The Sandbox ecosystem has faced a serious challenge: I have managed to establish that an attacker exploited a vulnerability in the project's cross-chain bridges and minted a colossal 14.9 billion unbacked SAND tokens on the Base and BSC networks. For comparison, the total supply of the original asset on Ethereum is only 3 billion SAND, which is equivalent to approximately $140 million at current market prices. The numbers speak for themselves: the volume of fake issuance is five times greater than the legitimate supply, which could have led to a catastrophic devaluation of the asset.
Threat Localization: The Team's Prompt Measures
The project's developers acted professionally, promptly blocking all cross-chain operations and isolating the attacker's tokens on the original blockchains. This made it possible to prevent the further spread of unbacked assets to other networks. A key point worth emphasizing: user wallets were not affected during the incident. According to my data, only 0.01% of the total SAND in circulation was impacted — a microscopic fraction, which indicates a high level of protection for the core infrastructure.
Nevertheless, the very fact of such an attack exposes a systemic problem of trust in cross-chain solutions. While the Sandbox team demonstrates competent crisis management, investors should reconsider the risks associated with bridge protocols. I have repeatedly warned about the fragility of such mechanisms, and this case is yet another confirmation that security in DeFi requires constant vigilance and multi-layered protection.
At the moment, the situation is under control, but the question of the attacker's motivation and the potential consequences for the project's reputation remains open. I recommend keeping your finger on the pulse and monitoring further updates from the team, as such incidents often signal deeper architectural flaws that require a fundamental audit.