A serious incident occurred in The Sandbox metaverse ecosystem that could have been a catastrophe for the market if not for the team's prompt actions. I managed to determine that an unknown attacker exploited a vulnerability in the project's cross-chain mechanisms and minted 14.9 billion unbacked SAND tokens on the Base and BSC networks. For context: the total supply of the original asset on Ethereum is only 3 billion SAND, equivalent to approximately $140 million at current prices.
This case highlights the fragility of trust in multi-chain infrastructure. If the minted tokens had leaked onto major decentralized exchanges, the consequences for SAND's liquidity and price could have been devastating. The Sandbox developers, recognizing the scale of the threat, immediately blocked all cross-chain operations and isolated the attacker's tokens on the original blockchains. This prevented further spread of the fake assets.
It is important to note that, in my assessment, user wallets were not affected. The damage impacted only 0.01% of the total SAND in circulation, indicating the targeted nature of the attack. However, the very fact that such a vulnerability existed raises questions about the security of cross-chain bridge architecture in high-capitalization projects.
In my view, the incident at The Sandbox is a warning sign for the entire industry. Many teams rely on complex inter-network protocols but do not always devote sufficient attention to auditing and monitoring minting mechanisms. Although the containment of the problem was successful, the market must learn a lesson: the security of cross-chain operations requires continuous improvement, not just reactive measures after a hack.