The team behind The Sandbox metaverse has successfully neutralized a critical vulnerability that allowed an attacker to generate 14.9 billion unbacked SAND tokens on the Base and BSC networks. This is an extraordinary case, given that the total supply of the original asset on Ethereum is only 3 billion SAND — meaning the attacker created five times more coins than legitimately exist.
Scale and Consequences of the Incident
The market value of the legitimate issuance is estimated at approximately $140 million, making the attack particularly audacious: the monetary value of the fabricated tokens would potentially have exceeded the entire project's market capitalization. However, the developers acted swiftly — they blocked cross-chain operations and isolated the attacker's tokens on the source blockchains, preventing their movement to other ecosystems.
It is important to emphasize: user wallets were not affected. According to the team's estimates, the damage affected only 0.01% of the total SAND in circulation — a microscopic share that should not cause panic among holders. Nevertheless, the very fact of such a vulnerability in cross-chain bridge mechanisms raises questions about the project's security architecture.
My Analysis of the Situation
This incident is yet another reminder that cross-chain bridges remain the most fragile point of DeFi infrastructure. Even with rapid containment, the very possibility of minting 14.9 billion tokens points to systemic gaps in cross-chain message validation. For The Sandbox, this is a reputational blow, but the team's competent actions — isolation and blocking — minimized financial losses. Investors should pay closer attention to projects' security audits, especially in the metaverse sector, where liquidity and trust are key assets.