Invest1 distinct publisher2 min readUpdated
Lookonchain says the mint equals 16.7% of SAND's cap. Two Korean exchanges froze transfers, the issuer has said nothing, and the quote is still up.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
Comparing the mint to SAND's 3 billion cap understates what happened on the contract it came from. A BaseScan snapshot taken before the incident put the Base contract's total supply at 14.699 million SAND [6], which is under half a percent of the cap [1]. If the 500 million figure holds, about 97% of the SAND on that chain now originates with the suspected minter [2], and the deployment produced more than 34 times its own prior total [19].
The mechanics were not subtle. BaseScan showed the address linked to the unauthorised minting had run 302 transactions as of 05:23:10 UTC [9], averaging roughly 1.66 million SAND each [3], and Lookonchain described an infinite mint, in which minting permissions are compromised and the cap stops binding [7]. Cryptopolitan reported that individual transaction pages on BaseScan returned a bot-protection screen, so no exploit hash has been published [12]. Exchanges acted anyway, while the issuer has said nothing about the cause, how minting rights were obtained, or where the new tokens went [11].
Two earlier cases set the range of outcomes. In May 2024 Blockchain Game Partners said a compromised minter key let a contractor create 5 billion GALA on Ethereum, and the company blocklisted the wallet and burned the supply [13]. Harmony took the other route, rolling back its chain to reverse a mint of roughly 4 billion ONE, about 26% of supply, after a cross-shard flaw; ONE fell [14]. SAND's share of its own cap is around two-thirds of what Harmony reversed [5], which is a scale reference rather than a reassurance. Both remedies required something the issuer or its validators still controlled.
The dilution channel is specific. Tokens created without demand dilute existing holders, and the damage lands hardest if those tokens reach exchange order books [16]. On that reading the transfer freeze at Upbit and Bithumb [10] does more work than the caution banner, because it keeps the new units off two of the venues where they could be sold into bids.
There is also a measurement problem. Global Ledger tallied 224 publicly disclosed hacks and about $1.32 billion in losses over the year [18], an average near $5.9 million each [4]. A supply-side mint sits badly in that accounting: nothing leaves a treasury, so there is no clean loss figure to publish. The cost moves to holders through the float, and it only registers as a number once the tokens are sold.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
On August 22, Lookonchain said more than 500 million new SAND had been minted during the incident and that the alleged attack was still active.
Lookonchain called the event an "infinite mint attack", which happens when minting permissions are compromised and tokens can be minted without limits; it said SAND on Base may have a loophole allowing minting at any time.
On August 22, 2026, South Korean exchange Upbit cautioned traders to treat SAND with "special caution" due to indications of security problems and potential price fluctuations.
A BaseScan snapshot taken before the incident shows the Base SAND contract had a total supply of just 14.699 million SAND.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One publisher, one analyst, no primary confirmation
Concrete, checkable artifacts exist - a contract address, a suspect minter address, a 302-transaction count with a UTC timestamp, and a pre-incident Base supply of 14.699 million SAND. But every load-bearing figure traces to a single on-chain firm relayed by a single publisher, the article itself hedges 'may have been minted', transaction-level verification was blocked by bot protection so no exploit hash exists in the record, and the issuer has not confirmed cause, mint-authority compromise or token destination.
Two venues restricted transfers; issuer silent
Real-world response is observable but narrow: two Korean exchanges - Upbit and Bithumb - restricted SAND deposits and withdrawals, Upbit posted a special-caution notice, and markets kept trading $87 million in 24 hours. Against that, no other venue action, no issuer remediation (unlike the GALA burn or the Harmony rollback) and no evidence of where the minted supply went are recorded.
Cap-percentage framing outruns the chain-scoped facts
Overstated on net, though not egregiously. The framing that at least 16.7% of a 3 billion cap was minted measures an unconfirmed, Base-scoped mint against global supply, while the same article shows the Base contract previously held only 14.699 million SAND - about 0.49% of that cap. The Harmony comparison lends implied severity from a confirmed chain-level event to an unconfirmed one, and the dilution and contagion argument is presented although the destination of the tokens is explicitly unknown. Offsetting the overstatement: the report hedges repeatedly, states plainly that The Sandbox has not confirmed anything, and discloses its own inability to obtain a transaction hash.
Attention-driven crypto desk, self-citation, analyst visibility
Several incentives are visible in the material itself rather than inferred: the publisher is a crypto trading-news outlet running a price-and-exploit headline with an investment disclaimer, and it cites its own earlier Harmony reporting as the comparative precedent. The primary source is an on-chain monitoring firm whose reach grows with early attribution of live exploits, and the exchanges issuing caution notices have liability and customer-protection reasons to warn quickly - a dynamic the article links to disclosures arriving twice as fast as a year earlier. The issuer, silent so far, has the clearest incentive to delay confirmation.
Directionally plausible, quantitatively unsettled
That something anomalous happened on the Base SAND contract is well supported by convergent circumstantial signals - a named minter address with 302 transactions, two exchanges freezing transfers, and a caution notice from Upbit. The magnitude, cause and consequence are not: the 500 million figure is a hedged estimate, no exploit hash is available, the cap-percentage framing is methodologically loose, the issuer is silent, and the entire cluster is one publisher.
invest
MANTRA froze its chain and left the order book open: RWA's risk is plumbing, not story1 distinct publisher
invest
Upbit and Bithumb lose half their revenue, and the fee-only model shows its cost base1 distinct publisher
invest
Japan's 55.1 flash PMI puts the AI capex cycle into a G7 macro print1 distinct publisher
invest
Singapore freezes $58M after an exchange paid out the same 2,500 BTC twice1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 22, 2026