The Sandbox metaverse has faced a serious security threat: attackers managed to compromise the cross-chain bridge for the SAND token, connecting the Base and BNB Smart Chain networks. As a result of the attack, unbacked tokens were issued in both networks, putting the integrity of the entire project ecosystem at risk.
The incident was detected by the analytics platform Blockaid, which recorded suspicious activity in the morning hours. As it turned out, hackers intercepted control of the LayerZero delegate through the approveAndCall function, which allowed them to gain access to the bridge mechanism and mint tokens without real backing.
The scale of the issuance is impressive: by my estimates, fake SAND worth approximately $49 million was created in more than 400 transactions. However, importantly, the The Sandbox team responded promptly, estimating the actual damage at less than 0.01% of the total SAND supply.
Emergency measures and asset isolation
The developers immediately disabled the bridge between Base and BSC, completely blocking the ability to move and recover the compromised tokens. In an official statement, the team emphasized that SAND is now isolated in these networks and unavailable for any operations. Notably, the original SAND locked in Ethereum, which serves as backing for all bridges, remained untouched — the attack did not affect user wallets.
Nevertheless, token holders in the Base and BSC networks are strongly advised to refrain from any trading operations, as the liquidity of these assets is now in question. The team is preparing a network snapshot from before the attack for subsequent compensation to affected liquidity providers, and promises to publish a detailed report on what happened shortly.
Market and exchange reaction
Korean crypto exchanges immediately responded to the incident. Bithumb suspended deposits and withdrawals of SAND at 05:11 Moscow time, and Upbit followed suit a minute later. Both platforms cited suspicions of a security breach and local legislation on protecting the rights of virtual asset holders. Upbit even suspended operations with the Ethereum network version of SAND, despite The Sandbox's assurances that this network was not affected.
This incident is another link in an alarming chain of events. According to DefiLlama, there have been 17 hacks in the industry over the past month, and bridges have once again proven to be the most vulnerable link. It is obvious that cross-chain infrastructure continues to be a prime target for hackers, and projects need to radically rethink their security protocols before entrusting them with multi-million dollar assets.