In less than a day, the The Sandbox team neutralized a critical vulnerability in the SAND token cross-chain bridge connecting the Base and BNB Smart Chain networks. The attacker, exploiting a flaw in the LayerZero delegation function, managed to mint unbacked coins in both networks, threatening the integrity of the entire ecosystem.
In my assessment, this incident is another link in the chain of attacks on cross-chain bridges, which over the past month have shown alarming statistics: 17 hacks, mostly small but systemic. The problem lies not in the blockchains themselves, but in trusted intermediaries—bridges—which become a point of failure for entire ecosystems.
Attack Mechanics and Scale of Damage
Security analysts recorded anomalous activity early in the morning: through the approveAndCall function, the attacker intercepted control over the LayerZero delegate and issued SAND worth approximately $49 billion in more than 400 transactions. However, the actual damage turned out to be minimal—less than 0.01% of the total token supply. The Ethereum and Polygon networks, where the main SAND liquidity is held, remained untouched, and user wallets were not compromised.
The The Sandbox team promptly disabled the bridge between Base and BSC, blocking the ability to move and recover compromised tokens. This is a temporary solution, but it prevented further spread of fake coins. Developers are already preparing a network snapshot from before the attack to compensate liquidity providers.
Market and Exchange Reaction
South Korean giants Bithumb and Upbit immediately suspended SAND deposits and withdrawals, citing suspicions of a security breach and local virtual asset protection legislation. Notably, Upbit even halted operations with the Ethereum version of SAND, although The Sandbox confirms that this network was not affected.
Token holders on the Base and BSC networks are now strongly advised against performing any operations with SAND—liquidity there is disrupted, and trading could lead to unpredictable consequences. The team promises to publish a detailed report on the incident shortly.
My verdict: this incident is a stark reminder that even established projects with years of history are vulnerable to the complexity of cross-chain architecture. Investors should reconsider their strategy of storing assets on bridges and favor native networks until the industry develops unified security standards for cross-chain interactions.