The Sandbox ecosystem has faced a serious security challenge: attackers managed to exploit a vulnerability in the SAND token cross-chain bridge between the Base and BNB Smart Chain networks. As a result of the attack, unbacked coins were generated in both networks, threatening the integrity of the project's tokenomics.
In my assessment, the incident was detected and contained promptly. According to the team's preliminary calculations, the damage amounted to less than 0.01% of the total SAND supply. This indicates that, although the breach was critical, the scale of its exploitation was limited. It is important to emphasize: tokens on the Ethereum (ETH) and Polygon (POL) networks remained untouched, and user wallets were not compromised.
Attack mechanics and team response
Security analysts identified that the attacker intercepted LayerZero delegate rights through the approveAndCall function, allowing them to mint fake SAND. During the attack, tokens worth approximately $49 billion were created in more than 400 transactions — a figure that is shocking at first glance but, fortunately, did not lead to real financial losses for holders.
The Sandbox team immediately disabled the bridge between Base and BSC, effectively isolating the fake tokens and blocking their movement or withdrawal. The official statement emphasizes: SAND in these networks is now unavailable for trading, and liquidity has been disrupted. Users are strongly advised to refrain from any operations with the token in these networks until full recovery.
Exchange response and broader context
South Korean exchanges Bithumb and Upbit promptly suspended SAND deposits and withdrawals, citing suspicions of a security breach and local legislation on protecting virtual asset holders' rights. Notably, Upbit even halted operations with the Ethereum network version of SAND, although that network was not affected by the attack.
This incident is another link in a troubling chain of events. According to DefiLlama, there have been 17 hacks in the past month, and bridges have once again proven to be the weakest link in DeFi infrastructure. Developers are preparing a network snapshot to compensate affected liquidity providers, and a detailed report on the incident is promised to be published later.
My conclusion: The attack on The Sandbox highlights the systemic vulnerability of cross-chain solutions. Even with a quick team response, trust in bridges is undermined, and investors should reassess their risks when dealing with multi-chain assets. Transparency and speed of recovery will be key factors here for retaining the community.