The Sandbox metaverse faced a serious security threat that was promptly neutralized. Attackers exploited a vulnerability in the cross-chain bridge for the SAND token, connecting the Base and BNB Smart Chain (BSC) networks, to mint unbacked coins in massive quantities. This incident once again highlights how critical the security of cross-chain bridges is for the entire DeFi ecosystem.
Scale of the Attack and Rapid Response
During the exploit, a colossal amount of SAND was generated — worth approximately $49 billion, distributed across more than 400 transactions. Security analysts identified that the attacker intercepted LayerZero delegate rights through the approveAndCall function, allowing them to mint tokens without corresponding backing. Despite the impressive figure, The Sandbox team assessed the actual damage as minimal — less than 0.01% of the total SAND supply.
The key point was that SAND tokens locked on the Ethereum network, which serve as backing for all bridges, remained untouched. The project's critical infrastructure was not compromised, and user wallets were not hacked. This indicates that the attack targeted the minting mechanism rather than direct theft of funds.
Bridge Shutdown and Precautionary Measures
In response to the incident, The Sandbox team immediately disabled the bridge between Base and BSC. This blocked the ability to move and recover the minted fake tokens. In an official statement, developers emphasized that SAND in these networks is now isolated and unavailable for transfer or withdrawal. Holders are strongly advised to refrain from any operations with SAND on Base and BSC until liquidity is fully restored.
To compensate liquidity providers who may incur losses, a network snapshot taken before the attack is being prepared. The team promises to publish a detailed report of what happened in the near future. This is the right step to restore trust, but the incident itself clearly demonstrates that even major projects are not immune to such attacks.
Market Reaction and the Bigger Picture
Korean exchanges Bithumb and Upbit promptly suspended SAND deposits and withdrawals, citing suspicions of a security breach and local user protection legislation. Upbit even halted operations with the Ethereum network version of SAND, although The Sandbox assures that this network was not affected by the attack.
This case fits into a worrying trend: according to DefiLlama, there have been 17 hacks in the past month, and bridges have once again proven to be the industry's weakest link. Vulnerabilities in cross-chain protocols continue to be a primary target for attackers, requiring developers to exercise heightened vigilance and code auditing.
My take: Although The Sandbox team acted quickly and decisively, this incident is yet another reminder of the systemic risks of cross-chain infrastructure. Investors should closely monitor the project's further reports, and the industry as a whole should seriously reconsider approaches to bridge security, which remains the most vulnerable link in the ecosystem.