The Sandbox has eliminated a critical vulnerability: fake SAND tokens flooded Base and BNB Chain.
The Sandbox metaverse has found itself at the center of an incident involving the compromise of a cross-chain bridge for the SAND token between the Base and BNB Smart Chain networks. Attackers managed to exploit a vulnerability in LayerZero's delegation function, allowing them to mint unbacked tokens in both networks. This represents a serious breach of asset integrity, although the scale of the damage, according to preliminary estimates, turned out to be limited.
Exploit details and team response
Security analysts recorded the attack in the morning hours. The attacker intercepted control over LayerZero delegate rights through the approveAndCall function, which allowed them to issue SAND worth approximately $49 billion in more than 400 transactions. It is important to emphasize: despite such an impressive nominal figure, the project team estimates the actual damage at less than 0.01% of the total SAND supply. Tokens on the Ethereum and Polygon networks remained untouched, and user wallets were not compromised.
The Sandbox team immediately disabled the bridge between Base and BSC, blocking the ability to move and recover the compromised tokens. This led to the complete isolation of SAND in these networks, making them unavailable for trading or withdrawal. Developers have already warned holders to refrain from any operations with the asset, emphasizing that liquidity in these networks has been disrupted.
Exchange response and the broader picture
Korean crypto exchanges Bithumb and Upbit quickly responded to the incident by suspending SAND deposits and withdrawals. Notably, Upbit even closed operations for the token version on the Ethereum network, despite assurances from The Sandbox team that this network was not affected. This demonstrates the increased caution of exchanges amid the growing number of attacks on cross-chain infrastructure.
This incident is just part of a worrying trend. Over the past month, the industry has seen 17 hacks, and bridges have once again proven to be the most vulnerable link. Although most attacks were minor, the very fact that such scenarios keep recurring points to systemic security issues in cross-chain protocols.
The Sandbox team has promised to publish a detailed report on what happened and is preparing a network snapshot to compensate liquidity providers.
My analysis: This case highlights that even when direct damage appears insignificant, bridge attacks deliver a reputational blow and create a risk of panic among holders. Investors should be extremely cautious with assets locked in cross-chain bridges and closely monitor project security updates. Vulnerabilities in LayerZero are a red flag for the entire ecosystem, and I expect increased auditing of such protocols in the near future.