The Sandbox has contained a serious cross-chain bridge exploit that allowed attackers to create enormous quantities of unbacked SAND tokens on Base and BNB Smart Chain, forcing major South Korean cryptocurrency exchanges to suspend SAND transfers while the project worked to isolate the affected networks.

Initial blockchain alerts on August 22 showed more than 500 million SAND had been created without corresponding collateral. Subsequent analysis by security firm PeckShield identified approximately 14.9 billion SAND minted across two attacker-controlled addresses.

The numbers sound catastrophic, but they require important context.

The 14.9 billion figure represents tokens that were artificially created on affected bridge deployments. It does not mean attackers stole $49 billion in actual funds.

How the exploit worked

The vulnerability affected The Sandbox's cross-chain bridge infrastructure connecting SAND to Base and BNB Smart Chain.

The attacker exploited permissions associated with the LayerZero Omnichain Fungible Token system, enabling new SAND to be minted without the corresponding SAND being locked as collateral on Ethereum.

Normally, a cross-chain bridge works by locking legitimate tokens on one blockchain and creating an equivalent representation on another network.

That backing mechanism is crucial.

In this case, the compromised bridge effectively allowed the destination chains to create tokens without receiving the necessary collateral.

The scale of the mint was extraordinary

Early alerts identified more than 500 million newly minted SAND.

That amount alone represented about 16.7% of SAND's official three-billion-token maximum supply.

The number later expanded dramatically.

PeckShield identified approximately 14.9 billion SAND minted across two addresses, nearly five times the token's official maximum supply on Ethereum.

Blockaid separately estimated that the attack generated roughly $49 billion in face-value SAND across more than 400 transactions.

But that number should not be interpreted as a $49 billion theft.

The tokens were unbacked.

Once The Sandbox disabled the bridges, the affected tokens on Base and BNB Smart Chain could no longer be officially redeemed through the bridge.

The actual financial damage appears much smaller

The distinction between “tokens minted” and “money stolen” is critical.

Security researchers cited by several reports estimate that the actual amount of value extracted from legitimate reserves was dramatically lower than the headline face value of the exploit.

One on-chain analysis estimated the apparent extraction at approximately 14.75 million SAND, worth roughly $675,000 at the time, plus about 79.74 ETH. That estimate has not been independently confirmed by The Sandbox.

The enormous quantity of counterfeit SAND could nevertheless have caused severe market disruption if attackers had succeeded in moving large amounts through functioning liquidity pools.

That is why the bridge shutdown was so important.

The Sandbox shuts down affected bridges

The project quickly suspended bridging to and from Base and BNB Smart Chain.

The Sandbox said the action isolated the affected SAND and prevented the newly minted tokens from being moved or redeemed through the official system.

The company said Ethereum and Polygon SAND were not affected.

The Ethereum reserves backing legitimate bridged SAND also remained intact.

That limited the incident's potential impact on the broader SAND ecosystem.

South Korean exchanges freeze transfers

The exploit nevertheless triggered an immediate response from major Korean exchanges.

Upbit and Bithumb suspended SAND deposits and withdrawals after receiving security alerts. The exchanges warned users about potentially extreme price volatility while the incident was investigated.

That response highlights how closely centralized exchanges monitor bridge incidents.

Even if an attack is limited to one blockchain deployment, exchanges may temporarily halt transfers because they cannot immediately determine whether counterfeit tokens could reach their platforms.

Freezing deposits and withdrawals gives investigators time to establish which versions of a token remain legitimate.

Ethereum and Polygon holders were protected

One of the most important positive developments is that native SAND on Ethereum and Polygon was not compromised.

The Sandbox said the Ethereum reserves supporting legitimate bridged SAND remained intact, helping ensure that the attack did not become a direct assault on the core token supply.

That distinction should reassure users holding SAND on unaffected networks.

The incident was a bridge-level security failure rather than an indication that the underlying Ethereum-based SAND supply had been hacked.

The episode exposes bridge vulnerabilities

Cross-chain bridges remain one of the most challenging parts of blockchain infrastructure.

They are designed to move assets between different networks, but that requires mechanisms capable of determining whether tokens are properly backed and authorized.

A single compromised permission can therefore create a much larger vulnerability than an ordinary smart-contract bug.

The Sandbox exploit is the latest reminder that building multi-chain infrastructure introduces risks that do not necessarily exist when a token operates on a single network.

The headline numbers can confuse investors

The 14.9 billion figure is particularly important to understand.

SAND's official maximum supply is three billion tokens.

Seeing five times that amount suddenly appear on blockchain explorers naturally creates fears of catastrophic inflation.

But those tokens were created outside the normal backed supply mechanism and were not automatically equivalent to legitimate SAND circulating through the main ecosystem.

The economic risk depended on whether the fraudulent tokens could be converted into real assets through exchanges, liquidity pools or the official bridge.

Once the bridge was disabled, the attackers' ability to monetize the counterfeit supply was substantially reduced.

The Sandbox is preparing a compensation process

The project has said it is taking a pre-incident snapshot and preparing a compensation plan for eligible liquidity providers affected by the exploit.

The company has also indicated that a full post-mortem will follow.

For users, the compensation process will be important because liquidity providers may have experienced losses or become exposed to distorted SAND markets during the attack.

The details of eligibility and reimbursement remain to be finalized.

Markets may remain volatile

Even though the exploit was contained, SAND remains vulnerable to volatility.

News of a bridge attack can reduce investor confidence, particularly among users who rely on cross-chain liquidity.

Centralized exchange restrictions can also reduce available trading liquidity temporarily.

That can make price movements larger than usual.

Investors therefore face both technical and market risks even after the underlying bridge vulnerability has been isolated.

A broader lesson for multi-chain crypto

The incident is another reminder that the weakest part of a blockchain ecosystem can often be the connection between networks rather than the underlying blockchain itself.

Ethereum may remain secure.

Base may remain operational.

BNB Smart Chain may remain operational.

But the software connecting assets between them can still create a point of failure.

As more crypto projects expand across multiple chains, bridge security is likely to become an even more important part of the industry's infrastructure.

What happens next

The immediate priority for The Sandbox is clear: secure the affected contracts, prevent movement of fraudulent SAND and determine the extent of actual financial losses.

The next step will be a technical post-mortem and a compensation framework for qualifying users.

The market will also want to know how the attacker obtained minting privileges and whether other projects using similar LayerZero infrastructure could face related risks.

The incident is serious, but its headline value needs to be interpreted carefully.

More than 500 million unbacked SAND was detected initially, and later analysis found about 14.9 billion tokens minted.

Yet those figures do not represent an equivalent amount of stolen cash.

The central danger was the potential to turn counterfeit tokens into legitimate value.

By shutting down the affected bridges quickly, The Sandbox appears to have significantly limited that risk.

Keep Reading