The Sandbox metaverse team has revealed details of a large-scale attack in which an unknown attacker managed to generate 14.9 billion unbacked SAND tokens on the Base and BSC networks. This volume is five times greater than the total supply of the original asset on Ethereum, which amounts to only 3 billion SAND — at the current market price, this is equivalent to approximately $140 million.
During the rapid response, developers completely blocked cross-chain operations, preventing further spread of the fake tokens. A key step was isolating the attacker's funds on the source blockchains, which made it possible to contain the threat before it moved to the Ethereum mainnet.
Scale of damage and market reaction
It is important to emphasize that user wallets were not affected. According to official data, the incident impacted only 0.01% of the total SAND in circulation. This suggests that the attack targeted infrastructural weaknesses rather than end holders of the asset.
Nevertheless, the very fact that such a volume of unbacked tokens could be minted raises serious questions about the security of cross-chain bridges and liquidity management protocols. Incidents like this highlight the vulnerability of multi-chain ecosystems, where a single point of failure can lead to catastrophic consequences for trust in a project.
In my view, this case is a warning sign for the entire industry. Even with successful containment, the very existence of a vulnerability in the minting mechanisms calls into question the reliability of the smart contracts in use. Investors should closely monitor The Sandbox's further audits and public reports to assess how deeply the root cause has been addressed, rather than just its consequences.