A potential violation of security surrounding The Sandbox’s SAND token has caused a stir among traders. According to on-chain researchers, the perpetrators could be behind the minting of several hundred million in SAND tokens. On August 22, 2026, South Korean exchange Upbit cautioned traders to treat SAND with “special caution” due to indications of problems with security and potential fluctuations in prices.
The Sandbox still managed to print green indexes. SAND price surged by more than 19% over the last 7 days. Its 24-hour trading volume stood at $87 million. However, the biggest concern is supply. Lookonchain reported that more than 500 million new SAND were created during the incident. That is equivalent to at least 16.7% of the token’s maximum 3 billion supply.
BaseScan snapshot taken before the incident shows that the Base contract had a total supply of just 14.699 million SAND. This means that the new mint was more than 34 times the previous total supply of the Base chain. When new tokens are created without market demand, the existing token holders can be diluted. Especially if the newly minted tokens went to exchanges.
The risk goes way beyond SAND alone. Any sudden supply shocks can lead to a loss of trust in other utility tokens traded on exchanges if big exchanges notify customers about a problem.
Upbit announced the situation and advised the owners of the tokens to be ready for the possibility of increased volatility. The company, though, didn’t stop operations; nevertheless, both Upbit and Bithumb put restrictions on deposits and withdrawals for SAND.
What on-chain sleuths say happened
SAND on Base may possess a serious loophole that might let hackers mint tokens at any time, according to Lookonchain. The on-chain monitoring firm referred to what was happening as an “infinite mint attack,” which happens when the minting permissions are compromised, enabling the minting process that allows for tokens to be minted without limits.
The Base SAND contract can be represented as the following: 0xac531Eb26Ca1d21b85126De8FB87E80E09002DcF, while the address linked to the suspected unauthorized minting is 0x67624BFadee937c9281B4f98Ce18aF1bee01257e.
On August 22, Lookonchain announced that over 500 million SAND had been minted and that the alleged attack was still active. According to BaseScan, the wallet in question had executed 302 transactions at 05:23:10 UTC.
There are still many unanswered questions. The Sandbox has not furnished any official statement with regard to the entire episode since the time of writing, the reasons behind the incident, how the attacker was able to gain the rights for minting, and what happened with the new tokens.
BaseScan exposed the wallet summary, but attempts to open individual transaction details encountered a bot-protection screen. An exploit-specific transaction hash is therefore not included, rather than relying on an unverified repost.
The market has watched this movie before
Crypto traders have seen similar supply shocks before. In May 2024, Blockchain Game Partners Inc. said a compromised minter key allowed a malicious contractor to create 5 billion GALA tokens on Ethereum. The company said it stopped the incident before blocklisting the wallet and burning the supply.
More recently, Cryptopolitan reported that Harmony rolled back its blockchain to reverse the effects of a roughly 4 billion ONE mint, equal to about 26% of the token’s supply, after an attacker exploited a cross-shard flaw. ONE fell following the mint.
Those cases illustrate the two outcomes SAND holders are now weighing: whether The Sandbox can neutralize the unauthorized supply, or whether the market reprices the token before that happens.
What to watch next
The next signals are an official statement from The Sandbox, confirmation of the final amount minted, evidence showing where the new tokens moved, and whether more exchanges restrict SAND.
The incident also comes during an active year for crypto exploits. Global Ledger counted 224 publicly disclosed hacks totaling about $1.32 billion in losses during the first half of 2026. It also found that incidents are now being disclosed roughly twice as quickly as a year earlier, helping explain why exchange warnings can reach traders within hours of an emerging breach.
This articles is written by : Nermeen Nabil Khear Abdelmalak
All rights reserved to : USAGOLDMIES . www.usagoldmines.com
You can Enjoy surfing our website categories and read more content in many fields you may like .
Why USAGoldMines ?
USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.
