The Sandbox metaverse has faced a serious security threat: attackers exploited a vulnerability in the cross-chain bridge for the SAND token between the Base and BNB Smart Chain networks. As a result of the attack, unbacked tokens were minted in both networks, jeopardizing the integrity of the asset.

Scale of the attack and team response

In my assessment, the incident was promptly contained. The damage amounted to less than 0.01% of the total SAND supply, indicating that the attacker did not manage to deliver a critical blow. It is important to note that tokens on the Ethereum (ETH) and Polygon (POL) networks remained untouched, and user wallets were not compromised.

Security analysts identified that the attack was carried out through the interception of LayerZero delegate rights using the approveAndCall function. This allowed the hacker to mint SAND worth approximately $49 billion across more than 400 transactions, highlighting the severity of the breach in the bridge protocol.

Emergency measures and isolation

The Sandbox team immediately disabled the bridges between Base and BSC, blocking the ability to move or recover the minted tokens. This led to the complete isolation of SAND in these networks — it is now unavailable for transfer or withdrawal. Project representatives warned holders against performing any operations with SAND in these networks, as the token's liquidity has been disrupted.

To compensate for the damage, developers are preparing a network snapshot from the moment before the attack, which will allow restoring a fair balance for affected liquidity providers. A full report on the incident will be published later, but it is already clear that the team is acting proactively.

Exchange response and market context

Korean exchanges Bithumb and Upbit immediately suspended deposits and withdrawals of SAND, citing suspicions of a security breach and local legislation on virtual asset protection. Upbit also halted operations with the Ethereum network version of SAND, although The Sandbox claims that this network was not affected.

This incident is just part of a worrying trend. According to DefiLlama, there have been 17 hacks in the past month, and bridges have once again proven to be the industry's weakest link. Bridge infrastructure remains a primary target for hackers, and this case is yet another reminder of the need to strengthen auditing and monitoring.

My expert opinion: Vulnerabilities in cross-chain bridges are a systemic issue that requires not just point fixes but a revision of security architecture. Although the damage here is limited, such attacks undermine trust in DeFi infrastructure. Investors should be especially cautious with assets moving between networks until the industry develops more robust standards.