The Sandbox metaverse has faced a serious security challenge: an unknown actor managed to mint 14.9 billion unbacked SAND tokens on the Base and BSC networks. This volume is several times larger than the total supply of the original asset on Ethereum, which amounts to only 3 billion SAND — approximately $140 million at the current exchange rate. The scale of the attack is obvious: the attacker effectively created five times more tokens than legitimately exist.
Rapid response and threat isolation
The project's developers acted quickly: cross-chain operations were blocked, and the attacker's tokens were isolated on the original blockchains. This prevented further spread of the fake assets. It is important to emphasize that user wallets were not affected — the incident impacted only 0.01% of SAND in circulation, indicating a targeted attack rather than a systemic failure.
Nevertheless, the very fact of such minting raises questions about the reliability of cross-chain bridges and token verification mechanisms. If the attacker was able to generate such a volume, it means there is a fundamental breach in smart contract logic or in the inter-network interaction process. Although the team has localized the issue, investors should closely monitor further audits and clarifications.
My analysis: This case is yet another reminder that cross-chain infrastructure remains the most vulnerable link in the DeFi ecosystem. Even with a rapid response, reputational damage can be more significant than financial losses. I recommend market participants reassess their risks when working with bridges and temporarily refrain from operations with SAND on Base and BSC until full trust is restored.