South Korean crypto exchanges Upbit and Bithumb designated The Sandbox’s SAND token as an investment caution asset on August 24, 2026, after unresolved security concerns linked to a cross-chain bridge vulnerability. The incident involved abnormal minting of unbacked SAND on Base and BNB Smart Chain, prompting both platforms to suspend deposits and withdrawals while keeping trading available during review periods.
According to Upbit, the caution applies to SAND’s Korean won and Bitcoin markets. Deposits and withdrawals had already been halted at 11:12 a.m. KST on August 22. Upbit’s initial review period runs from August 24 at 3 p.m. KST through the fifth week of September, between September 28 and October 4. The exchange said it may remove the warning, extend the review, or terminate trading support depending on its findings. SAND deposits made after the caution notice will not be credited and will qualify for return processing. The token was also removed from assets available for new borrowing applications under Upbit’s coin lending service.
Bithumb issued its own designation at 3 p.m. KST on August 24, citing confirmed security incidents involving virtual asset wallets or distributed ledgers where the cause had not been identified or the problem had not been fully resolved. Bithumb had stopped SAND deposits and withdrawals at 11:11 a.m. KST on August 22 after detecting signs of a possible security problem. Bithumb expects to decide between September 28 and October 2 whether to extend, remove, or escalate the designation into a trading support termination.
The Sandbox said it identified and contained a vulnerability affecting its SAND cross-chain bridge on Base and BNB Smart Chain. An attacker was able to mint unbacked SAND on the two networks, leading the team to disable bridging to and from both chains. The project estimated the actual impact at less than 0.01% of SAND’s total supply and said SAND held on Ethereum and Polygon was unaffected. No user wallets were compromised, and the SAND locked on Ethereum to back legitimate bridged tokens remained secure. With bridging disabled, SAND on Base and BNB Smart Chain was isolated and could not be moved or redeemed through the affected bridge. The team advised users against buying, selling, or trading SAND on those networks while liquidity remained affected.
Security firm Blockaid separately reported that attackers had hijacked LayerZero delegate permissions through the approveAndCall function used by SAND’s omnichain token setup. A large nominal amount of unbacked SAND was minted across hundreds of transactions, although the face value of newly created tokens did not represent the project’s reported financial loss. The Sandbox has taken a snapshot of balances from before the incident and is preparing a compensation plan for eligible liquidity providers affected on Base and BNB Smart Chain.
The caution follows previous South Korean exchange reviews after security exploits. Upbit removed a warning on Taiko in July after a 32-day review of a June bridge exploit. In contrast, Flow Foundation and Dapper Labs sought a court order after Upbit, Bithumb, and Coinone moved to end FLOW trading support following a December 2025 exploit. South Korean regulators have also increased scrutiny of platform security under the Virtual Asset User Protection Act, with the Financial Supervisory Service beginning a formal sanctions process against Upbit operator Dunamu over a November 2025 wallet breach affecting Solana-based assets.