The Sandbox has contained a cross-chain bridge security breach that allowed attackers to mint enormous quantities of unbacked SAND tokens on Base and BNB Smart Chain, prompting exchanges to restrict transfers while investigators assessed the damage.
Initial on-chain alerts on August 22 showed more than 500 million SAND had been created without corresponding collateral. Blockchain security firm PeckShield subsequently identified approximately 14.9 billion SAND minted across two attacker-linked addresses, nearly five times SAND's legitimate maximum supply of 3 billion tokens. Blockaid reported roughly $49 billion in face-value SAND was minted across more than 400 transactions while the attack was active. Those figures do not represent actual losses, because the unauthorized tokens lacked sufficient liquidity to be sold at their nominal market price.
The vulnerability affected The Sandbox's cross-chain SAND infrastructure on Base and BNB Smart Chain rather than the canonical SAND token on Ethereum. Attackers gained control over permissions associated with SAND's LayerZero-based Omnichain Fungible Token infrastructure. Blockaid said compromised delegate permissions involving an approveAndCall function enabled unauthorized creation of SAND without the Ethereum collateral normally required to back bridged tokens.
The Sandbox confirmed the bridge vulnerability later on August 22 and said it had fully contained the incident. The company disabled bridging to and from Base and BNB Smart Chain, isolating the unauthorized tokens and preventing them from being redeemed through its official bridge. SAND held on Ethereum and Polygon was unaffected, and the legitimate SAND backing the cross-chain infrastructure remained secure.
Despite billions of tokens being created, The Sandbox estimated the direct impact at less than 0.01% of SAND's legitimate 3 billion-token supply. On-chain investigators estimated approximately 14.75 million legitimately backed SAND, worth around $675,000 at prevailing prices, ultimately left the bridge adapter. Approximately 79.7 ETH was also reportedly extracted. South Korean exchanges reacted quickly: Upbit issued a caution notice concerning SAND, while Bithumb suspended deposits and withdrawals as the scope of the incident became clearer.
The Sandbox has warned users against buying, selling or providing liquidity for SAND on Base and BNB Smart Chain while those deployments remain isolated. The company plans to use a pre-attack snapshot to compensate eligible liquidity providers affected by the breach, though no reimbursement timetable has been disclosed. The incident is another example of cross-chain infrastructure becoming an attack surface even when a project's primary token contract remains uncompromised.