Loading...
Loading...
🚨 GoPlus Security Alert Aug 21, 23:42 UTC — attackers hijacked the delegate permissions on @TheSandboxGame’s SAND OFT (LayerZero Omnichain Fungible Token) contract on Base. They forged cross-chain messages and started infinitely minting unbacked $SAND. The exploit ran for hours. Trillions of tokens got printed. Liquidity + reserve limits kept the damage to ~$670k. Attacker-linked wallets: 0x67624bfadee937c9281b4f98ce18af1bee01257e 0x07bc449e85d9b66899425df8c8ab49cfb44a5f1e 0xAbE09907D2038181FC5Fb0ff0c961C147CdA4D22 0x638Ccb18370eE228378a565c1d4D0F9620d7F296 0x53eda2e80E46B804C5a47260cE04642e82d004cA 0xac76b04397c9296dfc00e25c96d8e51b4edfaf29 Compromised contract: 0xac531Eb26Ca1d21b85126De8FB87E80E09002DcF Example attack tx: https://basescan.org/tx/0xbddb102a5dbc9324a84390aaa5a9767b89c2bac8955d486fe1cf697e2e9a8fa9 🛡️ GoPlus Security Notes 1️⃣ Projects: Strip or hard-disable any generic approveAndCall / paidCall style arbitrary-call functions on OFTs. At minimum, block calls to LayerZero Endpoint, MessageLib, and other privileged contracts. Set the delegate to a multisig + Timelock. Actively monitor DelegateChanged, ConfigSet, PeerSet events. Audits must specifically test the cross-contract combo risk: “ERC20 extension functions × Endpoint relying on msg.sender auth.” Auditing them in isolation isn’t enough. 2️⃣Users: Do not trade $SAND on Base or BSC — both chains’ liquidity is already polluted. If you provided SAND liquidity on Base/BSC, sit tight for the official snapshot + compensation plan. Watch for fake support / phishing links in replies and socials. Stay sharp.
Source:https://x.com/GoPlusSecurity/status/2091350029617500439
Impact Score