Sandbox Bridge Hack Mints 14.9B SAND While Coinbase Delists Futures

Ledger
fiverr


Key Takeaways

Exploit Hits Base and BSC Bridges

Sandbox, the metaverse gaming platform behind the SAND token, contained a vulnerability affecting its cross-chain bridges on Base and BNB Smart Chain (BSC). An attacker exploited the bridges’ minting mechanism to create SAND tokens with no real backing on both networks. The Sandbox disabled bridging on Base and BSC as soon as the exploit was detected, cutting off the attacker’s ability to move the fabricated tokens further.

Sandbox Bridge Hack Mints 14.9B SAND While Coinbase Delists Futures

The Sandbox’s bridge infrastructure normally works by locking SAND on one chain, typically Ethereum, and minting an equivalent, fully backed amount on the destination network. That 1:1 backing model is what broke down in this incident, allowing tokens to be minted on Base and BSC without a matching lock on the source chain.

A 14.9 Billion Token Anomaly

Peckshield identified approximately 14.9 billion unbacked SAND minted across two addresses tied to the exploit. The scale of that figure stands out given SAND’s legitimate total supply is capped at 3 billion tokens, meaning the minted amount was nearly five times larger than every real SAND token that has ever existed or will exist.

itrust

The mismatch is common in bridge exploits, where an attacker manipulates a smart contract’s mint function rather than actually stealing locked collateral. Similar mint-based attacks have hit other protocols throughout the year, including a bridge exploit that let an attacker mint 1 billion unauthorized DOT tokens on Polkadot’s bridge earlier in 2026, and a smaller incident where roughly 13.76 million unbacked ALPH tokens were created on the Alephium bridge.

In each case, the fabricated tokens carried no real value and could be neutralized once the affected chain froze the exploited contract.

The Sandbox said the incident affected less than 0.01% of SAND’s total supply in terms of genuine backing at risk. SAND held on Ethereum and Polygon, user wallets across the ecosystem, and the Ethereum-locked assets that back the token remained untouched throughout the exploit, the company said.

The platform is now preparing a compensation plan for eligible liquidity providers who held positions affected by the unbacked minting, and it has advised users not to trade SAND on Base or BSC until the bridges are restored.

Part of a Bigger Bridge Security Problem

Bridge exploits have topped $320 million in losses across the crypto industry over the first half of the year, as attackers have increasingly started targeting the smart contracts that connect separate blockchains rather than individual protocols. Bitcoin.com News has tracked a similar pattern in recent months, including the Gravity Bridge exploit that saw a hacker drain $5.4 million and route the funds through Binance before the trail went cold.

Moreover, it bears mentioning that SAND was already facing pressure independent of the exploit, with its token trading near $0.039 as of this week, and Coinbase announcing its plans to delist ten perpetual futures contracts, including SAND, effective August 26, as part of a broader review of trading volume and liquidity across its derivatives markets.

Open positions will be settled automatically at that point, adding a second source of near-term volatility on top of the bridge incident.

The next step for The Sandbox is a post-mortem on how the bridge’s minting controls failed and a security audit before Base and BSC bridging is switched back on.



Source link

Ledger

Be the first to comment

Leave a Reply

Your email address will not be published.


*