Sandbox Bridge Exploit Mints Billions in Unbacked SAND on Base and BSC

yesterday / 21:21 3 sources negative

Key takeaways:

  • Bridge attacks target auxiliary chains while canonical contracts stay secure — audit all OFT deployments.
  • Sensational $49B minting figures mask minimal actual losses; SAND selloff may present dip-buying opportunity.
  • Broader LayerZero ecosystem projects should reassess delegate permissions following Sandbox's approveAndCall exploit.

The Sandbox has contained a cross-chain bridge security breach that allowed attackers to mint enormous quantities of unbacked SAND tokens on Base and BNB Smart Chain, prompting exchanges to restrict transfers while investigators assessed the damage.

Initial on-chain alerts on August 22 showed more than 500 million SAND had been created without corresponding collateral. Blockchain security firm PeckShield subsequently identified approximately 14.9 billion SAND minted across two attacker-linked addresses, nearly five times SAND's legitimate maximum supply of 3 billion tokens. Blockaid reported roughly $49 billion in face-value SAND was minted across more than 400 transactions while the attack was active. Those figures do not represent actual losses, because the unauthorized tokens lacked sufficient liquidity to be sold at their nominal market price.

The vulnerability affected The Sandbox's cross-chain SAND infrastructure on Base and BNB Smart Chain rather than the canonical SAND token on Ethereum. Attackers gained control over permissions associated with SAND's LayerZero-based Omnichain Fungible Token infrastructure. Blockaid said compromised delegate permissions involving an approveAndCall function enabled unauthorized creation of SAND without the Ethereum collateral normally required to back bridged tokens.

The Sandbox confirmed the bridge vulnerability later on August 22 and said it had fully contained the incident. The company disabled bridging to and from Base and BNB Smart Chain, isolating the unauthorized tokens and preventing them from being redeemed through its official bridge. SAND held on Ethereum and Polygon was unaffected, and the legitimate SAND backing the cross-chain infrastructure remained secure.

Despite billions of tokens being created, The Sandbox estimated the direct impact at less than 0.01% of SAND's legitimate 3 billion-token supply. On-chain investigators estimated approximately 14.75 million legitimately backed SAND, worth around $675,000 at prevailing prices, ultimately left the bridge adapter. Approximately 79.7 ETH was also reportedly extracted. South Korean exchanges reacted quickly: Upbit issued a caution notice concerning SAND, while Bithumb suspended deposits and withdrawals as the scope of the incident became clearer.

The Sandbox has warned users against buying, selling or providing liquidity for SAND on Base and BNB Smart Chain while those deployments remain isolated. The company plans to use a pre-attack snapshot to compensate eligible liquidity providers affected by the breach, though no reimbursement timetable has been disclosed. The incident is another example of cross-chain infrastructure becoming an attack surface even when a project's primary token contract remains uncompromised.

Previously on the topic:
yesterday / 08:43
Upbit and Bithumb Flag SAND After Cross-Chain Bridge Exploit
Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.