Register and share your invite link to earn from video plays and referrals.

GoPlus Security 🚦
@GoPlusSecurity
Protect Your Every Transaction. User App: 🛡️ Dev Integration: Security Intelligence & SafeToken Protocol 🛡️
Joined May 2021
1.1K Following    436.8K Followers
🚨 GoPlus Security Alert Aug 21, 23:42 UTC — attackers hijacked the delegate permissions on @TheSandboxGame’s SAND OFT (LayerZero Omnichain Fungible Token) contract on Base. They forged cross-chain messages and started infinitely minting unbacked $SAND. The exploit ran for hours. Trillions of tokens got printed. Liquidity + reserve limits kept the damage to ~$670k. Attacker-linked wallets: 0x67624bfadee937c9281b4f98ce18af1bee01257e 0x07bc449e85d9b66899425df8c8ab49cfb44a5f1e 0xAbE09907D2038181FC5Fb0ff0c961C147CdA4D22 0x638Ccb18370eE228378a565c1d4D0F9620d7F296 0x53eda2e80E46B804C5a47260cE04642e82d004cA 0xac76b04397c9296dfc00e25c96d8e51b4edfaf29 Compromised contract: 0xac531Eb26Ca1d21b85126De8FB87E80E09002DcF Example attack tx: 🛡️ GoPlus Security Notes 1️⃣ Projects: Strip or hard-disable any generic approveAndCall / paidCall style arbitrary-call functions on OFTs. At minimum, block calls to LayerZero Endpoint, MessageLib, and other privileged contracts. Set the delegate to a multisig + Timelock. Actively monitor DelegateChanged, ConfigSet, PeerSet events. Audits must specifically test the cross-contract combo risk: “ERC20 extension functions × Endpoint relying on msg.sender auth.” Auditing them in isolation isn’t enough. 2️⃣Users: Do not trade $SAND on Base or BSC — both chains’ liquidity is already polluted. If you provided SAND liquidity on Base/BSC, sit tight for the official snapshot + compensation plan. Watch for fake support / phishing links in replies and socials. Stay sharp.
Show more
The Sandbox team has identified and fully contained a recent vulnerability regarding the SAND cross-chain bridge on Base and BNB Smart Chain (BSC). The impact is minimal, representing less than 0.01% of the total SAND token supply. SAND tokens on Ethereum and Polygon are NOT affected. No user wallets were compromised, and no action is required from holders and liquidity pool (LP) providers on those networks. The SAND locked on Ethereum, which backs all bridged SAND, is fully intact. An attacker was able to mint unbacked SAND on Base and BSC. We have disabled bridging to and from both networks, so SAND on Base and BSC is currently isolated and cannot be moved or redeemed. ⚠️ Do not buy, sell, or trade SAND on Base or BSC. Liquidity on those networks is compromised. We are taking a pre-incident snapshot and preparing a compensation plan for the qualified users of the impacted LPs. Affected users can reach out to official support via contact@sandbox.game. We continue to monitor the situation and are actively investigating its scope, and we will share a full incident report and detailed technical post-mortem soon. We apologize for the inconvenience this has caused and deeply appreciate the continued patience and support of The Sandbox community. ⚠️ Reminder: Our team will NEVER DM you first. Please beware of scam links in the replies.
Show more