon are NOT…
— The Sandbox (@TheSandboxGame) August 22, 2026 The team has also asked users not to buy, sell, or trade SAND on Base or BSC. It is taking a snapshot of the network before the attack and plans to compensate eligible liquidity providers.
SAND Price Keeps Rising Despite ExploitSurprisingly, SAND has continued to rise despite reports of the exploit. The token was up 4.76% at $0.0476, while trading volume jumped more than 400%.
Story Ends Here
Trust with CoinPedia:CoinPedia has been delivering accurate and timely cryptocurrency and blockchain updates since 2017. All content is created by our expert panel of analysts and journalists, following strict Editorial Guidelines based on E-E-A-T (Experience, Expertise, Authoritativeness, Trustworthiness). Every article is fact-checked against reputable sources to ensure accuracy, transparency, and reliability. Our review policy guarantees unbiased evaluations when recommending exchanges, platforms, or tools. We strive to provide timely updates about everything crypto & blockchain, right from startups to industry majors.
Investment Disclaimer:All opinions and insights shared represent the author's own views on current market conditions. Please do your own research before making investment decisions. Neither the writer nor the publication assumes responsibility for your financial choices.
Sponsored and Advertisements:Sponsored content and affiliate links may appear on our site. Advertisements are marked clearly, and our editorial content remains entirely independent from our ad partners.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
US Treasury repurchase operations unexpectedly pushed Bitcoin’s price up 25%, triggering $4 billion in short-position liquidations.
After the U.S. Treasury expanded its long-term U.S. Treasury bond repurchase operations, the 30-year U.S. Treasury yield fell from a 19-year high of 5.34% to around 5.19%, while Bitcoin rose roughly 25% in several days, briefly topping $79,000. Around $4 billion in cryptocurrency short positions were liquidated during this period, further amplifying the rally. The U.S. Treasury had earlier announced it would raise the size of its longest-dated Treasury repurchase operations from $2 billion per operation to $4 billion. Analysts noted that this operation is not equivalent to the Federal Reserve’s quantitative easing (QE); its main function is to improve the liquidity of older bonds and optimize the debt structure, but the market views it as a policy support signal for long-term U.S. Treasury yields. Analysts believe the key driver of Bitcoin’s recent rally is not the repurchase operation itself, but the market’s prior over-concentration of short positions. As long-term U.S. Treasury yields fell, short sellers were forced to cover their positions, triggering a powerful short squeeze. Meanwhile, U.S. spot Bitcoin ETFs saw a net inflow of around $650 million this week, and Trump once again urged Congress to advance the CLARITY Act, further boosting market risk appetite. Jeff Ko, chief analyst at CoinEx, said the key now is whether Bitcoin can hold its 200-day moving average around $69,000 and turn it from resistance into support. Market participants also warned that if the 10-year U.S. Treasury yield re-breaks above 4.7% and the 30-year yield approaches 5.3%, Bitcoin’s current breakout could face renewed tests. Bitcoin has now broken above its 200-day moving average and continues to rise; the next phase of the market will focus on whether it can sustain its rally in a high-yield environment.
6 minutes ago
Strategy's Bitcoin holdings have generated an unrealized profit of $1.7187 billion.
Strategy currently holds 840,447 Bitcoin, with a total cost of $63.36 billion and an average entry price of $75,385. At Bitcoin’s current price of $77,430, the company’s Bitcoin holdings now have an unrealized profit of $1.7187 billion.
6 minutes ago
A crypto whale opened a 4x long position worth $10.7 million on HYPE, with a liquidation price of $64.47.
According to monitoring by TradingBeats (formerly Hyperinsight), a crypto whale recently deposited approximately $4 million in USDC into Hyperliquid and opened a long position on HYPE. The wallet address established a 134,930 HYPE long position with 4x leverage, valued at around $10.7 million. Its entry price was $81.64, liquidation price stands at $64.47, and the current unrealized loss amounts to $315,000. The whale’s address is 0xa9d1c0fe2aa58038bac208ad390f69e7ce0c29a2.
6 minutes ago
Tesla has set the date for the press conference of its self-driving electric Cybercab.
Tesla has announced on social platforms that it will hold the Cybercab launch event on September 3, 2026, in Austin, Texas, United States. The automaker’s self-driving electric Cybercab officially entered production in North America this April, and the vehicle is AI-powered, with no steering wheel, pedals, or rearview mirrors.
6 minutes ago
Tencent's chip division head Gao Jianlin has resigned to found a startup, targeting the high-performance AI CPU track in the RISC-V space.
According to MaxForAI's disclosure, Gao Jianlin, a core lead in Tencent's chip research and development, recently left the tech giant to launch a startup focused on high-performance AI servers and Agentic AI, with plans to develop high-performance CPUs based on the RISC-V architecture. Gao is widely regarded as one of the early core drivers of Tencent's in-house chip ecosystem. Public records show he formed Tencent's FPGA hardware team in 2013, began laying the groundwork for AI chip R&D in 2018, established Penglai Lab in 2020, and spearheaded the development and data center deployment of multiple AI chips for Tencent. Unlike the currently fiercely competitive AI GPU market, Gao's new venture will center on CPUs. Gao believes that as Agentic AI advances rapidly, AI inference processes will involve model calls, tool execution, searches, database interactions, and extensive task scheduling, making CPUs take on a more critical scheduling and control role in AI systems. Reportedly, Gao was already involved in RISC-V-related R&D during his tenure at Tencent, contributing to multiple technical areas including chip architecture, verification, and backend development. His new company plans to build high-performance server CPUs based on the open RISC-V instruction set to enter the AI infrastructure market. To date, the startup's name, financing details, and specific product launch timeline have not been made public. The market is closely watching whether it will emerge as another key player in China's AI chip space targeting server CPUs and agent infrastructure.
6 minutes ago
Crypto influencer 'Maji' incurs a $2 million floating loss in 80 minutes, holding long positions of 888.88 BTC and 19,100 ETH.
According to monitoring by TradingBeats (formerly Hyperinsight), the trading performance of the address linked to "Brother Ma Ji" Huang Licheng has seen a sharp reversal recently. After nearly 500 liquidations, the account grew its capital from $152,000 to over $10 million in just three days. However, amid a short-term crypto price plunge over the past two hours, the account balance dropped from $12.8 million to $10.8 million in 80 minutes, reflecting significant volatility. Currently, he still holds long positions of 888.88 BTC and 19,100 ETH: the BTC long position has an unrealized loss of $470,000, while the ETH long position has an unrealized profit of $2.17 million.
Coinbase will suspend perpetual contract trading for the following assets around 21:00 on August 26: Memecoin (MEME-PERP), The Sandbox (SAND-PERP), Moonbirds (BIRB-PERP), Blur (BLUR-PERP), Katana (KAT-PERP), SPX6900 (SPX-PERP), ZORA (ZORA-PERP), Axie Infinity (AXS-PERP), Gensyn (AI-PERP), and LayerZero (ZRO-PERP). Remaining open positions will be automatically settled, with the final settlement price based on the average index price of the 60 minutes prior to the trading suspension. The funding rate for the last cycle will be set to zero.
Relevant content
Mitsubishi UFJ Financial Group plans to launch an instant settlement service for Japanese government bonds using blockchain technology.
Japan’s largest banking group Mitsubishi UFJ Financial Group (MUFG) plans to leverage blockchain technology to offer instant settlement services for certain Japanese Government Bond (JGB) transactions. According to reports, MUFG will carry out blockchain-based JGB repurchase transactions using tokenized money market funds and stablecoins, with the goal of shortening the settlement process for traditional securities trades. (Nikkei)
4 hours ago
Goldman Sachs forecasts core PCE at 0.23%, slightly above core CPI and market consensus.
Following the release of CPI data, market focus has shifted to the July core PCE figures set to be published on August 26. Goldman Sachs projects July core PCE to rise 0.23% month-over-month, a slight uptick from core CPI and market consensus. Specifically, portfolio management fees are forecast to climb 8 basis points, reflecting second-quarter stock market gains. The investment bank notes that upcoming methodological adjustments may trigger volatility in PCE readings and drag down the annual core inflation rate. Goldman Sachs expects August core inflation to hold near 0.2%, and anticipates the Federal Reserve will maintain interest rates stable through the end of the year.
4 hours ago
Bank of America announces $250 billion infrastructure investment plan
Bank of America announced a $250 billion infrastructure investment plan on Wednesday, pledging to invest in key U.S. infrastructure sectors over the next year. The plan covers multiple areas including data centers and computing power, renewable energy generation, energy storage, natural gas, power transmission networks, and critical minerals and mining, aiming to support energy security, job growth, and economic competitiveness.
4 hours ago
The USDC Treasury has minted 250 million new USDC on Solana.
According to on-chain data, the USDC Treasury minted 250 million new USDC tokens on Solana 10 minutes ago.
4 hours ago
Morgan Stanley maintains its overweight rating on SpaceX, with a target price of $600 under a bull market scenario.
Morgan Stanley reaffirmed its overweight rating on SPCX, setting a target price of $300, and a $600 target in a bull case scenario. Analyst Adam Jonas believes the market is underestimating SpaceX’s broader AI platform, including its computing, connectivity, and real-time data capabilities. The upcoming Grok model could help narrow this valuation gap. Jonas views the approaching lock-up expiration as an opportunity rather than a risk, offering a potential entry point for investors.
4 hours ago
SpaceXAI launches Grok 4.6
According to official announcements, SpaceXAI has officially launched Grok 4.6. The official statement notes that Grok 4.6 prioritizes enhancing the capabilities of long-running agents, as well as boosting performance in more complex interactive and visualization tasks. It can sustain work on multi-step complex tasks, including researching topics, analyzing information, collaborating across codebases, or translating ideas into complete applications or work deliverables. Grok 4.6 has achieved leading performance across multiple agent coding and knowledge work benchmarks, with its Artificial Analysis Intelligence Index score matching that of GPT-5.6 Sol.
Not financial or tax advice. PANews content is strictly educational and informational and is not investment advice, financial advice, tax advice, legal advice, or a solicitation to buy or sell any digital asset, security, or financial product. Do your own research and consult qualified advisers.
Disclosure. PANews may publish sponsored content, partner content, advertisements, affiliate links, event promotions, and market commentary involving Web3 projects, service providers, or financial products. PANews personnel, contributors, or affiliates may hold digital assets or other interests related to covered topics. See our Terms of Service.
Coinbase will suspend trading in the following perpetual contracts around 21:00 on August 26: Memecoin (MEME-PERP), The Sandbox (SAND-PERP), Moonbirds (BIRB-PERP), Blur (BLUR-PERP), Katana (KAT-PERP), SPX6900 (SPX-PERP), ZORA (ZORA-PERP), Axie Infinity (AXS-PERP), Gensyn (AI-PERP), and LayerZero (ZRO-PERP). All remaining open positions will be automatically settled at that time, with the final settlement price calculated as the average index price over the 60 minutes prior to the trading suspension. The funding rate for the last cycle will be set to zero.
Relevant content
Mitsubishi UFJ Financial Group plans to launch an instant settlement service for Japanese government bonds using blockchain technology.
Japan’s largest banking group Mitsubishi UFJ Financial Group (MUFG) plans to leverage blockchain technology to offer instant settlement services for certain Japanese Government Bond (JGB) transactions. According to reports, MUFG will carry out blockchain-based JGB repurchase transactions using tokenized money market funds and stablecoins, with the goal of shortening the settlement process for traditional securities trades. (Nikkei)
4 hours ago
Goldman Sachs forecasts core PCE at 0.23%, slightly above core CPI and market consensus.
Following the release of CPI data, market focus has shifted to the July core PCE figures set to be published on August 26. Goldman Sachs projects July core PCE to rise 0.23% month-over-month, a slight uptick from core CPI and market consensus. Specifically, portfolio management fees are forecast to climb 8 basis points, reflecting second-quarter stock market gains. The investment bank notes that upcoming methodological adjustments may trigger volatility in PCE readings and drag down the annual core inflation rate. Goldman Sachs expects August core inflation to hold near 0.2%, and anticipates the Federal Reserve will maintain interest rates stable through the end of the year.
4 hours ago
Bank of America announces $250 billion infrastructure investment plan
Bank of America announced a $250 billion infrastructure investment plan on Wednesday, pledging to invest in key U.S. infrastructure sectors over the next year. The plan covers multiple areas including data centers and computing power, renewable energy generation, energy storage, natural gas, power transmission networks, and critical minerals and mining, aiming to support energy security, job growth, and economic competitiveness.
4 hours ago
The USDC Treasury has minted 250 million new USDC on Solana.
According to on-chain data, the USDC Treasury minted 250 million new USDC tokens on Solana 10 minutes ago.
4 hours ago
Morgan Stanley maintains its overweight rating on SpaceX, with a target price of $600 under a bull market scenario.
Morgan Stanley reaffirmed its overweight rating on SPCX, setting a target price of $300, and a $600 target in a bull case scenario. Analyst Adam Jonas believes the market is underestimating SpaceX’s broader AI platform, including its computing, connectivity, and real-time data capabilities. The upcoming Grok model could help narrow this valuation gap. Jonas views the approaching lock-up expiration as an opportunity rather than a risk, offering a potential entry point for investors.
4 hours ago
SpaceXAI launches Grok 4.6
According to official announcements, SpaceXAI has officially launched Grok 4.6. The official statement notes that Grok 4.6 prioritizes enhancing the capabilities of long-running agents, as well as boosting performance in more complex interactive and visualization tasks. It can sustain work on multi-step complex tasks, including researching topics, analyzing information, collaborating across codebases, or translating ideas into complete applications or work deliverables. Grok 4.6 has achieved leading performance across multiple agent coding and knowledge work benchmarks, with its Artificial Analysis Intelligence Index score matching that of GPT-5.6 Sol.
Four-week jam starts 28 July with support from leading Hong Kong universities and partnersThe Sandbox and Animoca Brands today announced Creative Minds Jam #1, Hong Kong, a four-week competition challenging students, developers, and creators to build innovative content creator-centric experiences using Minds by Animoca Brands (“Minds”), a persistent, always-on agentic AI platform. The official community partner of the jam is Open Campus, a community-led DAO that is building the blockchain-powered financial layer for education.
The guiding theme of Creative Minds Jam #1 is "Build What Creators Need Next". With an aggregate of US$10,000 prize pool, the jam invites participants to explore how agentic AI can reshape digital experiences and help address challenges faced by today’s content creators and the broader creator economy, including discoverability, engagement, and workflow efficiency. Winners of the jam will also be considered for the Minds Investment Programme, which has an aggregate allocation of up to US$10 million, subject to the approval of the investment committee of the programme.
Submissions open on 28 July 2026, with a final showcase event in early September. The competition is open to all students, builders, developers, and creators, and no prior AI experience is required. Participants will be free to use any tools, provided that Minds agents are an integral part to their product submissions.
Minds is a persistent AI agent platform designed to reduce complexity while preserving control and customization for both builders and general users. It enables anyone to deploy and direct sovereign, always-on AI agents, known as Minds, without needing to operate local servers or manage hardware or software.
As the official community partner of Creative Minds Jam #1, Open Campus will support participants throughout the four weeks with weekly workshops including core Minds concepts, mentor-led sessions and speaking slots, and open office hours where teams can brainstorm and refine their submissions. Participants will also have access to a dedicated Open Campus community hub for the duration of the jam. Open Campus brings relevant experience to the jam through 18 months of building developer ecosystems for EDU Chain through bootcamps and incubation programmes, along with a 1,000-strong AI creator community.
Creative Minds Jam #1 is also supported by experts and leaders in education, including the Hong Kong Institute of Information Technology (HKIIT), Hong Kong Design Institute (HKDI), Index Academy, The Hong Kong Polytechnic University School of Design (PolyU Design), and Hong Kong Designers Association (HKDA), alongside industry partners.
Submissions to the jam will be evaluated by a distinguished panel of judges based on creativity, technical execution, user experience, and the innovative use of agentic AI. Judges are drawn from multiple fields including education, technology, and creative industries:
Ansh Grey, creative director and founder, Axies GreyFoxBecky Wong, founder, Index AcademyProf. Benny Leong, professor of Practice (Design Practice) and director of SD Plus, School of Design, The Hong Kong Polytechnic UniversityBowie Lau, managing director, MaGE GroupDerek Ting, creative director, Random Art WorkshopHo-Man Wong, senior lecturer, HKDIJay Leung, founder, Starz Group; vice chairman, HKDA; vice chairman, CIID Hong KongJonah Lau, project lead and core contributor, Open CampusJoyce Yung, visual content creator, producer, and author, Random Art WorkshopMohamed Ezeldin, head of Animoca Labs, Animoca BrandsRicky Ng, senior lecturer, HKIITRobby Yung, CEO of investments, Animoca Brands; CEO of The SandboxSébastien Borget, co-founder and ambassador, The SandboxYat Siu, co-founder and executive chairman, Animoca BrandsYusuf Goolamabbas, chief knowledge officer, Animoca Brands
Commentary from JudgesSébastien Borget, co-founder and ambassador of The Sandbox, said: “I’m excited to launch Creative Minds Jam #1 to solve real-world creator problems and step into the agentic web while learning new tools. Hong Kong has always been a thriving city where creativity meets rapid adoption of technology, whether it’s Web3, metaverse, or AI. Creative Minds Jam #1 gives students and creators, regardless of their technical background, the chance to explore how agentic AI can transform digital experiences.”
Yat Siu, co-founder and executive chairman of Animoca Brands, said: "AI agents represent a shift from tools that require technical expertise to collaborators that can adapt to the user. In the creator economy, that means helping more people turn ideas into content, experiences, and businesses with greater speed and flexibility. Creative Minds Jam #1 is an invitation to students and creators in Hong Kong to experiment with these new forms of creative leverage and help shape the future of the agentic web."
Mohamed Ezeldin, head of Animoca Labs, the innovation team within Animoca Brands that is developing Minds, said: “One of the biggest opportunities in the agentic web is making it easier for more people to build, experiment, and bring new ideas to life. Creative Minds Jam #1 is about broadening access and giving students, creators, and developers the opportunity to build with Minds using familiar interfaces and accessible tools. Hong Kong has long been a place where creativity and technology move quickly, and I’m excited to see how this generation of builders uses these tools to turn bold ideas into practical experiences and real solutions.”
Ansh Grey, creative director and founder at Axies GreyFox, said: “AI agents will profoundly transform the creator economy, empowering creators to scale their creativity and unlock entirely new forms of value creation. Those who embrace AI today will help shape the future of the digital economy.”
How to applyApplications to the Creative Minds Jam# 1 will open on 28 July 2026. Visit the Creative Minds page on Dorahack at https://dorahacks.io/hackathon/creativeminds/details to pre-register now.
All participants in the Jam, as well as anyone interested in AI and Minds, are also encouraged to join the official Minds Telegram channel and the Open Campus WhatsApp community hub, where workshop schedules and office hours will be posted.
Timeline
28 July: Registration opens 30 July: Hong Kong in-person kick-off session28 August: Submission deadlineSeptember: Showcase event and results announcement
Hong Kong In-Person Kick-Off Event
For local participants, The Sandbox and Animoca Brands will host an in-person workshop with the Minds team at Animoca Brands’ headquarters on 30 July, offering attendees an opportunity to hear from some of the judges and meet with fellow jam participants. For more details and to register for this event, visit Luma.
- END -
About Minds by Animoca Brands
Minds by Animoca Brands is a persistent AI agent platform that removes complexity while preserving full control and customization for both builders and general users. It enables anyone to deploy and direct sovereign, always-on AI agents, called Minds, without having to operate local servers or manage any hardware or software. Learn more at www.hellominds.ai.
About The Sandbox
The Sandbox, a subsidiary of Animoca Brands, is an immersive metaverse platform in which users play, create, and monetize unique experiences alongside their favorite brands, IPs, and celebrities across gaming, entertainment, music, art, and more. The Sandbox leverages web3 technologies to fully enable end-user creation and creator economies, disrupting existing platforms by providing both Players and Creators with true ownership of their assets, creations, and rewards as non-fungible tokens (NFTs). Over 400 partners have joined The Sandbox, including Warner Music Group, Gucci, Ubisoft, Paris Hilton, Attack on Titan, Snoop Dogg, Lacoste, Steve Aoki, The Smurfs, and many more. For more information, please visit www.sandbox.game and follow the regular updates on X, Medium, and Discord.
About Animoca Brands
Animoca Brands Corporation Limited (ACN: 122 921 813) is a global digital assets leader building and investing in impactful technologies and ecosystems to reimagine future economies through AI and the agentic web. It has received broad industry and market recognition including Fortune Crypto 40, Top 50 Blockchain Game Companies 2025, Financial Times’ High Growth Companies Asia-Pacific, and Deloitte Tech Fast. Animoca Brands is recognized for building digital asset platforms such as the Moca Network, Open Campus, Anichess, and The Sandbox, as well as institutional-grade platforms; providing digital asset services to help Web3 companies launch and grow; and investing in frontier Web3 technology, with a portfolio of over 600 companies and digital assets. For more information visit www.animocabrands.com or follow on X, YouTube, Instagram, LinkedIn, Facebook, and TikTok.
Binance, the well-known centralized crypto exchange, has officially become a part of the Philippines market. In this respect, the SEC has granted the conclusive authorization to BlockShoals Technologies Inc. to begin testing the financial services and products under the Strategic Sandbox model. As per Yi He, the Chief Customer Service Officer and Co-Founder of Binance, the platform will play the role of BlockShoals’ global crypto-asset service provider (CASP) partner. Hence, BlockShoals will operate in line with a crypto-asset intermediary framework, letting Philippine-based consumers leverage selected services and products through Binance.
BlockShoals Selects Binance as CASP Partner in Philippines after SEC Sandbox Approval The Strategic Sandbox approval from the SEC permits BlockShoals to leverage Binance as a CASP partner to offer crypto-related services and products in the Philippines. Thus, Binance will be a critical player to onboard consumers after the completion of the integration with the native partners. The SEC approval delivers a controlled setting for fintech entities to test cutting-edge products while guaranteeing regulatory compliance.
For BlockShoals, this authorization is a gateway to unveiling advanced crypto-asset services within the Philippine market. With the use of the global infrastructure of Binance, BlockShoals endeavors to connect native demand with the wider international expertise. In this respect, it guarantees that consumers leverage transparent and secure digital asset access.
Apart from that, the collaboration highlights the rising significance of the exclusive regulatory sandboxes when it comes to advancing innovation while making no compromise on investor protection. Over ninety days, BlockShoals is to officially integrate its mechanisms with a regional virtual asset service provider collaborator. The respective integration is crucial to ensure that its operational models align with the fine international practices and local compliance benchmarks.
Binance Drives Strategic Expansion in Southeast Asia Binance considers this move as a key development for its wider adoption. According to Yi He, this serves as Binance’s strategic expansion into one of the top crypto markets in Southeast Asia. At the same time, the initiative reaffirms Binance’s wider commitment to integrating with regional networks while maintaining the worldwide reach. Overall, as integration moves forward, Philippine consumers can anticipate comprehensive access to diverse digital asset services, supported by international infrastructure and regulatory safeguards.
AUTHOR
Umair Younas is a cryptocurrency-related content writer linked with this work since 2019. Here, at Blockchainreporter, he serves as a news and article writer. He is a crypto, blockchain, NFTs, DeFi, and FinTech enthusiast. He has strong command over writing authentic reviews about brokers and exchanges and he has collaborated with our education team to write educational content as well. He has a dream to raise awareness among people about digital currencies. His works are well-researched and brimmed with information hence they provide fresh insights. Stay tuned to his posts if you want to stay up-to-date with the crypto-verse.
The SEC of the Philippines has authorized BlockShoals to commence the regulatory sandbox testing of the project, utilizing Binance as its partner. This move will enable Filipino consumers to access chosen crypto products through the Strategic Sandbox program in a supervised way. BlockShoals Technologies Inc. has been authorized by the Philippine SEC to undertake product testing through the Strategic Sandbox program. This move was triggered by BlockShoals completing further regulatory requirements after being cleared under the StratBox program in November 2025.
The Binance co-founder He Yi announced the news through social media, confirming Binance’s entry into the Philippines through the program. This is one more step made in the direction of the examination of blockchain-based financial services under a supervised regulatory regime. Philippine regulators keep on enhancing their testing programs.
The Strategic Sandbox enables firms to test innovative financial products before pursuing a wider commercial launch of the product. Regulatory bodies monitor and evaluate compliance, control systems, and consumer protection initiatives for the firms during every testing process.
Binance Supports Testing Phase of BlockShoals As per the approved framework, BlockShoals would operate using a crypto-asset intermediary structure that links local individuals with a number of digital asset products. The individuals in the Philippines will access their services via the crypto asset service provider partner network of BlockShoals internationally within the existing regulatory framework.
BlockShoals would use ninety days for integration of its systems. Also, with local virtual asset service provider partners before launching any testing phase. Once it completes the integration process, it will move ahead with its testing plans. Customer onboarding is part of the rollout process, where Binance acts as the Crypto Asset Service Provider Partner of BlockShoals during the sandbox exercise period.
SEC Conducts Blockchain Testing As stated by the Philippine SEC, the Strategic Sandbox was established to foster innovation within the financial sector despite regulation before widespread application. The companies enrolled in the program should complete their testing tasks before seeking further approvals or expansion. This shows that regulators continue applying a controlled testing environment for the evaluation of financial instruments powered by blockchain technology.
This approval comes after the Philippine SEC has taken steps towards building a regulatory framework. It surrounds digital assets in the country. It is also worth noting that the process of testing BlockShoals would be monitored by regulators. Before considering other blockchain initiatives in the future.
Highlighted Crypto News:
Senator Cynthia Lummis Defends Clarity Act Against Elizabeth Warren’s Criticism
I specialize in Web3 and crypto writing, producing clear, research-driven content on blockchain, cryptocurrencies, and market trends.
The crypto market is flooded with GameFi projects that promise the next Fortnite and deliver nothing more than overpriced NFTs.
So it’s no wonder that investors ghosted tokens like SAND (The Sandbox) and MANA (Decentraland) after the metaverse mania cooled off. Once it occurred to them that virtual plots in pixelated universes aren’t exactly generational wealth, these cryptos plunged more than 95% to a point of no return.
The GameFi movement has been mostly lukewarm ever since.
But things are changing, and the coming crypto bull cycle could see another GameFi token race for the top charts. Let’s take a closer look at Tapzi ($TAPZI) – an underrated crypto gem trending among early backers now.
How Tapzi Redefines Gamefi Your success largely hinges on luck more than gameplay in GameFi, whether it’s the rewards you earn or the value appreciation of the token.
But if we take the long-term picture, it’s game mechanics that retain users, and gamers who drive the token price. Any project that compromises the interests of the gamer for the gamblers’ is likely to fail.
And the painful dissipation of the metaverse mania made it clear that hype is far from enough to build a serious gaming community.
Tapzi is a decentralized skill-based gaming platform that challenges the GameFi status quo.
Here, players can stake tokens to compete in real games – like Chess, Checkers, Rock-Paper-Scissors, or Tic Tac Toe – and unlock rewards as they hone their skills.
Crypto incentivization is integral to Tapzi’s gaming economy, but it doesn’t come at the cost of real engagement. Built on the BNB Chain, the project shows that the crypto gaming sector has more to offer than tokenomics and chance mechanics.
Tapzi’s Skill-Based Gaming Model: Explained Tapzi has a mobile-first design where you can play on the go.
On a commute or stuck in a boring meeting, you no longer have to mindlessly scroll through Instagram anymore.
Tapzi gives your mind a much-needed refresh with its skill-based games. And if you’re good enough, you can claim prize pools directly from opponent stakes. Being entirely funded by players, the prize pools don’t rely on a central treasury.
The entry barrier is set low, financially and technically.
Anybody can join the gasless gameplay, and there is even a free mode where you can get plenty of practice before shifting to the paid version.
Tapzi’s developer ecosystem is not limited to a single project. It provides SDKs and exposure to promising projects, aligned with its goal to build a hub for skill-based Web3 games.
All gaming rewards and payments are paid in $TAPZI tokens. The native crypto has a fixed supply of 5B, out of which 20% is made available for early backers at low prices in the ongoing presale.
25% of the presale tokens unlock at the TGE, and the remaining 75% follows a 3-month vesting schedule to prevent supply shocks. Team tokens, on the other hand, are locked for six months, and vested over 18 months.
Together, these strategies encourage long-term adoption of the game and nurture a sustainable gaming economy.
Entertainment doesn’t always have to be brain-rot. It can sometimes sharpen your mind and earn money, too.
Visit the Tapzi website for more details about the gaming hub and how it works.
More in Store Tapzi’s roadmap focuses on phased infrastructure development over feature overload, instilling confidence in its journey ahead.
For example, the demo game launch (Web Beta) is scheduled for this quarter, followed by the public release of Tapzi’s web-based multiplayer engine with sample games (Chess, Checkers, RPS, Tic Tac Toe), staking preview, and matchmaking.
Tapzi offers multi-layered rewards Alongside, the team will run user acquisition campaigns through gaming guilds, influencer partnerships, and paid traffic from high-conversion Web3 channels.
Once the presale is sold out, the token will make its exchange debut on PancakeSwap, with the launch of the $TAPZI/BNB pair.
In addition to these, the launch of the Tapzi Platform Beta (mainnet), the first global tournament with a live leaderboard and sponsored rewards, and the mobile gaming app debut are also slated for this quarter.
The next phases will focus on expansion and scaling. Some of the most awaited features are NFT avatars, cosmetic stores, cosmetic rarity system, analytic dashboard, and multilingual support.
Presale Hits 41% – The Next Crypto to Explode? The $TAPZI presale has already completed 41.6% of its goal, leaving investors with a small window to grab the token before it hits exchanges.
The token is currently priced at $0.0035, while the planned launch price is $0.01. So early presale investors are sitting on 186% profit even before the price action begins.
But what about early-stage dumping?
Tapzi has taken care of that, too. The vesting schedule prevents sell-offs and supports the token’s sustainable value appreciation.
And the smart contract has undergone extensive audits by Solidproof and Coinsult, clearing any concerns early-stage investors may have around code vulnerabilities and fraud.
Why join the $TAPZI presale But the project’s long-term growth is rooted in its gameplay, boldly shifting the focus from chance to skills.
The global gaming industry is predicted to cross $400B by 2028, with mobile gaming at its core, and Web3 gaming is expected to grow from $25B in 2024 to nearly $125B by 2032.
These numbers highlight what early positioning in a promising GameFi project like Tapzi could capture in a few years.
The $TAPZI presale supports purchases using both cryptocurrencies and fiat cards.
But as always, do your own research before investing in crypto. This is not financial advice.
Authored by Aaron Walker – https://www.newsbtc.com/news/tapzi-redefines-gamifi-next-altcoin-to-explode
META is back and has pushed SAND, AXS, and MANA higher. But network growth and liquidity trends still look weak.
The market leadership appears to have undergone a massive change since January 9th. Data shows that several small caps are taking charge while larger cryptocurrencies consolidate, driven by the resurgence of the META narrative.
Three tokens, in particular, have stolen the spotlight this month.
“Pocket Rally” Altcoin Vector explained that the latest trend is not a sign that the overall market is getting healthier, amidst falling network growth and weaker liquidity. In fact, the current rally is being touted as a “pocket rally,” fueled by speculation on thin liquidity rather than fundamental structural growth. Three tokens – SAND, AXS, and MANA- are at the center of this movement.
The platform found that Axie Infinity (AXS) is leading following tokenomic adjustments designed to reduce inflation, sparking renewed speculative interest across the gaming and metaverse ecosystem. Altcoin Vector’s Altcoin Quadrant shows that most altcoins remain in the “Accumulation” phase, while META assets have surged into “Scalp” territory, thereby marking them as outliers.
When comparing SAND and AXS, the latter demonstrated stronger performance as its Impulse metric stayed positive and steadily recovered after a brief cooldown. This indicates market recognition of Axie Infinity’s focus on ecosystem sustainability.
META Rally Remains a Speculative Play Despite the momentum, Altcoin Vector warned that speed does not equal stability. Small Caps are currently leading due to “fast capital” chasing immediate returns, but foundational growth remains absent. For a durable rally, adoption must rise, and dominance return to Bitcoin (BTC) and Ethereum (ETH).
“Ride the META narrative, but proceed with caution. For a sustained long-term rally, growth must stem from infrastructure and adoption, not just narrative. Without a solid base in core assets, this remains a speculative play.”
AXS is trading at $2.69. Over the past month, the token appreciated by 224.4%. Next up was MANA, which saw a monthly increase of nearly 47% and is currently trading at $0.169. Meanwhile, SAND was found exchanging hands at $0.157 after a more than 41% surge during the same period.
You may also like: Axie Infinity’s bAXS Overhaul Sparks 200% AXS Rally Tags:
PANews reported on February 10th that, according to SoSoValue data, the cryptocurrency market saw a slight rebound after a period of continuous decline. Bitcoin (BTC) rose 0.45% in the last 24 hours, fluctuating narrowly around the $70,000 mark. Ethereum (ETH) rose 3.15%, breaking through $2,100. Meanwhile, the GameFi sector performed relatively well, rising 2.24%, with Axie Infinity (AXS) rising 16.31% and The Sandbox (SAND) rising 1.85% within the sector.
In other sectors, the PayFi sector rose 2.10% in the last 24 hours, with Monero (XMR) up 6.22% and XRP (XRP) up 2.06%; the Meme sector rose 1.18%, with MemeCore (M) up 11.41%; the Layer 1 sector rose 0.89%, with Solana (SOL) up 1.58%; the CeFi sector rose 0.84%, with NEXO (NEXO) up 3.47%; the Layer 2 sector rose 0.37%, with zkSync (ZK) up 5.28%; and the DeFi sector rose 0.03%, with River (RIVER) up 7.79%.
In brief The Sandbox is rolling out its Season 7 content package featuring more user-created games and token rewards for players. With accessibility a key focus, players will be able to play some games directly from their web browser. The game is focused on adding and retaining players amid a difficult period in the crypto gaming industry. Crypto gaming ecosystem and metaverse platform The Sandbox is lowering the barriers to entry in its Season 7 rollout, enabling users to join select games directly from their browser without requiring downloads, installations, or an account.
The new season launch will also feature at least 20 creator-built experiences alongside a mix of those from established IP from partners, including Atari, “Black Mirror,” musician Steve Aoki, "The Terminator," and the Bruce Lee estate.
“Accessibility is definitely at the core of the launch of the season,” The Sandbox and Animoca Brands CEO Robby Yung told Decrypt.
“One of the challenges that we've had since the very earliest days is that we wanted to make this a user-generated content (UGC) platform for everybody,” he added. “But I think we have been held back in the past, honestly, by the kind of technical infrastructure that we put in place that we built it with.”
The team behind The Sandbox, which was acquired by Animoca Brands in 2018, has learned a lot in the last seven years. According to Yung, who took over the CEO role last August, the game is “kind of an old product” by blockchain standards. Since launch, the team recognized that “simple things”—like requiring big file downloads—can dissuade players from jumping in and playing.
A screenshot from The Sandbox Season 7. Image: The Sandbox"It's much easier if people can jump into a browser right away and engage in the experience quickly,” Yung said. “One of the things we're really pleased about is the browser-level ability to just jump right into The Sandbox. I think it is going to make a big difference, especially for people who are new to the experience.”
And while the developers will be watching lots of different metrics to evaluate the season, Yung said that retention—or the ability to bring people back to the game—will be of key importance.
"It's really about creating engagement that leads to retention as the north star metric,” he said.
With retention, Yung said that hopefully revenues should follow and create the potential for impact on token price as well—though he reiterated that all else is secondary to the game’s retention rate.
The price of SAND is down approximately 78% over the last year, per CoinGecko, amid a tough stretch in crypto gaming marked by investment broadly drying up across the industry. Many blockchain-based games shut down in 2025 and into early 2026 due to factors including a lack of funding and low player retention rates.
Players in The Sandbox ecosystem that keep coming back will have the opportunity to earn rewards in Season 7 as well, which is highlighted by a prize pool of more than 650,000 SAND or around $52,000 worth based on the ecosystem token’s current price.
A screenshot from The Sandbox Season 7. Image: The Sandbox“We're really excited,” said Yung of the Season 7 launch. “I think this is going to be the best season yet as far as content goes. And I think most importantly, it's all about the creators at the end of the day. Having more than 50% of the content coming from creators now, I think, is an overdue milestone for us.”
The ecosystem’s growing embrace of user-generated content mirrors that of other successful gaming platforms like Minecraft and Roblox. While The Sandbox has leaned on prominent brands and IP to drive interest across all of its seasons, the goal is ultimately for developers of all sorts to come in and create an ever-evolving array of experiences.
“We want to be a place where it's not just us making content that people enjoy and have fun with. It's also a place where any third-party, any player or professional developer, can come and create cool stuff and engage audiences—and do so in a way that benefits them,” he said.
“It's exactly what big platforms like Roblox are doing every day. But we want to do so in a way that's true to our Web3 values,” Yung added. “That basically means that there are low take rates, low transaction costs, and low infrastructure costs—so the benefit goes back to the creators and the IP holders.”
Daily Debrief NewsletterStart every day with the top news stories right now, plus original features, a podcast, videos and more.
The Sandbox opens pre-registration for NEXT mobile playtest built on Unreal Engine
18 March 2026
Following introduction of browser-based access in Season 7, The Sandbox opens pre-registration for playtesting NEXT, new mobile battle royale game
18 March 2026 – The Sandbox, an immersive gaming platform and subsidiary of Animoca Brands, today opened pre-registration for the playtest of NEXT, its first dedicated mobile battle royale game. NEXT is built on Unreal Engine, a significant technical shift for The Sandbox, which has historically run on Unity. Register for free at sandbox.game/next.
NEXT is a mobile battle royale game in which players carry over their identity, progression, and assets from The Sandbox game platform. NEXT provides players with a fast-paced, replayable PvP experience that connects intense and skill-demanding gameplay with the broader player-driven ecosystem of The Sandbox, where player avatars extend beyond a single match.
Players of NEXT are dropped into the Desert, an open-terrain environment built around sightlines and long-range combat, or the City, a vertical, close-quarters map that rewards adaptability. Matches support solo play or multiplayer groups of up to 20 players per instance.
NEXT will serve as a new entry point into The Sandbox, where playing, collecting, and expressing identity all converge. The mobile launch represents a major step for one of web3’s most established entertainment brands, with more than 400 brand and IP partners spanning gaming, music, fashion and culture, including Warner Music Group, Gucci, Ubisoft, Snoop Dogg and Lacoste.
Season 7 of The Sandbox, which is currently ongoing, introduced three browser-based games as a frictionless entry point to The Sandbox ecosystem. Now, with the NEXT playtest, The Sandbox is taking steps to integrate additional experiences via mobile.
“Like our recent launch of WebGL games, NEXT is part of our plan to increase the reach of The Sandbox so players can discover, play and come back more often, whether they’re on desktop or on their phone,” said Robby Yung, CEO of The Sandbox. “The goal is to meet people where they spend their time. A native mobile experience in addition to the desktop version makes that possible in a way browser access alone can’t.”
Registration for NEXT playtest is now open until 25 March 2026 at 2 p.m. (UTC), with limited spots assigned on a first-come first-served basis. The playtest begins on 26 March, with additional features rolling out as NEXT evolves. Register now at sandbox.game/next.
For more information about The Sandbox and the NEXT mobile app playtest, visit sandbox.game/blog and follow The Sandbox on X, Discord, and Instagram for regular updates.
###
About The Sandbox
The Sandbox, a subsidiary of Animoca Brands, is an immersive metaverse platform in which users play, create, and monetize unique experiences alongside their favorite brands, IPs, and celebrities across gaming, entertainment, music, art, and more. The Sandbox leverages web3 technologies to fully enable end-user creation and creator economies, disrupting existing platforms by providing both Players and Creators with true ownership of their assets, creations, and rewards as non-fungible tokens (NFTs). Over 400 partners have joined The Sandbox, including Warner Music Group, Gucci, Ubisoft, Paris Hilton, Attack on Titan, Snoop Dogg, Lacoste, Steve Aoki, The Smurfs, and many more. For more information, please visit www.sandbox.game and follow the regular updates on X, Medium, and Discord.
About Animoca Brands
Animoca Brands Corporation Limited (ACN: 122 921 813) is a global digital assets leader building and investing in impactful technologies and ecosystems to reimagine future economies. It has received broad industry and market recognition including Fortune Crypto 40, Top 50 Blockchain Game Companies 2025, Financial Times’ High Growth Companies Asia-Pacific, and Deloitte Tech Fast. Animoca Brands is recognized for building digital asset platforms such as the Moca Network, Open Campus, Anichess, and The Sandbox, as well as institutional-grade platforms; providing digital asset services to help Web3 companies launch and grow; and investing in frontier Web3 technology, with a portfolio of over 600 companies and digital assets. For more information visit www.animocabrands.com or follow on X, YouTube, Instagram, LinkedIn, Facebook, and TikTok.
The Sandbox opens pre-registration for playtesting The Sandbox NEXT, new mobile game
LOS ANGELES, March 19, 2026 /PRNewswire/ — The Sandbox, an immersive gaming platform and subsidiary of Animoca Brands, today opened pre-registration for the playtest of The Sandbox NEXT, marking for the franchise a going back to its roots after 40 million historical downloads on mobile. The Sandbox NEXT is built by Unreal Engine, a significant technical shift for The Sandbox, which has historically run on Unity. Register for free at sandbox.game/next.
The Sandbox NEXT offers a multiplayer extraction and survival mobile gameplay in which players carry over their identity, progression, and all the voxel assets from The Sandbox game platform, including UGC and branded ones. The Sandbox NEXT provides players with a fast-paced, replayable PvP experience that connects intense and skill-demanding gameplay with the broader player-driven ecosystem of The Sandbox, where player avatars from over 56 collections of branded Avatars (Snoop Dogg, Attack on Titan, Smiley, Steve Aoki, Paris Hilton, Smurf, etc) extend beyond a single match.
Players of The Sandbox NEXT are dropped into the Desert, an open-terrain environment built around sightlines and long-range combat, or the City, a vertical, close-quarters map that rewards adaptability. Matches support solo play or multiplayer groups of up to 20 players per instance.
The Sandbox NEXT will serve as a new entry point into The Sandbox, where playing, collecting, and expressing identity all converge. The mobile launch represents a major step for one of web3’s most established entertainment brands, with more than 400 brand and IP partners spanning gaming, music, fashion and culture, including Warner Music Group, Gucci, Ubisoft, Snoop Dogg and Lacoste.
Season 7 of The Sandbox, which is currently ongoing, introduced three browser-based games as a frictionless entry point to The Sandbox ecosystem. Now, with The Sandbox NEXT playtest, The Sandbox is taking steps to integrate additional experiences via mobile.
“Like our recent launch of WebGL games, The Sandbox NEXT is part of our plan to increase the reach of The Sandbox so players can discover, play and come back more often, whether they’re on desktop or on their phone,” said Robby Yung, CEO of The Sandbox. “The goal is to meet people where they spend their time. A native mobile experience in addition to the desktop version makes that possible in a way browser access alone can’t.”
Registration for The Sandbox NEXT playtest is now open until 25 March 2026 at 2 p.m. (UTC), with limited spots assigned on a first-come first-served basis. The playtest begins on 26 March, with additional features rolling out as The Sandbox NEXT evolves. Register now at sandbox.game/next.
For more information about The Sandbox NEXT mobile app playtest, visit sandbox.game/blog and follow The Sandbox on X, Discord, and Instagram for regular updates.
About The Sandbox
The Sandbox, a subsidiary of Animoca Brands, is an immersive metaverse platform in which users play, create, and monetize unique experiences alongside their favorite brands, IPs, and celebrities across gaming, entertainment, music, art, and more. The Sandbox leverages web3 technologies to fully enable end-user creation and creator economies, disrupting existing platforms by providing both Players and Creators with true ownership of their assets, creations, and rewards as non-fungible tokens (NFTs). Over 400 partners have joined The Sandbox, including Warner Music Group, Gucci, Ubisoft, Paris Hilton, Attack on Titan, Snoop Dogg, Lacoste, Steve Aoki, The Smurfs, and many more. For more information, please visit www.sandbox.game and follow the regular updates on X, Medium, and Discord.
About Animoca Brands
Animoca Brands Corporation Limited (ACN: 122 921 813) is a global digital assets leader building and investing in impactful technologies and ecosystems to reimagine future economies. It has received broad industry and market recognition including Fortune Crypto 40, Top 50 Blockchain Game Companies 2025, Financial Times’ High Growth Companies Asia-Pacific, and Deloitte Tech Fast. Animoca Brands is recognized for building digital asset platforms such as the Moca Network, Open Campus, Anichess, and The Sandbox, as well as institutional-grade platforms; providing digital asset services to help Web3 companies launch and grow; and investing in frontier Web3 technology, with a portfolio of over 600 companies and digital assets. For more information visit www.animocabrands.com or follow on X, YouTube, Instagram, LinkedIn, Facebook, and TikTok.
PANews reported on April 15th that, according to SoSoValue data, the crypto market experienced overall volatility and divergence, with most sectors declining. The GameFi sector fell 5.02% in the last 24 hours, with The Sandbox (SAND) and Axie Infinity (AXS) falling 2.41% and 1.94% respectively. Only the CeFi and Meme sectors remained relatively resilient, rising 0.40% and 0.23% respectively. Within the CeFi sector, Gate (GT) rose 2.52%, and Binance Coin (BNB) rose 0.66%. In the Meme sector, Binance Life continued its significant upward trend, surging 66.27%.
In addition, Bitcoin (BTC) rose 0.40% to $74,000, having briefly broken through $76,000 during the session; Ethereum (ETH) pulled back 1.28%, having broken through the $2,400 mark during the session.
In other sectors, the PayFi sector fell 0.30% in the last 24 hours, while SafePal (SFP) rose 1.60%; the Layer 1 sector fell 0.53%, but TRON (TRX) rose 0.96%; the DeFi sector fell 0.68%, while Genius (GENIUS), which was newly launched yesterday, rose 24.72%; the Layer 2 sector fell 1.90%, and Mantle (MNT) fell 3.45%.
Jefferies: Samsung is likely to follow SK Hynix’s example to list in the US via ADRs.
Jeff Kim, Head of Research at Jefferies, said Samsung is likely to follow SK Hynix in listing on the U.S. market via American Depositary Receipts (ADRs), which will boost the share price of the South Korean chipmaker whose valuation lags behind Micron. "Chip stocks are at a turning point. ADRs will serve as an important catalyst to drive their valuations," he added.
7 minutes ago
UBS and TD Cowen sharply raise Arm’s target price, betting on a revaluation of Arm’s AI data center CPU value.
Arm’s stock price pulled back this week alongside the high-valuation AI sector, though some Wall Street analysts say the correction does not alter the company’s long-term standing in AI data centers. UBS sharply raised Arm’s price target from $260 to $470, retaining its Buy rating; TD Cowen lifted its target from $265 to $475, also keeping a Buy recommendation. Both firms share the view that as agentic AI evolves, CPUs could gain greater importance in data center architectures, rather than GPUs continuing to monopolize the investment narrative. TD Cowen believes that over the long term, CPUs could hold a more strategic position in certain AI workloads. UBS, meanwhile, emphasizes that the real debate in the market centers on the revenue potential of Arm’s self-developed or independent CPU business. The bank projects Arm’s CPU-related revenue could reach around $14 billion by 2030, though the company itself has stated this business will not have a material impact on its finances until fiscal 2028. Arm’s strengths lie in low latency and energy efficiency—metrics that major cloud providers are increasingly prioritizing as they expand AI infrastructure. Even with its stock pulling back from recent highs in the short term, analysts still view Arm as one of the key beneficiaries of the server CPU upgrade cycle.
7 minutes ago
Crypto whale who profited over $23.77 million from BAT ICO liquidates 27,586 ETH
According to monitoring by Yu Jing, a whale that earned $23.77 million from participating in the BAT ICO sold 15,000 ETH (valued at roughly $24.29 million) two hours ago. The whale has now fully liquidated all 27,586 ETH it received from selling 35 million BAT on-chain over the past day and a half, converting the proceeds into 44.836 million USDS at an average selling price of $1,625.
7 minutes ago
Sources: Iraqi officials once considered withdrawing from OPEC, but current plans are to remain a member and pursue a higher quota.
A senior Iraqi oil ministry official said that if OPEC quotas are not significantly increased, Iraq will be forced to consider all available options. Sources said Iraqi officials had considered withdrawing from OPEC, but the current plan is to remain a member and push for higher quotas. (Jinshi)
7 minutes ago
Kepler Cheuvreux raises ASML’s European share price target from €1,460 to €1,830.
Kepler Cheuvreux has raised the target price for ASML’s European shares from €1,460 to €1,830.
7 minutes ago
Stifel: U.S. economy in "overheated expansion" as AI investment cycle outweighs consumer pressure
U.S. large diversified financial services holding company Stifel has raised its year-end S&P 500 target and rolled out a stock allocation framework for a "high-growth, high-inflation" environment. The firm lifted its year-end S&P 500 target to 7,800 points, noting the U.S. economy is entering a "running hot" state—where economic growth is strengthening alongside mounting inflationary pressure. Stifel’s models show U.S. growth momentum is picking up while inflation momentum is clearly overheating, a trend that will reshape the market’s leading sector structure in the second half of the year. Instead of traditional consumer sectors, Stifel’s top picks are investment-led cyclical industries, including banks, transportation, materials, energy, semiconductors, software and equipment. The firm adds that fixed-asset investment in AI remains on the rise: large tech firms including Amazon, Microsoft, Meta and Google are projected to combine for roughly $725 billion in total capital expenditures in 2026, some $100 billion higher than prior estimates. This means the AI investment chain is likely to continue outperforming the consumption chain squeezed by inflation. Stifel advises investors to reduce exposure to discretionary consumer, consumer staples, communication services and some financial services sectors, as these areas see weaker earnings revisions. Conversely, the firm favors cyclical value stocks and hedges with defensive value sectors such as insurance, autos, energy and banks.
PANews reported on May 21 that, according to The Block, the wife of Sebastien Borget, co-founder and COO of The Sandbox, was recently the victim of an attempted kidnapping at her home in Villenoy, Seine-et-Marne, France. The report, citing French media, stated that a suspect posing as a deliveryman rang the doorbell to lure her in, after which five hooded accomplices broke into the yard and attempted to force her into a vehicle. Neighbors intervened, and the suspects fled. Police subsequently intercepted a ride-hailing vehicle and arrested two teenage suspects, recovering a toy handgun, restraints, and a hood at the scene. Preliminary investigations suggest the incident is related to cryptocurrency; France has recorded over 100 kidnapping or attempted kidnapping incidents related to crypto assets since 2023.