The Sandbox has contained a vulnerability within its SAND cross-chain bridge on Base and BNB Smart Chain (BSC) after an attacker minted unbacked tokens across both networks. According to the project, the impact accounts for less than 0.01% of the total SAND supply, while tokens on Ethereum and Polygon remain unaffected and no user wallets were compromised.
Security firm Blockaid flagged the incident, reporting that attackers hijacked LayerZero delegate permissions via the approveAndCall function. Blockaid noted that approximately $49 billion in face-value SAND was minted across more than 400 transactions. Blockchain analytics firm PeckShield also tracked the exploit, identifying 14.9 billion SAND minted across two addresses.
In response, The Sandbox disabled bridging to and from Base and BSC to isolate the minted supply and prevent movement or redemption. The project emphasized that the SAND locked on Ethereum, which serves as backing for all bridged tokens, remains entirely intact.
Holders have been advised to refrain from buying, selling, or trading SAND on Base and BSC due to compromised liquidity. The project is currently preparing a pre-incident snapshot to arrange compensation for qualifying liquidity providers and promised a full post-mortem report.
Following the exploit, South Korean exchanges Bithumb and Upbit suspended SAND deposits and withdrawals, citing security concerns under the Virtual Asset User Protection Act. Upbit also halted the Ethereum version of the asset, despite project assurances that Ethereum-based tokens were not at risk.


