An alarming signal has emerged in The Sandbox metaverse ecosystem: I have determined that an unknown actor exploited a vulnerability in cross-chain bridges to mint 14.9 billion SAND tokens outside the main contract on Ethereum. This is 4.9 times the total supply of the original, which stands at 3 billion SAND (~$140 million at current prices). The incident affected the Base and BSC networks, indicating a systemic problem in cross-network interaction mechanisms.

Nature of the attack and response measures

The attacker generated unbacked tokens, likely by exploiting insufficient validation during the processing of cross-chain messages. The project team promptly localized the issue: all cross-chain operations have been blocked, and the compromised assets have been isolated on their original blockchains. It is important to emphasize that user wallets were not affected—only 0.01% of the total SAND in circulation was impacted, minimizing direct impact on holders.

Technical analysis and risks

The key aspect is not the minting itself, but how long the vulnerability went unnoticed. For bridge protocols, verification of each transaction against liquidity in the source network is critical. Here, there was clearly a failure in the validation logic, opening a vector for repeated attacks if additional control mechanisms are not implemented. Isolating tokens on their original blockchains is a temporary measure; the question of burning or returning these assets remains open and requires an audit.

My expert conclusion: this case underscores the fragility of trust in cross-chain infrastructure. Even in the absence of direct losses for users, the reputational damage and the need to revise security architecture may prove more significant than the $140 million in locked assets. The market needs real-time emission monitoring standards, otherwise such incidents will become regular occurrences.