The Sandbox ecosystem has faced a serious security incident: attackers managed to exploit a vulnerability in the cross-chain bridge connecting the Base and BNB Smart Chain (BSC) networks. As a result of the attack, unbacked SAND tokens were minted, forcing the project team to take emergency measures to protect user assets.

Attack Details and Scale of Damage

Analysis of the incident shows that attackers intercepted LayerZero delegate rights through the approveAndCall function, allowing them to mint tokens in both networks. According to preliminary estimates, SAND worth approximately $49 billion was minted across more than 400 transactions. However, despite the astronomical figures, the actual damage to liquidity turned out to be minimal — less than 0.01% of the total SAND supply.

It is important to note that tokens on the Ethereum (ETH) and Polygon (POL) networks remained untouched, and user wallets were not compromised. This indicates that the attack was aimed solely at the cross-chain bridge mechanism, not directly at holders' funds.

Response from the Team and Exchanges

The Sandbox team promptly disabled the bridges between Base and BSC, blocking the ability to move or recover the minted tokens. The official statement emphasizes that SAND in these networks is now isolated and unavailable for transfer or withdrawal. Developers also warned users to refrain from any operations with SAND in these networks, as liquidity has been disrupted.

Korean crypto exchanges Bithumb and Upbit immediately suspended SAND deposits and withdrawals, citing suspicions of a security breach and local legislation on the protection of virtual asset holders' rights. Notably, Upbit even closed operations with the Ethereum network version of SAND, although the attack did not affect that network.

Analysis and Conclusions

This incident fits into the broader alarming trend of a rising number of attacks on the crypto sector. According to DefiLlama, there have been 17 hacks over the past month, and bridges have once again proven to be the industry's weakest link. The Sandbox team is preparing a network snapshot to compensate affected liquidity providers and promises to publish a detailed report.

My expert opinion: This case once again confirms that cross-chain bridges remain the primary target for hackers. Even with minimal actual damage, such attacks undermine trust in DeFi infrastructure and require a revision of security standards. Investors should closely monitor updates from the project team and avoid operations with tokens in the affected networks until full trust is restored.