The Sandbox has disabled cross-chain bridging for its SAND token on Base and BNB Smart Chain after an attacker exploited a compromised bridge permission to mint billions of dollars in unbacked tokens. The metaverse project said the vulnerability has been fully contained and that funds locked on Ethereum backing legitimate SAND remain untouched.
Security firm Blockaid was first to flag the incident publicly, identifying unusual minting activity on SAND's Base deployment. By the time the exploit was contained roughly five hours later, on-chain trackers had recorded close to $49 billion in face-value SAND minted across more than 400 transactions — though the figure vastly overstates the real damage.
How the Bridge Was Compromised
SAND's cross-chain deployments run on LayerZero's Omnichain Fungible Token standard, which relies on a “delegate” address to hold administrative rights over bridge configuration — including the power to authorize privileged calls into the token contract. In LayerZero's own architecture, control of that delegate is effectively control of the bridge: once it's compromised, an attacker can mint on the destination chain without ever burning the corresponding SAND on Ethereum. According to onlookers tracking the exploit, the attacker hijacked the delegate through the ERC-20 utility function approveAndCall, then used the elevated permissions to mint at will on Base before the network's multisig cut off the compromised peer connection.
Actual Losses Far Below the Headline Number
Despite the eye-catching $49 billion mint figure, The Sandbox says real extraction totaled roughly 14.75 million SAND — about $675,000 — plus close to 80 ETH drained from liquidity before the exploit was shut down. The team estimates the impact at under 0.01% of SAND's 3 billion total supply and says no user wallets were compromised; SAND on Ethereum and Polygon was never affected, and the reserves backing all legitimate bridged SAND remain fully intact.
Related: Sandbox Exploit Mints $49B in Fake SAND, But Actual Loss Is Tiny
With bridging disabled, The Sandbox is telling users not to buy, sell, or provide liquidity for SAND on Base or BNB Smart Chain while the affected deployments stay isolated. The team says it is taking a snapshot of balances from before the attack and plans to compensate liquidity providers who were caught up in the unbacked minting once bridging resumes. Bithumb suspended SAND deposits and withdrawals within minutes of the exploit being flagged, with Upbit following shortly after — a now-familiar reflex among exchanges reacting to cross-chain incidents in real time.
The episode adds to a rough stretch for bridge security across the industry. It follows closely on the heels of a separate incident in which BounceBit abandoned its own blockchain after a $3 million exploit, and comes as BNB Chain itself prepares to ship a hard fork specifically patching a bridge validator vulnerability — a coincidence of timing that underscores how much of this year's crypto security spending is being funneled into the connective tissue between chains rather than the chains themselves.