The Sandbox Disables SAND Bridging on Base and BSC
Following the discovery, The Sandbox disabled SAND bridging to and from Base and BNB Smart Chain.
The emergency action was intended to isolate the affected infrastructure and prevent additional unbacked SAND from moving through the official bridge.
The project also advised users against buying, selling or providing liquidity for SAND on Base and BSC while its investigation continues.
The Sandbox said the incident did not affect SAND held directly on Ethereum or Polygon.
The Sandbox official website
Attackers Reportedly Minted Billions of SAND
The scale of the minting activity initially raised concerns across the crypto market.
Blockchain security firm PeckShield reported that approximately 14.9 billion SAND had been minted across two attacker-controlled addresses.
The reported amount is several times larger than SAND's stated maximum supply of 3 billion tokens.
Blockaid separately reported that unbacked SAND with a nominal value approaching $49 billion had been minted across more than 400 transactions.
However, the $49 billion figure does not mean that $49 billion worth of legitimate assets were stolen.
The figure reflects the nominal value of newly created tokens. Unbacked tokens minted on a compromised destination network do not automatically represent an equivalent amount of legitimate SAND reserves.
Actual Financial Impact Appears Much Smaller
On-chain analysis cited in reports surrounding the incident indicates that approximately 14.75 million SAND, worth around $675,000 at the time, may have been extracted from Ethereum-side bridge reserves, together with approximately 80 ETH.
The Sandbox has not independently confirmed those specific figures, so the final amount of legitimate value lost remains subject to the project's investigation.
This distinction is important when assessing the incident.
An attacker can potentially mint billions of tokens if a bridge's authorization mechanism is compromised, but converting those tokens into legitimate assets requires sufficient liquidity and counterparties willing to accept them.
The Sandbox said the overall impact was below 0.01% of SAND's total supply.
How the SAND Bridge Vulnerability Worked
The vulnerability involved the cross-chain implementation of SAND rather than the core SAND token supply on Ethereum.
Security researchers reportedly identified an issue involving the LayerZero-powered omnichain token infrastructure deployed on Base.
The attacker allegedly exploited permissions associated with an approveAndCall mechanism, enabling unauthorized SAND minting.
Cross-chain systems normally maintain a relationship between tokens issued on destination networks and assets locked or otherwise accounted for on the source chain.
If that authorization mechanism is compromised, an attacker can potentially create tokens without providing the corresponding backing.
That makes bridges and omnichain token contracts some of the most sensitive components of multichain crypto infrastructure.
Why the Incident Matters for BNB Smart Chain
The incident is particularly relevant for BNB Smart Chain, where SAND had cross-chain liquidity and trading activity.
BNB Smart Chain supports a large ecosystem of decentralized exchanges, liquidity pools and DeFi applications. When a token's supply becomes compromised on one network, the effects can quickly spread to exchanges and liquidity providers.
The risk is especially significant when unbacked tokens enter decentralized liquidity pools.
If users or protocols treat those tokens as legitimate SAND, attackers may attempt to exchange them for other assets, potentially draining liquidity from pools before the exploit is detected.
The Sandbox's decision to disable bridging therefore helps limit further contagion while the affected infrastructure is investigated.
BNB Chain official website
Ethereum and Polygon SAND Remain Unaffected
The Sandbox has emphasized that the vulnerability was isolated to the affected cross-chain deployments.
The project said:
SAND on Ethereum was not affected.
SAND on Polygon was not affected.
SAND locked on Ethereum as bridge backing remained secure.
SAND bridging on Base and BSC was disabled.
The project said user wallets were not compromised.
A compensation plan is being prepared for eligible liquidity providers.
The Sandbox is also taking a snapshot of positions from before the incident to help identify liquidity providers who may qualify for compensation.
South Korean Exchanges Suspend SAND Transfers
The incident also prompted action from South Korean cryptocurrency exchanges.
Upbit and Bithumb temporarily suspended SAND deposits and withdrawals following the security incident.
Exchange suspensions can help prevent potentially compromised or unbacked tokens from entering or leaving centralized trading platforms while investigators determine the legitimate supply.
The response also shows how a vulnerability affecting a specific blockchain deployment can quickly become a broader market issue.
Cross-Chain Bridges Remain a Major Security Risk
The SAND incident highlights a persistent challenge across the multichain ecosystem.
Projects deploy tokens on multiple networks to access additional users, liquidity and applications. However, each deployment introduces additional smart contracts, permissions and messaging infrastructure.
A cross-chain system must correctly manage:
A weakness in one component can potentially break the relationship between an asset's legitimate supply and its representation on another blockchain.
For BNB Smart Chain, the incident underscores the importance of verifying token contracts and bridge infrastructure before interacting with newly created or unusually priced liquidity.
The Sandbox Plans a Technical Post-Mortem
The Sandbox said it will publish a full incident report and technical post-mortem detailing the vulnerability and the measures taken to contain it.
The project is also developing a compensation plan for eligible liquidity providers affected by the incident.
The post-mortem should help answer several outstanding questions, including how the attacker obtained the ability to mint SAND, how much legitimate value was ultimately extracted and what security changes will be implemented.
Until those details are available, users should exercise caution when interacting with SAND on BSC and Base.
What Happens Next for SAND on BSC?
The immediate priority is to ensure that the compromised bridge infrastructure remains isolated and that the legitimate SAND supply is properly reconciled across affected networks.
Before bridging resumes, The Sandbox will need to complete its investigation and implement additional controls to prevent unauthorized minting.
For BSC users, the most important signal will be an official confirmation from The Sandbox that SAND bridging has been secured and restored.
Users should also avoid unofficial bridges or contracts claiming to provide replacement SAND while the official investigation remains underway.
Conclusion
The Sandbox has contained a significant vulnerability affecting the SAND cross-chain bridge on BNB Smart Chain and Base, after an attacker reportedly gained the ability to mint large quantities of unbacked SAND.
Although security firms reported billions of tokens being created, the amount of legitimate value apparently extracted was substantially smaller. The Sandbox estimates the overall impact at less than 0.01% of SAND's total supply.
The incident nevertheless demonstrates the risks associated with cross-chain token infrastructure. A compromised minting mechanism can create enormous amounts of nominal token value and potentially threaten liquidity across decentralized markets.
For the BNB Smart Chain ecosystem, the incident reinforces the importance of bridge security, contract permissions, liquidity monitoring and rapid containment when abnormal token activity is detected.
The upcoming technical post-mortem and compensation plan should provide greater clarity on the exploit, the final losses and the safeguards The Sandbox will introduce before normal SAND bridging resumes.