Sandbox isolates SAND bridges after attacker mints 14.9 billion tokens on Base and BNB Smart Chain

·

The Sandbox said Saturday that it had contained a vulnerability in the cross-chain bridge for its SAND token after an attacker minted 14.9 billion unbacked SAND on Base and BNB Smart Chain. To stop further damage, the blockchain gaming project disabled official bridging to and from both networks, cutting those SAND deployments off from the canonical Ethereum adapter that backs the token across chains.

That left an immediate problem for users on Base and BNB Smart Chain: those SAND tokens are now isolated and cannot be redeemed through the official bridge. The Sandbox warned users not to buy or sell SAND on either network. “An attacker was able to mint unbacked SAND on Base and BSC. We have disabled bridging to and from both networks, so SAND on Base and BSC is currently isolated and cannot be moved or redeemed,” the company said in a statement quoted by The Defiant.

The largest headline number came from blockchain security firm PeckShield, which said 14.9 billion SAND were minted across two addresses, 0xAbE0…4D22 and 0x638C…F296. “#PeckShieldAlert Seems like The @TheSandboxGame ($SAND) got exploited. 14.9B $SAND minted across 2 addresses: 0xAbE0…4D22 & 0x638C…F296,” the firm said. But on-chain forensic reporting summarized by multiple outlets points to a much smaller direct drain of backed assets: the Ethereum Omnichain Fungible Token, or OFT, adapter balance fell from about 14,769,723 SAND to 0.0056 SAND in under a minute, implying about 14.75 million backed SAND were unlocked or released from Ethereum. Those tokens were then reportedly sold for roughly 80 ETH, or about $675,000 at the time.

That gap is the key to understanding the incident. The huge mint happened on isolated SAND deployments on Base and BNB Smart Chain, not on Ethereum itself. In The Sandbox’s setup, SAND uses LayerZero’s OFT model, which generally works by locking tokens on a canonical chain such as Ethereum and minting corresponding tokens on a destination chain. If that minting process is abused, very large balances can appear on a destination chain without equivalent backing. The Sandbox said the impact was “less than 0.01% of the total SAND token supply,” and said SAND on Ethereum and Polygon were not affected and no user wallets were compromised. Security firm Blockaid separately estimated the exploit created roughly $49 billion in face-value SAND across more than 400 transactions, but that was a notional market-value figure based on on-chain balances, not a confirmed loss or realizable proceeds.

Blockaid’s preliminary forensic explanation points to how the attacker may have done it. The firm said the exploit involved hijacking LayerZero delegate permissions through an approveAndCall path and then forging mint-related executions. That account remains an early technical assessment, not a final official diagnosis from The Sandbox. More broadly, cross-chain bridges have been a recurring attack vector in crypto, and this case again shows how nominal minted values on-chain can far exceed the collateral actually extracted.

The incident also drew a quick response from South Korean exchanges. Bithumb suspended SAND deposits and withdrawals at 11:11 a.m. local time on Aug. 22, citing the Virtual Asset User Protection Act, while Upbit issued trading cautions and warnings. The Sandbox said it will use a pre-incident snapshot, prepare a compensation plan for eligible liquidity providers and publish a post-mortem on what happened.

Tags: #crypto, #blockchain, #sand, #sandbox