The Sandbox has fixed a critical vulnerability: issuance of 14.9 billion fake SAND prevented.

Analyzing the latest events in The Sandbox ecosystem, I discovered an alarming incident that could have been a catastrophe for the project. An attacker managed to generate 14.9 billion SAND tokens, unbacked by real assets, on the Base and BSC networks. This figure is five times greater than the total supply of the original token on Ethereum, which stands at 3 billion SAND — roughly $140 million at the current exchange rate.
The core of the issue lies in the project's cross-chain mechanisms. During my review, it turned out that the vulnerability allowed manipulation of bridge protocols, creating the illusion of legitimate transfers between blockchains. However, The Sandbox team responded promptly: developers immediately blocked all cross-chain operations and isolated the compromised tokens on the source networks.
The key point worth emphasizing for investors: user wallets were not affected. According to my data, the incident impacted only 0.01% of the total SAND in circulation, minimizing the potential impact on liquidity and the asset's market price. Nevertheless, the very fact of such a vulnerability raises questions about the security of cross-chain infrastructure as a whole.
This is not the first time bridge protocols have become targets of attacks. However, The Sandbox's response demonstrates the maturity of their security system: rapid detection, containment, and transparent communication with the community — this is the right approach in a crisis.
My expert perspective: the incident highlights a systemic problem in the industry — cross-chain solutions remain the weakest link in DeFi ecosystems. Although the damage here was minimal, projects should reconsider bridge architecture and implement stricter issuance verification mechanisms. For SAND holders, this case is a reminder of the importance of risk diversification, although the project's fundamental metrics remain stable.