In less than a day, The Sandbox team repelled a coordinated attack on its cross-chain bridge infrastructure. The attackers managed to compromise a LayerZero delegate through the approveAndCall function and mint unbacked SAND tokens on the Base and BNB Smart Chain networks. This is a classic attack on trust in inter-network routing, and it once again exposes the vulnerability of DeFi bridges as a single point of failure.

In my estimation, the scale of the minting was significant: nominally, about $49 billion in fake SAND was issued, distributed across more than 400 transactions. However, the actual damage to holders is minimal — the team estimates it at less than 0.01% of the total supply. The key point: the SAND pool on the Ethereum network, which serves as collateral for all bridges, remained untouched, and user wallets were not compromised.

Project response: isolation and preventive measures

The developers promptly disabled the bridge between Base and BSC, effectively freezing the movement and recovery of the minted tokens. Currently, SAND in these networks is isolated and unavailable for withdrawal or trading. The Sandbox team has already warned holders: buying, selling, or exchanging SAND in these networks is now extremely risky due to disrupted liquidity.

To compensate liquidity providers, a network snapshot is being prepared for the moment before the attack — this is a standard but important procedure that will allow restoring a fair balance. A full report on the incident will be published later, and I expect it to shed light on the specific exploitation vector.

Korean exchanges on alert

The market reaction was swift. Bithumb suspended SAND deposits and withdrawals at 05:11 Moscow time, and Upbit followed suit a minute later, citing suspicions of a security breach and local legislation on protecting virtual asset holders' rights. Notably, Upbit even closed operations with the Ethereum network version of SAND, although The Sandbox claims this network was not affected. This is over-caution, but under current conditions, it is justified.

The incident fits into an alarming trend: according to DefiLlama, there have been 17 hacks in the past month, and bridges have once again proven to be the industry's weakest link. While The Sandbox team acted competently, minimizing the consequences, this case is yet another reminder: the security of cross-chain solutions requires not point patches, but a fundamental rethinking of the trust architecture.

My expert opinion: the attack on the LayerZero delegate is a signal for the entire industry. Even major projects with strong teams are vulnerable if they rely on third-party bridges without deep access-control audits. Investors should reassess their risks when dealing with cross-chain assets, and developers should accelerate the adoption of more reliable verification mechanisms.