- Upbit issued a caution notice on August 22, 2026, flagging a suspected security issue tied to a specific wallet address active on the Base network.
- Reports on the size of the mint diverge sharply: several outlets cite roughly 500 million SAND, while a PeckShield security alert points to 14.9 billion, a figure nearly five times The Sandbox’s entire supply cap.
- The affected contract is a Base-only bridge version of SAND built on LayerZero’s cross-chain standard, separate from the token’s fixed 3 billion supply on Ethereum.
- SAND was trading at $0.0456 as of 06:32 UTC, up 1.59 percent on the day, with a market cap near $134 million and roughly 2.93 billion of its 3 billion token supply already in circulation.
Upbit told users on August 22 that it had confirmed “circumstances suggesting a security issue” on the network behind The Sandbox’s SAND token. The exchange’s notice pointed directly to a wallet address on Base, the Coinbase-incubated layer-2 network, as the one tied to the suspected issue.
That address, 0x67624bfa…1257e, shows real, recent activity. Base’s own block explorer records SAND-related transfers from the address dated August 21 and 22, matching Upbit’s timeline, and shows it was funded through deBridge, a tool commonly used to move assets between chains.
What isn’t settled yet is how large the exploit actually was. The more widely cited total puts just over 500 million SAND minted without authorization. PeckShield, a blockchain security firm that tracks exploits in real time, has instead flagged roughly 14.9 billion SAND minted across two addresses. Neither figure has been independently reconciled against the contract’s own on-chain mint log.
#PeckShieldAlert Seems like The @TheSandboxGame ($SAND) got exploited. 14.9B $SAND minted across 2 addresses: 0xAbE0…4D22 & 0x638C…F296 pic.twitter.com/a5Jgym87gR
— PeckShieldAlert (@PeckShieldAlert) August 22, 2026
A Bridge Contract Separate From SAND’s Supply Cap
The contract at the center of the incident, 0xac531Eb26Ca1d21b85126De8FB87E80E09002DcF, is not the same SAND token most holders are used to. It is a Base-network deployment built on LayerZero’s Omnichain Fungible Token standard, designed to let SAND move between chains.
SAND’s supply on Ethereum mainnet is fixed at 3 billion tokens. That cap has nothing to do with the Base contract’s own mint function. If an attacker gained minting rights on the bridge side, as the reporting so far suggests, the mainnet cap would not have stopped it.
Two Very Different Estimates of the Damage
The 500 million figure, if accurate, represents roughly 17 percent of SAND’s entire mainnet supply. The 14.9 billion figure, if accurate, is a different story entirely: nearly five times the token’s total supply, minted from a contract that was never supposed to issue more than its share of that fixed 3 billion.

Resolving it would take a direct query of the contract’s own transfer log for mints from the zero address during the incident window, a check this newsroom attempted but could not complete through the tools available in this pass.
SAND’s Price Holds Steady Despite the Uncertainty
SAND was trading at $0.0456 as of 06:32 UTC, up 1.59 percent over the previous 24 hours. Its market cap stood near $134 million on volume of about $85.4 million over the same period.

The token’s circulating supply sits at 2.93 billion SAND, just short of its 3 billion mainnet cap. That leaves little room on Ethereum itself to absorb dilution, which is part of why the unresolved Base-side mint figures matter regardless of which number turns out to be accurate.
Incident Status and Regulatory Context
The exploit was reportedly still active at the time the outlets above published, though none has confirmed whether it has since been stopped. The incident also comes amid wider crypto regulatory developments, including the Nigeria SEC regulatory sandbox, which reflects the growing focus on oversight across the digital-asset sector.
Upbit’s notice stopped short of calling this a confirmed hack, describing it only as circumstances suggesting a security issue. The development comes as regulators in markets such as the Philippines SEC regulatory sandbox continue exploring frameworks for digital-asset businesses. Until the Base contract’s mint activity is verified directly, that caution applies to the scale of the damage as much as to its cause.
Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.
To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.













