Web3 gaming project The Sandbox recently encountered a cross-chain bridge exploit impacting SAND tokens on the Base and BNB Smart Chain (BSC) networks. Security firm PeckShield reported that an attacker minted 14.9 billion unbacked SAND tokens, valued at approximately $718 million, across two wallet addresses.
Another security firm, Blockaid, specified that the incident involved The Sandbox’s SAND Omnichain Fungible Token (OFT) on Base. The OFT utilizes a LayerZero feature designed to enable projects to transfer tokens across blockchains. According to Blockaid, the attacker compromised the Base OFT to acquire administrative minting permissions, clarifying that the issue lay within the Base SAND minting system rather than LayerZero itself.
In response, The Sandbox project team stated that the vulnerability has been identified and contained. The team sought to downplay the impact, asserting that the affected tokens represent less than 0.01% of the total SAND token supply. They confirmed that SAND tokens operating on Ethereum and Polygon remain unaffected, no user wallets were compromised, and holders and liquidity pool providers on those networks do not need to take any action.
Despite these assurances, the project cautioned users against interacting with SAND tokens on the Base or BSC chains. Mitigation measures included disabling the movement and redemption of SAND between Base or BSC and other networks. The project also announced that liquidity providers affected by the unauthorized mint will be compensated following a review.
Following the security update, the price of SAND fell by 5%, reversing a portion of the gains it had accumulated earlier in the week during a broader market recovery.
This incident contributes to a broader wave of crypto exploits, with nearly $400 million lost over the past 90 days and approximately $1.6 billion lost on a year-on-year basis.


