In less than a day, The Sandbox faced a serious incident in its cross-chain infrastructure. Attackers managed to compromise the bridge connecting the Base and BNB Smart Chain networks and minted a significant amount of unbacked SAND tokens on both networks. This is a classic example of an attack on a cross-chain bridge, which has recently become an increasingly favored target for hackers.

In my estimation, the scale of the issuance was substantial: nominally, about $49 billion in fake SAND was minted, distributed across more than 400 transactions. However, to the team's credit, the real damage to the ecosystem turned out to be minimal—less than 0.01% of the total token supply. A key factor was that the attackers did not touch liquidity pools on Ethereum and Polygon, nor did they compromise user wallets. This indicates that the attack was aimed specifically at the bridge mechanism, not at end holders of assets.

Mechanics of the hack and the team's response

Analysis shows that the hackers intercepted control over the LayerZero delegate through the approveAndCall function. This allowed them to manipulate the cross-chain transfer process and generate tokens without corresponding backing on the source network. The Sandbox team responded promptly: the bridge between Base and BSC was completely disabled, and the minted tokens were frozen and isolated. They can no longer be moved or withdrawn, preventing further spread of the fake assets.

Developers have already warned holders against any operations with SAND on these networks, emphasizing the liquidity disruption. A compensation mechanism is being prepared for affected liquidity providers based on a network snapshot taken before the attack. A full report on the incident will be published later, but it is already clear that the team has brought the situation under control.

Market reaction and the broader picture

Korean exchanges, including Bithumb and Upbit, immediately suspended deposits and withdrawals of SAND, citing suspicions of a security breach and local legislation on protecting the rights of virtual asset holders. Notably, Upbit also halted operations with the Ethereum version of SAND, despite the team's assurances that this network was not affected. This demonstrates the heightened caution of exchanges amid uncertainty.

This incident is just another link in a troubling trend. According to my data, there have been 17 hacks in the industry over the past month, and bridges continue to be the most vulnerable link in DeFi infrastructure. Attacks on cross-chain protocols are becoming increasingly sophisticated, and this case is a stark reminder that even established projects are not immune to code errors. Investors should be more careful with assets moved through bridges and keep an eye on security updates from teams.

My expert opinion: although the damage turned out to be limited, the very fact of a successful attack on The Sandbox bridge undermines trust in cross-chain solutions. The market needs stricter audit and monitoring standards for such critical infrastructure components; otherwise, we will see similar incidents repeated with more serious consequences.