A large-scale incident in The Sandbox ecosystem has exposed a critical vulnerability in cross-chain bridge infrastructure. Attackers managed to compromise a delegate of the LayerZero protocol through the approveAndCall function, allowing them to mint unbacked SAND tokens on the Base and BNB Smart Chain networks. This involves a nominal volume of approximately $49 billion, distributed across more than 400 transactions.
Immediate response and asset isolation
The Sandbox team acted swiftly: the bridge between Base and BSC was disabled, and the minted tokens were blocked from transfers and withdrawals. According to developer estimates, the actual damage amounted to less than 0.01% of the total SAND supply. It is important to emphasize that tokens on the Ethereum and Polygon networks remained untouched, and user wallets were not compromised.
Nevertheless, SAND holders in the affected networks are strongly advised to refrain from any operations with the asset, as its liquidity has been disrupted. A network snapshot taken before the attack is being prepared for payouts to affected liquidity providers. The team promises to publish a full report on the incident at a later date.
Exchange response and systemic context
Korean crypto exchanges Bithumb and Upbit immediately suspended SAND deposits and withdrawals, citing suspected security breaches and local legislation on protecting virtual asset holders' rights. Notably, Upbit also halted operations with the Ethereum version of SAND, even though the attack did not affect it.
This case is another link in a troubling trend: over the past month, the industry has recorded 17 hacks, and bridges have once again proven to be the weakest link. Attacks on cross-chain protocols continue to dominate the list of the industry's largest losses.
My analysis: Although the nominal issuance volume looks alarming, the actual damage turned out to be minimal thanks to the team's quick response. However, this incident once again demonstrates that cross-chain infrastructure security remains the Achilles' heel of DeFi. Investors should keep in mind that even major projects with years of history are not immune to such exploits, and diversification across networks does not always mean diversification of risks.