Metaverse project The Sandbox has faced a critical security breach after its SAND cross-chain OFT contract on the Base network was exploited, leading to an infinite mint attack. According to security firm Blockaid, attackers gained control of LayerZero delegate permissions linked to SAND's OFT system on Base, utilizing "approveAndCall" to bypass normal controls and create new unbacked tokens.
On-chain data and security reports highlighted the massive scale of the minted tokens. PeckShield reported about 14.9 billion SAND across two addresses linked to the attack, while Blockaid reported that nearly $49 billion in face-value tokens were created across more than 400 transactions.
Analysts emphasized that the $49 billion figure represents the theoretical market value of the newly created tokens rather than actual funds stolen. Because the tokens lack backing, attempting to sell such a large volume would crash the market price. The actual amount extracted was significantly lower, with the Ethereum OFT adapter losing approximately 14.75 million SAND—valued at about $675,000 at the time—and roughly 79.74 ETH reportedly converted from the stolen funds.
Exchanges and security firms quickly responded to the abnormal on-chain activity. Bithumb suspended SAND deposits and withdrawals, Upbit issued an investor warning, and CertiK flagged the incident.
The Sandbox team later confirmed that the vulnerability affecting the cross-chain bridge on Base and BNB Smart Chain (BSC) had been fixed and fully contained, while Ethereum and Polygon remained unaffected. The project stated that no user wallets were compromised and locked SAND on Ethereum is secure. Bridging on Base and BSC was stopped, and the team advised users against trading SAND on those networks while planning to take a pre-attack snapshot to compensate eligible liquidity providers.


