Metaverse platform The Sandbox confirmed that an exploited bridge allowed an attacker to mint unbacked SAND tokens on Base and BNB Smart Chain (BSC). The platform disabled the affected bridges immediately following the detection of the vulnerability, protecting Ethereum and Polygon-based SAND holders.
According to Peckshield, approximately 14.9 billion unbacked SAND tokens were minted across two addresses on August 21. This figure is nearly five times larger than SAND's legitimate total supply cap of 3 billion tokens. The exploit occurred when an attacker manipulated the smart contract's mint function on Base and BSC without a matching lock of collateral on the source chain, bypassing the normal 1:1 backing model.
The Sandbox stated that the incident affected less than 0.01% of SAND's total supply in terms of genuine backing at risk. Assets held on Ethereum and Polygon, as well as user wallets across the ecosystem and Ethereum-locked assets, remained untouched. The platform is currently preparing a compensation plan for eligible liquidity providers affected by the unbacked minting and has advised users against trading SAND on Base or BSC until the bridges are restored.
The exploit follows a broader industry trend where cross-chain bridges have accounted for over $320 million in losses during the first half of the year. Additionally, the incident coincides with Coinbase's announcement to delist SAND perpetual futures contracts, alongside nine other contracts, effective August 26, following a review of trading volume and liquidity. Open positions are scheduled to be settled automatically at that time. The Sandbox plans to conduct a post-mortem and security audit before bringing the Base and BSC bridges back online.


