The Sandbox metaverse has faced a serious threat: attackers exploited a vulnerability in the cross-chain bridge for the SAND token, connecting the Base and BNB Smart Chain (BSC) networks. As a result of the attack, unbacked tokens were generated in both networks, which could have led to catastrophic consequences for the ecosystem.
In my assessment, the incident, detected by the analytics platform Blockaid, occurred after hackers intercepted LayerZero delegate rights through the approveAndCall function. This allowed them to mint a staggering volume of fake SAND — nominally around $49 billion across more than 400 transactions. Fortunately, the project team responded quickly and disabled the bridge, blocking the ability to move and recover the compromised tokens.
Scale of Damage and Market Reaction
Despite the impressive issuance figure, the actual damage turned out to be minimal. Developers estimated losses at less than 0.01% of the total SAND supply. Tokens on the Ethereum (ETH) and Polygon (POL) networks remained untouched, and user wallets were not hacked. This confirms that the attack targeted the bridge infrastructure, not end holders of assets.
Nevertheless, the market reacted immediately. Major South Korean exchanges Bithumb and Upbit suspended SAND deposits and withdrawals, citing suspicions of a security breach and local legislation on protecting virtual asset owners. Upbit even halted operations with the Ethereum network version of SAND, although The Sandbox claims that this network was not affected.
The Bridge — Achilles' Heel of DeFi
This incident is another link in a troubling chain of events. According to DefiLlama, there have been 17 hacks over the past month, and bridges continue to remain the industry's weakest link. The project has already warned holders about the illiquidity of tokens in the affected networks and is preparing a network snapshot for payouts to affected liquidity providers.
My analysis: Such attacks highlight the fundamental problem of trust in cross-chain infrastructure. Even with a quick response and minimal losses, the reputational damage and volatility caused by panic can prove more destructive than the exploit itself. Investors should closely monitor project security reports before placing capital in cross-chain protocols.