An incident occurred in The Sandbox ecosystem that once again exposed vulnerabilities in cross-chain infrastructure. Attackers exploited a breach in the bridge for the SAND token connecting the Base and BNB Smart Chain networks, issuing unbacked coins in both networks. According to estimates, the nominal issuance volume amounted to approximately $49 million, distributed across more than 400 transactions.
Attack on the LayerZero delegate
Analysis shows that the attackers intercepted the rights of the LayerZero protocol delegate through the approveAndCall function. This allowed them to manipulate the bridge and generate phantom SAND without corresponding backing. It is important to emphasize: tokens in the Ethereum and Polygon networks remained untouched, and user wallets were not compromised. According to preliminary estimates from the team, the damage does not exceed 0.01% of the total SAND supply, indicating the targeted nature of the attack.
Response from the team and exchanges
The Sandbox team acted swiftly: the bridge between Base and BSC was disabled, and the issued tokens were blocked from transfer and withdrawal. The official statement emphasizes that SAND in these networks is now isolated, and holders are strongly advised to refrain from any operations with the asset until liquidity is restored. Developers are preparing a network snapshot from the moment before the attack to compensate affected liquidity providers, and a detailed report on the incident will be published later.
Korean exchanges Bithumb and Upbit immediately suspended deposits and withdrawals of SAND, citing suspicions of a security breach and local legislation on the protection of virtual asset holders. Notably, Upbit even closed operations with the Ethereum network version of SAND, although the attack did not affect that network — a clearly precautionary measure, but one that sends a signal to the market.
Bridge vulnerability — a systemic problem
This case fits into an alarming trend: according to DefiLlama, 17 hacks have occurred over the past month, and bridges have once again proven to be the industry's weakest link. Small but frequent attacks on cross-chain protocols undermine trust in DeFi infrastructure.
My comment: The Sandbox incident is yet another reminder that cross-chain bridges remain the primary entry point for hackers. Even with a quick team response and minimal damage, reputational costs and temporary asset isolation create significant risks for holders. The market has long needed to move from targeted patches to standardized security protocols for cross-chain operations.