Crypto Bridge Exploit Lets Attacker Mint Billions in Fake Tokens
On August 22, 2026, attackers exploited a vulnerability in The Sandbox's SAND token smart contract on the Base blockchain, gaining unrestricted minting privileges. The contract relies on Layer Zero's Omnichain Fungible Token framework, which enables tokens to move between different blockchain networks.
Using this access, the attacker created 14.9 billion unbacked SAND tokens—tokens with no real value or backing behind them. This type of exploit, often called a bridge attack, targets the software connecting different blockchains and can undermine trust in a token's value if not addressed quickly.
While this incident centres on cryptocurrency infrastructure rather than traditional business systems, it's a reminder that any organisation using blockchain-based payments, tokens, or smart contracts should understand the risks tied to these newer technologies before adopting them.