The Sandbox has fixed a critical vulnerability: 14.9 billion fake SAND isolated

The team behind the metaverse The Sandbox has faced a serious challenge: an unknown attacker managed to generate 14.9 billion unbacked SAND tokens on the Base and BSC networks. For comparison, the total supply of the original asset on Ethereum is only 3 billion SAND, equivalent to approximately $140 million. The scale of the issuance is five times greater than the legitimate volume — this is an unprecedented case even for cross-chain exploits.
Threat Localization and Response Measures
Developers promptly blocked the cross-chain bridges and isolated the attacker's generated tokens on the original blockchains. Critically, user wallets were not affected — only 0.01% of the total SAND in circulation was impacted. This suggests that the vulnerability was related to the bridge's internal mechanisms, rather than a direct hack of user funds.
Nevertheless, the incident raises questions about the reliability of cross-chain solution architecture in gaming ecosystems. Even a temporary imbalance in issuance can create arbitrage opportunities and undermine trust in stablecoins and utility tokens. It remains unclear whether the fake SAND was used for trading before the block, but the fact of isolation on the initial networks minimizes potential damage to liquidity.
From my point of view, this case is another reminder that multi-chain expansion requires enhanced smart contract auditing and real-time issuance monitoring. The Sandbox chose the right strategy: rapid isolation and transparency. However, investors should pay closer attention to security updates in high-capitalization projects, as similar exploits could recur in less mature networks.