The Sandbox ecosystem has faced a serious security incident: attackers exploited a vulnerability in the SAND token cross-chain bridge between the Base and BNB Smart Chain networks. As a result of the attack, unbacked tokens were minted on both networks, requiring immediate intervention by the project team.
In my assessment, the scale of the minting was colossal — nominally, about $49 billion worth of SAND was created in over 400 transactions. However, the The Sandbox team promptly assessed the actual damage as minimal, amounting to less than 0.01% of the total SAND supply. It is important to emphasize: tokens on the Ethereum (ETH) and Polygon (POL) networks remained untouched, and user wallets were not compromised.
Attack mechanics and immediate response
Security analysts found that hackers intercepted LayerZero delegate rights through the approveAndCall function. This allowed them to manipulate the cross-chain transfer process and generate fake SAND. The The Sandbox team instantly disabled the bridges between Base and BSC, blocking the ability to move or recover the minted tokens.
"The attacker was able to mint unbacked SAND on the Base and BSC networks. We have disabled the bridges; SAND is now isolated on these networks and unavailable for transfer or withdrawal," project representatives stated.
Developers warned holders to avoid any operations with SAND on these networks, as the token's liquidity has been compromised. To compensate affected liquidity providers, a network snapshot from before the attack is being prepared. A full report on the incident will be published later.
Exchange reactions and systemic risks
Korean crypto exchanges reacted immediately: Bithumb suspended SAND deposits and withdrawals at 05:11 Moscow time, and Upbit followed suit a minute later. Both platforms cited suspicions of a security breach and local legislation on protecting virtual asset holders. Notably, Upbit also closed operations with the Ethereum network version of SAND, although The Sandbox assures that this network was not affected.
This incident fits into a worrying trend: according to DefiLlama, there have been 17 hacks in the past month, and bridges have once again proven to be the industry's weakest link. Although most attacks were minor, the vulnerability of cross-chain infrastructure remains a critical issue.
My expert conclusion: This case is a stark reminder that even large and long-established projects are not immune to smart contract errors. The Sandbox's prompt response deserves praise, but investors should reassess their risks when working with bridges. Until the industry implements more reliable verification mechanisms and multi-signature solutions for cross-chain operations, such attacks will continue to occur.