The Sandbox ecosystem has faced a serious security incident: attackers managed to compromise the cross-chain bridge connecting the Base and BNB Smart Chain networks and mint unbacked SAND tokens on both networks. This is a classic example of an attack on an inter-network gateway, which has recently become an increasingly favored target for hackers.

In my assessment, the vulnerability was exploited through the approveAndCall function of the LayerZero protocol. The attacker intercepted delegate rights, which allowed them to manipulate the cross-chain transfer process and generate tokens without corresponding backing. As a result, approximately $49 billion in nominal SAND was created across more than 400 transactions — a figure that immediately drew the attention of security analytics services.

Immediate Response and Asset Isolation

The Sandbox team acted swiftly: the bridge between Base and BSC was immediately disabled, blocking the ability to move and recover the compromised tokens. It is important to emphasize that the Ethereum network, where the bulk of SAND is held and which serves as the base for all bridges, remained untouched. User wallets were not hacked — the damage was limited solely to the minted "dummy" tokens in the two side networks.

The total damage is estimated at less than 0.01% of the total SAND supply, indicating that the project's core liquidity was not affected. However, the team warned holders against trading SAND on the Base and BSC networks until liquidity is fully restored. Developers are already preparing a network snapshot from before the attack for subsequent compensation to affected liquidity providers.

Exchanges and Broader Context

Korean giants Bithumb and Upbit promptly suspended SAND deposits and withdrawals, citing suspicions of a security breach and local legislation on protecting the rights of virtual asset holders. Notably, Upbit even halted operations with the Ethereum network version of SAND, although the attack did not affect it — this demonstrates the heightened caution of exchanges under current conditions.

This incident is just part of a worrying trend: over the past month, 17 hacks have been recorded in the industry, and bridges continue to remain the weakest link in DeFi infrastructure.

My expert conclusion: This case once again confirms that the security of cross-chain solutions is the Achilles' heel of the entire ecosystem. Even with minor financial damage, reputational costs and the temporary loss of trust in the project can prove far more serious. Investors should closely monitor The Sandbox updates and refrain from operations with SAND outside the main network until all restrictions are fully lifted.