The Sandbox ecosystem has faced a serious security threat: an attacker managed to compromise the cross-chain bridge for the SAND token between the Base and BNB Smart Chain (BSC) networks. As a result of the attack, the hacker issued unbacked tokens in both networks, but the project team responded promptly and fixed the vulnerability.
Incident details and scale of damage
The analytics platform Blockaid recorded anomalous activity early in the morning. According to my data, the attacker intercepted LayerZero delegate rights through the approveAndCall function, which allowed them to manipulate the bridge contract. As a result, SAND worth approximately $49 billion was minted in more than 400 transactions.
Despite the alarming figures, the Sandbox team assessed the actual damage as minimal — less than 0.01% of the total SAND supply. Critically, tokens in the Ethereum (ETH) and Polygon (POL) networks remained untouched, and user wallets were not compromised.
Team response and security measures
The developers immediately disabled the bridge between Base and BSC, effectively blocking the ability to move or recover the issued tokens. As project representatives emphasized, SAND in these networks is now isolated and unavailable for transfer or withdrawal. Users are strongly advised to refrain from any operations with the token in these networks, as its liquidity has been disrupted.
Notably, Korean exchanges Bithumb and Upbit promptly suspended SAND deposits and withdrawals, citing suspicions of a security breach and local legislation on protecting virtual asset holders. Upbit even closed operations with the Ethereum network version of SAND, although the project team assures that this network was not affected.
To compensate liquidity providers affected by the attack, a network snapshot is being prepared for the moment before the incident. The team promises to publish a full report on what happened later.
My analysis: This incident is yet another reminder that cross-chain bridges remain the most vulnerable point of DeFi infrastructure. According to DefiLlama, there were 17 hacks in a month, and most of them were related specifically to bridges. Although the damage here turned out to be minimal, the very fact that it was possible to mint tokens worth $49 billion demonstrates how fragile the security of cross-network protocols can be. Investors should be especially cautious with assets on bridges and keep an eye on project security updates.