News linked to both this project and an event.
The Sandbox stated that it will provide full compensation to affected users for the SAND vulnerability incident on Base and BNB Smart Chain that occurred on August 22. Any wallet that legitimately held cross-chain SAND at the time of the snapshot prior to the incident will receive SAND compensation on the Ethereum network at a 1:1 ratio.
According to disclosures from the Phoenix Veritas Foundation, the Hunter Biden laptop-themed cultural token, LAPTOP, has been issued on the Base chain with a total supply of 1 billion tokens and an initial circulating supply of 350 million tokens (35%) at TGE. Token allocation consists of 30% for founders (including Hunter Biden), 30% for the prediction mechanism, 20% for the community airdrop, 10% for liquidity, 10% for the foundation treasury, and 5% for charity. Founder tokens are subject to a six-month lock-up period followed by linear unlocking over 24 months. LAPTOP provides no utility, positioned strictly as a cultural digital collectible with its value driven entirely by community sentiment. The token contract underwent a security audit by Hacken in April 2026, revealing no major vulnerabilities. Regarding market maker arrangements, the foundation has entered into a lending agreement with G20 and GSR totaling 20.5 million tokens.
Odaily News, Base co-founder Jesse Pollak issued a statement on the X platform clarifying that his account was compromised. The attacker published a fraudulent token ticker through a third-party application connected to the account. Jesse stated that the related posts have been deleted, all third-party app connections have been removed, and full control of the account has been restored. He reminded users to stay vigilant.According to screenshots of the deleted posts, the attacker, after gaining control of Jesse Pollak's account, launched a token named BASEMEME, describing it as the "first Meme coin with real utility," while attaching a trading link to o1.exchange and the contract address. The Meme coin's market cap currently stands at $257,000.
blockchain gaming platform The Sandbox has announced it will compensate users who held bridged SAND on Base or BNB Smart Chain prior to the August 21 bridge vulnerability exploit at a 1:1 ratio. The compensation will be paid using Ethereum-based SAND from the project treasury, with no new tokens being minted.The attack resulted in approximately 14.744 million SAND being stolen from the Ethereum treasury, valued at around $700,000. The claims process is expected to open within two weeks and will last for two weeks; two centralized exchanges holding over 72% of eligible balances will directly distribute compensation to affected customers.The Sandbox stated that the attacker exploited a configuration vulnerability in SAND contracts on Base and BNB Chain, becoming the sole validator of bridge messages and minting unbacked tokens. Additionally, over 339 trillion unbacked SAND tokens were minted across the two networks, but these have been quarantined and cannot be bridged or exchanged. SAND on Ethereum and Polygon was unaffected, and the compromised bridge contracts will be permanently decommissioned. (Cointelegraph)
According to monitoring by Blockaid, its vulnerability detection system detected suspicious activity on Moonwell on Base. The attacker manipulated MAMO collateral pricing to borrow cbBTC from the mCBTC market. To date, approximately 50.6 cbBTC (valued at over $4 million) have been observed being transferred. More details remain to be disclosed.
Odaily News, The Sandbox has released a post-mortem report on the August 22 vulnerability incident. The report shows that attackers exploited vulnerabilities in contracts related to cross-chain configurations on Base and BNB Smart Chain (BSC), stealing 14,742,341.84 SAND from the Ethereum treasury, accounting for approximately 0.5% of the maximum supply, with an estimated economic impact of approximately $1.4968 million, of which about $987,000 was actually retained by the attackers. The Ethereum mainnet and Polygon network were not affected. Until further notice, please do not purchase or send SAND on Base or BNB Smart Chain. Contracts deployed on Base and BNB Smart Chain have been permanently deactivated and will not be reopened. The Sandbox stated that the team has reported the attacker's wallet address to blockchain analysis firms TRM Labs and Chainalysis, and has communicated directly with relevant exchanges. The Sandbox also announced a compensation plan, which will compensate wallets that legitimately held cross-chain SAND on Base or BSC prior to the incident at a 1:1 ratio in Ethereum SAND. Compensation funds will come from The Sandbox treasury, with no new tokens issued. The claim process will open within the next two weeks and remain open for two weeks.
Odaily News, SlowMist Security Team disclosed that the cross-chain bridge project Allbridge suffered an attack on August 19, 2026, with losses of approximately $190,000. Notably, this attack was not executed instantaneously—the attacker began laying the groundwork nearly a month in advance, bypassing the verification mechanism through forged cross-chain messages.According to SlowMist's analysis, on July 26, the attacker directly called Circle's MessageTransmitterV2.sendMessage function on the Polygon chain, constructing a cross-chain message disguised as CCTP-style, claiming a transfer of 1 million USDC, despite no actual USDC burn operation occurring. Subsequently, Circle generated a valid attestation for this complete message following standard procedures.Approximately 24 days later, on August 19, the attacker waited for the Base Router to receive a genuine CCTP deposit, bringing its balance to approximately 191,000 USDC, then launched the attack just 6 seconds later. Using the previously forged message and attestation, the attacker called Allbridge's receiveCctpMessage function. Due to the project's lack of critical validation, the system mistook the fraudulent cross-chain message for a genuine deposit and recorded a 1 million USDC credit.Subsequently, the attacker borrowed approximately 809,000 USDC temporarily via an Aave flash loan to match the Router's balance with the forged amount, then utilized the internal credit record to call the transfer function, ultimately moving out approximately 999,000 USDC (after deducting a 0.1% fee). After repaying the flash loan and fees, the attacker netted approximately $189,800 in profit. The root cause of this vulnerability lies in Allbridge's failure to verify the identity of the cross-chain message sender and receiver, as well as its failure to confirm whether USDC was genuinely minted or whether the balance actually increased—instead directly trusting the amount and message hash data constructed by the attacker.SlowMist emphasized that on-chain message verification does not equate to actual asset arrival. Cross-chain protocols must not only verify message authenticity but also ensure the message source is trustworthy, confirm the receiver is Circle's official TokenMessengerV2, and only record assets after confirming actual minting and balance changes. This incident once again highlights the security risks in cross-chain bridges' message verification and asset settlement processes.
Odaily News: Metaverse gaming platform The Sandbox has confirmed a vulnerability in its cross-chain bridge, allowing attackers to mint unbacked SAND on Base and BNB Smart Chain. Blockchain security firm PeckShield detected on August 21 that two addresses had collectively minted approximately 14.9 billion SAND. The Sandbox subsequently shut down bridging functionality on both networks.The Sandbox stated that the affected assets are bridged assets on Base and BNB Smart Chain, while SAND on Ethereum and Polygon, user wallet assets, and the Ethereum-locked assets backing the token remain unaffected. The proportion of genuinely collateralized assets involved in this incident is less than 0.01% of the total SAND supply.The Sandbox is developing a compensation plan for affected liquidity providers and advises users not to trade SAND on Base or BNB Smart Chain until bridging is restored. Coinbase plans to delist 10 perpetual futures contracts, including SAND, on August 26, with open positions to be automatically settled at that time. (Bitcoin.com News)
The Sandbox has officially confirmed and fully secured the recent SAND cross-chain bridge vulnerability affecting the Base and BNB Smart Chain (BSC) networks. Attackers exploited the flaw to mint uncollateralized SAND tokens across both networks, but the impact remains limited, accounting for less than 0.01% of the total SAND supply. SAND on Ethereum and Polygon, along with user wallets, remain unaffected. The Sandbox has since disabled cross-chain functionality on both networks. SAND on Base and BSC has been isolated and is temporarily non-transferable and non-redeemable. The official team advises users to avoid buying, selling, or trading SAND on the aforementioned networks.
According to earlier reports, the SAND contract for The Sandbox on the Base chain is suspected of anomalous minting, resulting in the issuance of over 500 million additional tokens.
Odaily News: Sheldon Lee, founder of cryptocurrency exchange BitMart, stated that a post on X claiming users were unable to withdraw funds and that some employees had not received their July salaries is a "fabricated rumor," adding that the exchange's Chinese-language account had been hacked. Critics, including users and on-chain investigator ZachXBT, have demanded that BitMart resume withdrawals or undergo an independent third-party audit. BitMart is gradually winding down operations, with the final trading day set for August 26. Troubled investment firm Echo Base said it had proposed a funded restructuring plan to BitMart but received no response. The firm warned that resolving a large volume of customer claims may require proceedings through the courts. (CoinDesk)
Odaily News: On-chain security firm PeckShield (@PeckShieldAlert) monitoring shows that an attacker, through controlling address 0x920d…9708, stole approximately 500,000 USDC from a victim wallet 0x3a53…0B5c on the Base chain. However, when the attacker subsequently attempted to swap the USDC into ETH, insufficient slippage protection parameters were set, causing the transaction to be sandwiched and arbitraged by MEV bots. In the end, the attacker only received approximately 67 WETH, valued at around $129,000, meaning the stolen funds suffered a loss rate exceeding 75%.
According to CCTV News reports, the helicopter carrying U.S. President Trump encountered a flight safety incident in Washington on the 4th. The White House stated that the incident did not pose a personal safety risk; however, the U.S. Federal Aviation Administration has launched an investigation. Reportedly, Trump departed from outside the White House on the afternoon of the 4th aboard the "Marine One" helicopter, heading to Joint Base Andrews, and then transferred to "Air Force One" to proceed to Los Angeles.
According to Cointelegraph, the cross-chain bridging and atomic swap protocol Garden Finance temporarily took its application offline after detecting abnormal activity on July 27. Blockchain security firm Blockaid disclosed that attackers exploited a vulnerability in Garden Finance's Hash Time Locked Contracts (HTLC), stealing a total of approximately $450,000 worth of USDT across four networks: Ethereum, Base, Arbitrum, and BNB Smart Chain.
the Coinbase Layer 2 network Base experienced two block production outages last week, with the root cause identified as a vulnerability in the sequencer's block construction logic. This vulnerability allowed outdated log states to persist after transaction validation failed, preventing the sequencer and validator nodes from processing invalid blocks until sequencing was restored.The first incident lasted 116 minutes, while the second, caused by a race condition following a system reset that prevented the sequencer from keeping up, lasted 20 minutes. The team has since fixed the issue by applying a patch to the sequencer, with future plans to improve protocol fuzz testing and build a graceful recovery mechanism. (Cointelegraph)
Base has officially released an analysis report on the block production outage, disclosing that the Base mainnet experienced two block production interruptions on June 25 and 26, lasting 116 minutes and 20 minutes respectively. On-chain asset security was unaffected, and funds remained safe at all times. The root cause was a vulnerability in the sequencer's block construction logic: after a transaction execution failure, the old journal state was not properly cleared, causing subsequent legitimate transactions to encounter gas calculation errors during execution, thereby generating invalid state transition blocks and halting block production on the entire L2 chain.Base stated that the issue has been resolved through a patch, and will strengthen the protocol's fuzz testing and stress testing framework to identify potential malicious transaction paths, while optimizing monitoring and operational processes. Additionally, plans are in place to introduce a recovery mechanism to enhance rapid recovery capabilities in future similar events.
Odaily Odaily News Blockchain analyst Vadim noted that Base experienced a network outage today due to a consensus bug triggered by a single invalid block. All block generation after height 47806542 ceased, halting the network for nearly two hours. Since Base utilizes a single sequencer architecture, when that node encountered an error, the entire network stopped running, with no backup block producer or other validator nodes available to bypass the fault and maintain on-chain activity. During the outage, users were unable to conduct transactions, perform liquidations, or process withdrawals.Furthermore, the network recovery process was not automated; node operators within the ecosystem had to manually restart for block synchronization to gradually resume. This is not the first such incident for Base. In August of last year, the network also experienced a freeze lasting approximately 33 minutes due to a sequencer switching failure. The single sequencer model exposes the centralization risks in some current L2 networks: while offering higher speed, the entire chain can come to a halt due to a single point of failure when the core component malfunctions.
Cosine, founder of SlowMist, posted an analysis of the Squid security incident on X. He stated that sampling revealed all affected Safe wallets were single-signature, with different owners—but the issue was not related to private keys. Rather, the vulnerability lay in the module shown in the image (SquidRouterModule) used by these Safe addresses. Attackers could forge messages and easily bypass relevant validations to initiate subsequent swap operations, thereby draining funds from the targeted Safe wallets. Additionally, Cosine disclosed the attacker’s profit accumulation address. Earlier reports indicated that a third-party Gnosis Safe module was exploited on Base and Ethereum, causing approximately $3.2 million in losses. The victims were 86 Gnosis Safe wallets that had added this contract as a trusted Safe Module. The contract is named “SquidRouterModule” on Basescan. Subsequently, Squid clarified that it was not impacted by the Gnosis Safe-related vulnerability incident.
Odaily news Squid posted on X platform, stating that this incident is unrelated to the Squid core protocol and contracts. All Squid users and integrators are unaffected and no action is required.Today, a third-party Gnosis Safe module on the Base and Ethereum networks was attacked, resulting in a loss of approximately $3.2 million. The vulnerable contract is verified on Basescan under the name "SquidRouterModule," but this contract was not built, deployed, or operated by Squid. It is a third-party smart wallet product that chose to integrate with Squid and other protocols, and has no connection with Squid.The attack principle is that this third-party module accepts a constant string provided by the caller as a message security proof. This string is publicly visible in the verified contract code. By inputting this string, the attacker could execute arbitrary calldata arrays and freely steal funds. The victim's Safe wallet had added this problematic contract as a trusted Safe Module, allowing the contract to control any tokens within the Safe without requiring a signature. Squid's own router contract (0xce16...D666) has a different architecture and was unaffected. Squid users' funds, authorizations, and integrations are completely safe.Early public reports may have mentioned "SquidRouter" due to the contract verification name on Basescan. The accurate description should be: a third-party SquidRouterModule was attacked, not Squid's Router contract. This contract shares the name with Squid, but it is not Squid's code. Squid is continuously monitoring the situation and will provide updates if there are any significant changes.
according to Blockaid monitoring, it detected an ongoing attack targeting the SquidRouter module on the Ethereum and Base chains. Within approximately 2 hours, 86 Gnosis Safe wallets were drained of about $3 million in assets. All stolen tokens were swapped for DAI via a Uniswap V3 pool controlled by the attacker.