The Sandbox metaverse has faced a serious security challenge: an unknown attacker managed to generate 14.9 billion SAND tokens, not backed by real assets, on the Base and BSC networks. This is a colossal figure that is several times higher than the legitimate issuance of the original token on Ethereum — just 3 billion SAND, equivalent to approximately $140 million at the current exchange rate.
Threat Containment: The Team's Rapid Response
The project's developers responded promptly to the incident. Cross-chain bridges and related operations were immediately blocked, and the attacker's suspicious tokens were isolated in the original blockchains. This prevented further spread of the phantom assets across the ecosystem. It is important to emphasize: user wallets were not affected, and the damage impacted only 0.01% of the total SAND in circulation.
From a technical standpoint, this case demonstrates the vulnerability of cross-network protocols. Token issuance in sidechains or L2 solutions requires flawless verification, and the slightest flaw in bridge logic can lead to the creation of unbacked assets. In this case, the scale of the attack — 14.9 billion — is almost five times the entire legitimate supply of SAND, indicating a targeted search for a breach in the system.
For SAND holders, this is an alarming signal, although the team assures the safety of funds. The incident underscores the need for stricter audits of cross-chain infrastructure and the implementation of real-time mechanisms to track anomalous issuance. In my analysis, such events often become a catalyst for reassessing trust in a project, so The Sandbox faces a long road to restoring its reputation.