The Sandbox team faced a serious challenge: an unknown attacker managed to generate 14.9 billion unbacked SAND tokens on the Base and BSC networks. This is almost five times the entire legitimate supply of the asset on Ethereum, which stands at 3 billion SAND — approximately $140 million at the current exchange rate.
The incident was promptly contained. Developers blocked cross-chain bridges and isolated the compromised tokens on their original blockchains, preventing their movement to other ecosystems. It is important to emphasize: user wallets were not affected, and the share of affected coins in total circulation was only 0.01%.
Technical details and lessons for the industry
The very fact of issuing such a volume indicates a critical vulnerability in the logic of smart contracts for cross-chain interactions. If the attacker had managed to convert the fake SAND into liquid assets or withdraw them to centralized exchanges, the consequences could have been catastrophic — from a price collapse to a loss of trust in the project.
This case is yet another reminder that multi-chain architecture remains the most fragile point in DeFi. Bridges and inter-network exchange mechanisms require not just audits, but constant stress testing for unauthorized issuance. The team's response was fast and competent, but the very existence of such a security hole raises questions about the quality of internal controls.
My assessment: the incident is contained, but trust in The Sandbox's cross-chain solutions has been undermined. Investors should closely monitor further security reports before increasing their positions in SAND. In current market conditions, even a small shadow on a project's reputation can cost more than $140 million in backing.