Security incident · 2026-08-22
The Sandbox
According to the public DefiLlama incident dataset, The Sandbox (Base, BSC, Ethereum) suffered a security incident on 2026-08-22, with about $675K reported lost.
| Date | 2026-08-22 |
|---|---|
| Reported loss | $675K |
| Chain | Base, BSC, Ethereum |
| Target type | DeFi Protocol |
| Technique class | Access Control |
| Technique | Improper Access Control |
| Bridge incident | Yes |
| Within 2026 | #126 by loss that year, 0.0% of all reported losses that year |
How this kind of attack works
A contract function meant for administrators was not locked down, and the attacker called it directly to move funds.
Would a pre-payment check have helped
Broken contract permissions are a code-audit matter that pre-payment screening cannot see.
Other incidents with the same technique
- Poly Network2021-08-10 · $611.0M
- Drift Trade2026-04-01 · $295.0M
- BitGrail2018-02-12 · $170.0M
- Parity Multisig2017-11-09 · $150.0M
- Mirror2021-10-08 · $90.0M
- UPCX2025-04-01 · $70.0M

