The team behind The Sandbox metaverse promptly fixed a critical vulnerability that allowed an attacker to generate 14.9 billion unbacked SAND tokens on the Base and BSC networks. This is several times higher than the total supply of the original asset on Ethereum, which stands at just 3 billion SAND — roughly $140 million at the current exchange rate.
The essence of the incident and response measures
The issue lay in the cross-chain mechanism: the attacker exploited a flaw in the bridge logic to mint tokens on sidechains without real backing in the main network. Developers reacted instantly — they blocked all cross-chain operations and isolated the compromised assets on the original blockchains. This prevented further spread of fake SAND into the ecosystem.
It is important to emphasize: user wallets were not affected. According to the team's estimates, only 0.01% of the total SAND in circulation was impacted, making the incident more of a targeted glitch than a systemic crisis. Nevertheless, the very fact of minting 14.9 billion tokens is a warning sign for the industry, showing that even mature projects can have hidden weaknesses in cross-network infrastructure.
My view as an analyst: This is a classic example of how the complexity of multi-chain architecture becomes an attack vector. Although The Sandbox quickly contained the damage, investors should be more cautious about projects where liquidity is distributed across multiple networks — the risks here are often underestimated. For the team, this is a lesson: auditing cross-chain logic should be priority #1, otherwise the next incident could be far more extensive.