READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Attacker Mints Over 500 Million Unauthorized SAND Tokens on The Sandbox's Base Network

Attacker Mints Over 500 Million Unauthorized SAND Tokens on The Sandbox's Base Network
A smart contract flaw on The Sandbox's Base network deployment let an attacker mint more than 500 million unauthorized SAND tokens, about 17% of the entire 3 billion token supply, in a single stroke. The Sandbox has not confirmed the exploit or explained how it happened, and as of the latest reports the vulnerability was still active.

Somebody found a hole in The Sandbox's code and started printing money. Not real money. Crypto. But the math works the same.

On-chain data shows more than 500 million unauthorized SAND tokens were minted through what appears to be an infinite mint exploit on The Sandbox's Base network deployment, according to Crypto Briefing. Base is Coinbase's Ethereum layer-2 network, one of several chains where The Sandbox has deployed its token beyond its original Ethereum and Polygon versions, according to Bloomingbit.

SAND has a hard cap of 3 billion tokens. Minting 500 million more, without authorization, works out to roughly 16.7% to 17% of that entire supply, according to both Crypto Briefing and Bloomingbit. That's one-sixth of a currency's total supply created out of thin air by someone who was never supposed to have that power.

As of the reporting from KuCoin and ababnews, the exploit was still ongoing. That means the 500 million figure isn't necessarily final. Every hour the vulnerability stays open is another hour someone can mint more.

What is actually known

The mechanism is called an infinite mint attack. It happens when a smart contract's permission controls or minting logic have a flaw, letting an attacker bypass the rules and issue tokens without limit, according to KuCoin and ababnews. It's a known failure mode in crypto, not some exotic new attack. Projects have gotten wrecked by this exact bug before.

What nobody has confirmed: who did it, how they got minting privileges, or where the newly created tokens ended up. Bloomingbit reported it remains unclear whether any of the minted tokens have actually been sold or moved to other networks. KuCoin's reporting, sourced to BlockBeats, says the same thing. The cause, the source of the attacker's access, and the destination of the tokens are all unconfirmed.

The Sandbox itself has said nothing. Crypto Briefing, KuCoin, and ababnews all note the company has issued no official statement addressing the incident. Holders don't know if the company has even patched the hole yet, let alone whether it plans to compensate anyone or coordinate a token snapshot to sort real supply from fake supply.

The price reaction

You'd expect a story like this to tank the price immediately. It didn't, at least not clearly. Bloomingbit reported SAND was trading around $0.051, up 13% from the previous day, even as the minting reports circulated. Bloomingbit's explanation is that there's no confirmed trail showing the new tokens actually hit the market, and Base-based liquidity is a small slice of SAND's overall trading volume.

Other outlets tell a different story. Reporting from bitcoinsistemi.com, republished by Crypto News, says SAND fell about 5.5% in a short window after the claims spread, with trading volume spiking to roughly 24 times normal levels and futures open interest jumping about 16% in an hour. Funding rates turned sharply negative, which points to traders piling into short positions, betting the price falls further.

Those two pictures aren't necessarily contradictory. Price moves in crypto happen fast and differ by exchange and by the minute. Anyone trying to gauge the real damage from headlines alone will get a muddled picture depending on which report they read and when.

Scope of the damage

Crypto Briefing reported the exploit appears confined to the Base-network version of SAND. The original Ethereum-based SAND token and The Sandbox's core operations do not appear to be directly compromised. If that holds up, it limits the damage to one chain's worth of tokens rather than the entire multi-chain SAND supply, though a 500-million-token dilution on any single chain still represents real money and real risk for anyone holding SAND there.

No exchange has announced trading suspensions or delisting action tied to this incident, according to Crypto Briefing, though the outlet says monitoring is ongoing.

The unresolved question is critical: does The Sandbox have the technical ability to freeze the Base contract and stop further minting, and if so, why hasn't it done that yet or said anything at all. Until the company breaks its silence, SAND holders on Base are flying blind on whether their tokens are still worth what they were yesterday, or a sixth less.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
Crypto BriefingThe Sandbox faces security breach as 500M SAND minted on Base network
unknown
en.bitcoinsistemiBREAKING: An Altcoin Is Allegedly Hacked, and Attackers Are Said to Be Able to Mint an Unlimited Number of Tokens
unknown
KuCoinThe Sandbox's SAND token on the Base network faces an infinite minting vulnerability, with over 500 million tokens minted.
unknown
BloomingbitSandbox Token Faces ‘Infinite Mint’ Allegations After 500 Million SAND Minted on Base
unknown
ababnewsSandbox SAND Suspected of Infinite Minting Attack on Base Network
unknown
Crypto NewsBREAKING: An Altcoin Is Allegedly Hacked, and Attackers Are Said to Be Able to Mint an Unlimited Number of Tokens