The Sandbox metaverse has faced a serious security incident: attackers exploited a vulnerability in the SAND token cross-chain bridge between the Base and BNB Smart Chain (BSC) networks. As a result of the attack, unbacked tokens were issued in both networks, threatening the integrity of the entire project ecosystem.
Scale of the attack and immediate response
According to my analysis, the incident was detected by the analytics platform Blockaid early in the morning. The attackers intercepted LayerZero delegate rights through the approveAndCall function, allowing them to mint SAND worth approximately $49 billion in more than 400 transactions. This is a colossal figure, hundreds of times exceeding the token's real market capitalization, yet the project team quickly assessed the actual damage as minimal—less than 0.01% of the total SAND supply.
Key point: tokens in the Ethereum (ETH) and Polygon (POL) networks remained untouched, and user wallets were not compromised. This indicates that the attack was aimed specifically at the cross-chain interaction mechanism, not at user assets.
Emergency measures and token isolation
The Sandbox team acted decisively: the bridge between Base and BSC was immediately disabled, blocking the ability to move or recover the compromised tokens. The official statement emphasizes that SAND in these networks is now isolated and unavailable for transfer or withdrawal. This is a standard but necessary measure to prevent further spread of fake assets.
The developers also warned holders against buying, selling, or trading SAND in the affected networks, as liquidity has been disrupted. To compensate affected liquidity providers, a network snapshot from before the attack is being prepared, and a detailed report on the incident will be published later.
Exchange response and broader context
Korean exchanges Bithumb and Upbit promptly suspended SAND deposits and withdrawals, citing suspicions of a security breach and local legislation on protecting virtual asset holders. Notably, Upbit even closed operations for the Ethereum network version of SAND, although The Sandbox claims this network was not affected. This is a precautionary step, though understandable amid uncertainty.
This incident is another link in a troubling chain of events. According to DefiLlama, there have been 17 hacks in the past month, and bridges have once again proven to be the industry's weakest link. This is a systemic problem requiring more radical solutions in cross-chain protocol security.
My conclusion: Although the damage turned out to be minimal, the very fact of a successful attack on the bridge via LayerZero raises questions about the reliability of delegated governance mechanisms. Projects should reconsider their security protocols, especially regarding control over administrative functions, before entrusting them with billion-dollar liquidity volumes.