The Sandbox team quickly resolved a critical vulnerability in the cross-chain bridge connecting the Base and BNB Smart Chain networks. The incident, detected at an early stage, allowed an attacker to mint unbacked SAND tokens in both networks, but the scale of the damage turned out to be minimal.
Exploit details and team response
The attack was carried out through the approveAndCall function, which allowed the hacker to take control of the LayerZero delegate. As a result, about 49 billion fake SAND were generated across more than 400 transactions. Nevertheless, the team estimates the total damage at less than 0.01% of the entire issuance volume. It is important to emphasize that tokens on the Ethereum and Polygon networks remained untouched, and user wallets were not compromised.
After detecting the anomaly, developers immediately disabled the bridge, isolating the compromised tokens. Now SAND on the Base and BSC networks is blocked from movement and withdrawal. Project representatives warned holders against trading these assets due to their impaired liquidity.
Exchange response and market context
Korean crypto exchanges Bithumb and Upbit immediately suspended SAND deposits and withdrawals. Notably, Upbit also froze operations with the token version on the Ethereum network, despite the team's assurances that this network was not affected. This demonstrates the increased caution of exchanges amid the growing number of incidents in the sector.
This case fits into a broader alarming trend: according to analytics platforms, 17 hacks occurred over the past month, with bridges once again proving to be the most vulnerable link in the infrastructure. The Sandbox team is already preparing a network snapshot to compensate liquidity providers and promises to publish a detailed report on what happened.
My comment: This incident is yet another reminder that cross-chain bridges remain the "Achilles' heel" of DeFi. Even with a quick response and minimal damage, trust in such solutions is undermined, and exchanges are forced to introduce preventive blocks. Investors should exercise particular caution when working with assets on new networks until teams conduct a full security audit.