Bridge exploits flood DeFi with fake tokens, real chaos
The gist
DeFi bridges minted billions in fake tokens, sparking real chaos with minimal actual theft but maximum systemic fallout.
What to know
- On August 22, 2026, The Sandbox’s bridge minted $49B in synthetic SAND on Base with just $675K actually stolen before the exploit was contained.
- Attackers across multiple bridges abused trust assumptions—not cryptography—to mint unbacked assets like SAND, syBTC, and rsETH, triggering lending crises and emergency shutdowns.
- Fake tokens quickly seeped into DeFi protocols, leaving Aave with $280M in bad debt and forcing governance interventions as TVL plummeted by billions.
Delegate Permissions Gone Rogue
A hijacked LayerZero delegate and a flawed approveAndCall function let attackers mint billions in unbacked SAND, exposing how a single contract misstep can override cross-chain trust.
What a bridge mint does became painfully clear in The Sandbox breach on August 22, 2026: the cross-chain system issued destination-chain SAND that was supposed to represent tokens locked elsewhere, but instead created synthetic balances with no matching collateral. FinanceFeeds reported that initial on-chain alerts showed more than 500 million SAND had been created without corresponding backing, and later that PeckShield identified about 14.9 billion SAND across two attacker-linked addresses, while Blockaid tied the unauthorized creation to compromised delegate permissions involving an approveAndCall function.
Crypto News showed why this was a bridge-layer minting vulnerability rather than a simple token bug: on Aug. 21 and 22, an attacker hijacked LayerZero delegate permissions and used the SAND omnichain fungible token contract’s approveAndCall function to gain effective administrative standing over endpoint configuration, enabling minting on Base without any corresponding token lock on Ethereum. Blockaid flagged $49 billion in face-value SAND across more than 400 transactions, and within five hours 703 minting events reached 173 addresses before, 24 minutes after minting stopped, at 05:09:19 UTC, The Sandbox’s multisig wallet zeroed out the trusted peer settings for Base and BNB Smart Chain, severing the cross-chain link that the attacker had exploited.
Assumed Trust, Real Fallout
Bridge contracts trusted forged cross-chain messages and faulty logic, allowing attackers to mint and withdraw synthetic assets without breaking cryptography—turning protocol assumptions into massive liabilities.
The August-September wave showed bridge attackers exploiting what destination contracts assume to be true, not breaking cryptography. As shattered.io put it, “On August 19, 2026, an attacker drained 191,156 USDC from Allbridge’s CCTP router on Base by redeeming a Circle-style message that moved no real money,” while the Coreum-XRPL bridge’s verification layer let 94 separate withdrawal calls drain the bridge in under two hours without flagging the abnormal velocity. These cases show how replay, verification, and permission-flow failures can turn forged cross-chain claims into real withdrawals.
The same pattern appeared in voucher forwarding and synthetic minting. Nomic’s forwarding logic let an attacker double-spend Bitcoin vouchers into Osmosis, and a single BTC deposit produced more than one valid voucher, minting roughly 40.65 BTC worth of unbacked nBTC. Symbiosis showed the same trust gap on September 11, 2026, when an attacker sent doctored reports across eight bridge transactions and created an Unbacked Cross-Chain Mint; shattered.io later said Symbiosis mis-parsed a Bitcoin transaction and minted roughly 46.1 billion units of fake syBTC, showing how delegate permission flaws, logic bugs, and risky trust assumptions amplify systemic risk across DeFi protocols.
Billions Minted, Thousands Stolen
Wildly inflated on-chain balances masked the reality that attackers could only extract a fraction of the fake tokens’ value before protocols slammed the brakes.
The bridge incidents showed enormous headline losses on paper, but the cash actually taken was far smaller. Startup Fortune reported that Blockaid valued the fake SAND mint at $49 billion across more than 400 transactions on Base and BNB Smart Chain, while the real loss was about $675,000, or roughly 14.75 million SAND, before containment. On August 22, 2026, The Sandbox halted bridging between Base and BNB Smart Chain and confirmed Ethereum and Polygon were unaffected.
Symbiosis showed the same gap between paper damage and realized theft. Shattered.io said that on September 11, 2026 at roughly 04:28 UTC, an attacker exploited BridgeV2 and minted approximately 2^62 raw units of syBTC, which Blockaid valued at $46.1 billion, but the attacker walked away with $336,000 because the tokens still had to pass through real liquidity pools. After Blockaid detected the abnormal mint, Symbiosis halted BTC routing within the same window, and by September 12 the team said it had recovered about 15 BTC into a team-controlled multisig and offered a 20% bounty.
Unbacked Tokens, Systemic Shock
DeFi protocols treated fake bridge tokens as real collateral, cascading bad debt and liquidity crises across lending markets before governance could intervene.
What made these bridge exploits systemically dangerous was not just false minting at the bridge, but the speed with which downstream protocols treated those tokens as real balance-sheet assets. Bankless described how attackers “exploited Kelp Dao's layer 0 powered bridge to create 116,000 RS ETH tokens… without any backing… They then deposited those tokens into AAVE v3… to borrow $236 million in wheat… leaving aave with about $280 million in bad debt,” turning a bridge failure into a lending solvency problem the moment unbacked collateral entered a major money market.
Once that bad collateral was inside lending and liquidity rails, the damage spread faster than governance could react: after “External nodes were DDoS-ed into silence,” “the remaining compromised nodes signed off on a forged cross-chain message, and the bridge minted 116,500 unbacked rsETH,” which was then used “as collateral,” and “The stolen rsETH went straight into Aave as collateral, borrowed real WETH against itself.” Cryptonews.net reported “Aave’s total value locked dropped $6.28 billion in 48 hours,” while Bankless said “some panic withdrawals have followed $5 billion in ETH outflows,” Aave paused markets across chains, and “now it's got $180 million in bad debt.” In the aftermath, “the Arbitrum Security Council recovered $70 million in ETH… by Dao governance vote… opening up Pandora's box about what immutability means on layer twos.”

