One of crypto's most eye-popping exploit headlines hides a lesson every user should understand: the difference between what a token says it's worth and what can actually be stolen.

Between August 21 and 22, an attacker exploited a bridge flaw in The Sandbox's SAND token to mint 329.24 trillion unbacked tokens across 703 events in roughly five hours on the Base and BNB Smart Chain networks. At SAND's market price, those tokens carried a nominal "face value" of around $49 billion, a number that raced across crypto media. Yet the actual amount drained was roughly $675,000.

The mechanics: the attacker weaponized a legacy approveAndCall function to hijack LayerZero "delegate" permissions on SAND's cross-chain contract, granting the ability to mint tokens on Base without any corresponding tokens being locked on Ethereum. Normally a bridge only creates tokens on one chain after proving a deposit on another; here, that check was bypassed entirely.

So why only $675K? Because the minted trillions were economically hollow. SAND's legitimate supply is capped at 3 billion tokens on Ethereum, and the attacker's mint exceeded that by a factor of roughly 110,000. No market could absorb even a sliver of that volume, any attempt to sell would collapse the price toward zero. The only real money accessible was the reserve held in the Ethereum vault, and the attacker drained about 14.75 million SAND (roughly 80 ETH, or $675,000) in under 60 seconds. On-chain records show the mint was calibrated to within 100 tokens of the vault's exact holdings, evidence of careful planning, before an arbitrage bot ate into liquidity and trimmed the final take.

The Sandbox team disabled Base and BNB Smart Chain bridging and removed the LayerZero peer settings via multisig, while exchanges Upbit and Bithumb suspended SAND deposits and withdrawals. Crucially, SAND's underlying supply on Ethereum was never compromised, and the project pledged 1:1 treasury reimbursement for affected bridged holders. This wasn't a flaw in cryptography but in configuration, and it echoes earlier cross-chain incidents like the KelpDAO and StakeDAO exploits, where catastrophic-looking mints translated into far smaller real losses. The takeaway for users: a token's on-chain "value" is only as real as the liquidity and reserves behind it.