The Sandbox infrastructure came under a targeted attack, but the project team managed to quickly contain the threat and prevent large-scale financial losses. The attackers exploited a vulnerability in the cross-chain bridge connecting the Base and BNB Smart Chain networks, allowing them to mint unbacked SAND tokens in both networks.
In my assessment, the incident was detected at an early stage thanks to the vigilance of analytics services. The attack occurred through the interception of LayerZero delegate rights using the approveAndCall function. As a result, SAND worth approximately $49 billion was minted across more than 400 transactions—a figure that looks alarming but, fortunately, did not lead to a real catastrophe.
Scale of Damage and Team Response
The damage inflicted on the ecosystem turned out to be minimal—less than 0.01% of the total SAND supply. Tokens locked in the Ethereum (ETH) and Polygon (POL) networks remained untouched, and user wallets were not compromised. This is an important signal: the attack targeted infrastructure, not end holders of assets.
The Sandbox team immediately disabled the bridge between Base and BSC, effectively isolating the minted tokens. SAND in these networks is now unavailable for transfer or withdrawal, preventing further spread of the fake assets. However, the liquidity of these tokens has been disrupted, and the team warns users against trading SAND in these networks until the situation is fully resolved.
Exchange Response and Broader Context
Korean cryptocurrency exchanges Bithumb and Upbit promptly suspended deposits and withdrawals of SAND, citing suspicions of a security breach and local legislation on protecting virtual asset holders' rights. Notably, Upbit even suspended operations with the Ethereum version of SAND, although the attack did not affect it—this demonstrates a conservative approach to risk management.
This incident is just part of a troubling trend. According to my data, the industry saw 17 hacks in a month, and bridges once again proved to be the weakest link. Attacks on cross-chain infrastructure are becoming a systemic problem that requires a reassessment of security approaches.
My conclusion: although the damage turned out to be minimal, this case underscores the critical importance of auditing and monitoring bridges. Investors should be cautious with assets in networks where incidents have recently occurred and wait for the team's official report on the details of the attack.