The Sandbox's SAND token was hit by a cross-chain bridge exploit on August 22 that let an attacker mint roughly $49 billion in face-value tokens on Base and BNB Smart Chain without the reserves on Ethereum to back them. The headline figure looks catastrophic, but The Sandbox says the actual damage was far smaller: the team has since said the real extractable loss sat at around $665,000 in drained Ethereum-side reserves, with the unbacked tokens themselves never redeemable for anything of value once the bridge was frozen.
Security firm Blockaid identified the attack as it happened, tracing it to an attacker who hijacked LayerZero delegate permissions tied to SAND's Omnichain Fungible Token setup on Base, using an approveAndCall function to bypass the controls that normally keep new SAND tied to real collateral. More than 400 transactions later, the exploit had produced tokens with a face value north of $49 billion — a number that reflects SAND's market price multiplied by a mint nobody could actually cash out, not real capital that left the ecosystem.
How The Sandbox Contained It
The Sandbox team disabled bridging to and from both Base and BNB Smart Chain as soon as the exploit was flagged, isolating the affected token deployments and preventing the unbacked SAND from being redeemed through the official bridge. The project urged users not to buy, sell, or provide liquidity for SAND on either chain while the isolation remained in place, and said the Ethereum-side reserves backing legitimately bridged SAND remained intact throughout. On-chain transaction records show the scale of the minting activity that triggered the alarm before the team moved to lock things down.
Exchanges reacted quickly. Upbit issued a warning to users about the abnormal on-chain activity, while Bithumb suspended SAND deposits and withdrawals outright — a standard precaution when a token's supply integrity comes into question, even temporarily.
Why the Real Damage Was Contained
What separates this incident from a typical bridge hack is that the attacker's minted tokens had no path to real value. Because the exploit targeted only the Base and BSC sides of the bridge rather than the Ethereum-side vault where genuine SAND collateral sits, the unbacked tokens were, in effect, cash that couldn't be spent — impressive on a block explorer but worthless without a working bridge back to real reserves. The project's decision to freeze bridging before large amounts of the minted supply could be moved to exchanges and sold is what kept the loss in the hundreds of thousands rather than the billions the headline number implied.
The incident is a reminder that cross-chain bridges, not base-layer smart contracts, remain one of the more exploited surfaces in crypto — LayerZero-style omnichain token standards let projects mint on multiple chains for convenience, but that same flexibility creates a larger attack surface if delegate permissions aren't locked down tightly enough. The Sandbox has said it is taking a pre-attack snapshot and evaluating compensation for affected liquidity providers, though it hasn't published a timeline.