The Sandbox disclosed on August 22 that a malicious actor exploited a vulnerability in its SAND cross-chain bridge on Base and BNB Smart Chain, prompting the gaming platform to suspend all cross-chain transfers and freeze the token’s functionality on both networks.
The attacker leveraged LayerZero’s Omnichain Fungible Token (OFT) standard to mint unbacked SAND tokens by compromising bridge delegate permissions through the approveAndCall function. On-chain monitoring flagged minting volumes with a face-value estimate of roughly $49 billion, a number that sounds apocalyptic until you look at what actually moved.
The gap between what was minted and what was moved
Approximately 14.9 billion SAND were minted to specific addresses during the exploit. That figure, on paper, dwarfs the token’s total supply of 3 billion.
But the real amount that appears to have been transferred to usable wallets is closer to 14.75 million SAND. The Sandbox itself assessed the direct impact at less than 0.01% of total supply.
The affected tokens on Base and BSC are now isolated, non-transferable, and non-redeemable against Ethereum-backed reserves. The Sandbox has explicitly warned users not to trade these tokens, since they carry zero backing and will likely never be honored.
Exchange response and market fallout
South Korea’s two largest crypto exchanges, Upbit and Bithumb, moved quickly to suspend SAND deposits and withdrawals following the disclosure.
The Sandbox’s bridge used LayerZero’s OFT standard, which is designed to allow tokens to exist natively across multiple chains without the traditional lock-and-mint model. The approveAndCall function, which the attacker manipulated, essentially allowed the creation of SAND tokens on Base and BSC without corresponding locked tokens on Ethereum.
What happens to affected users
The Sandbox said it is preparing compensation for liquidity providers who were impacted by the exploit. The plan relies on a pre-incident snapshot, meaning the team captured the state of affected pools before the exploit distorted balances.
The platform also committed to releasing a comprehensive technical report detailing the breach, including the attack vector, the timeline of the response, and broader implications for the ecosystem. The Sandbox has stated that no user funds were lost and no wallets were compromised, framing the incident as a contained infrastructure exploit rather than a user-level breach.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
22









English (US) ·