High Smart contract exploit Source: DeFiHackLabs

Add PoC: SandboxOFT LayerZero delegate hijack via approveAndCall (10M…

A Proof of Concept (PoC) demonstrates a delegate hijack vulnerability in SandboxOFT LayerZero's approveAndCall function, potentially allowing for an unbacked mint of 10 million SAND tokens.

Estimated loss
$10,000,000
Protocols
SandboxOFT, LayerZero
Confidence
High
First seen
23 Aug 2026, 03:31 UTC

Read the original report ↗ (opens in a new tab)