A vulnerability tucked inside The Sandbox’s cross-chain bridge briefly let an attacker conjure billions of unbacked SAND tokens out of thin air, setting off a scramble across South Korean exchanges before the metaverse studio said it had shut the breach down. The Sandbox bridge exploit, which hit deployments on Base and BNB Smart Chain in the early hours of August 22, 2026, has left security researchers and the project itself disagreeing sharply over how much damage was actually done.
Key takeaways
- The Sandbox says it fully contained a vulnerability in its SAND cross-chain bridge that let an attacker mint unbacked tokens on Base and BNB Smart Chain.
- Bridging between both affected networks has been disabled; The Sandbox says no user wallets were hit and that SAND on Ethereum and Polygon remains secure.
- Security firm Blockaid estimated roughly $49 billion in minted fake SAND across more than 400 transactions, while PeckShield counted 14.9 billion SAND minted across two addresses.
- The Sandbox itself puts the real impact at less than 0.01% of total SAND supply, a figure it has not fully reconciled with outside researchers’ numbers.
- Upbit and Bithumb froze SAND deposits and withdrawals in South Korea under the country’s Virtual Asset User Protection Act, with Upbit also suspending Ethereum transfers despite that chain being unaffected.
The Sandbox Contains a Cross-Chain Bridge Vulnerability
The Sandbox says the breach is over: the studio behind the virtual-world game announced it had “identified and fully contained” the flaw that allowed an attacker to mint unbacked SAND on Base and BNB Smart Chain. In a statement posted around 3:22 a.m. ET on Saturday, the team told users not to buy, sell, trade or provide liquidity for SAND on either network while the affected deployments remain isolated.
According to security firm Blockaid, the attacker obtained unauthorized access to LayerZero delegate permissions via an approveAndCall function present in SAND’s cross-chain fungible token contract deployed on Base. That delegate role governs who is authorized to mint new tokens on a given chain, and once compromised, it let the attacker generate SAND that had no matching reserve locked on Ethereum. Crypto.news reported that The Sandbox subsequently removed the LayerZero peer settings connecting Base and BNB Smart Chain to the rest of the network, cutting the official route attackers might otherwise have used to drain genuine tokens from the Ethereum-side reserve.
The Sandbox says no user wallets were compromised, and that SAND held on Ethereum and Polygon remained untouched throughout. Crucially, the project says the SAND locked on Ethereum that backs all bridged tokens is “fully intact,” meaning the underlying collateral for the cross-chain system was never actually drained at scale.
Security Firms and The Sandbox Disagree on the Scale of Damage
Here’s where the story gets murky. Blockaid flagged the exploit hours before The Sandbox’s own statement, putting the face value of minted fake SAND at roughly $49 billion in value moved through over 400 separate transactions by 12:14 a.m. ET — according to reports that at the time that the attack was still ongoing. PeckShield, in a separate notification issued at 1:40 a.m. ET, identified 14.9 billion SAND generated across a pair of addresses, with block-explorer records showing balances of 14.65 billion and 250 million tokens credited from the null address used to issue newly created tokens.
Both figures dwarf SAND’s actual circulating supply of about 2.94 billion tokens against a fixed maximum of 3 billion, according to CoinGecko. That’s not necessarily a contradiction: tokens minted on Base or BNB Smart Chain cannot expand Ethereum’s capped supply unless the attacker could also use the bridge to unlock genuine reserves held by the Ethereum adapter. Blockchain forensics account BlockWatchdog reported that the attacker did manage to withdraw approximately 14.75 million SAND from that Ethereum adapter in under a minute, selling the proceeds for roughly 80 ETH — worth about $675,000 at the time.
That smaller, real-money figure may explain why The Sandbox has framed the direct impact as “less than 0.01% of total SAND supply,” even as unofficial mint counts on the affected chains ran into the billions. The project has not published a technical report reconciling its own estimate with the numbers reported by Blockaid and PeckShield, nor has it disclosed a specific dollar-value loss. The gap between “tokens created” and “value actually extracted” is the crux of why outside estimates and the company’s own assessment look so far apart.
South Korean Exchanges Freeze Transfers as Warnings Spread
Regulators didn’t wait for The Sandbox’s official confirmation. Upbit suspended SAND deposits and withdrawals on Ethereum in a notice logged at 10:12 p.m. ET Friday — 11:12 a.m. Korea Standard Time Saturday — citing circumstances suggesting a security incident and invoking a user-protection clause under South Korea’s Virtual Asset User Protection Act. That’s notable because Ethereum is the very network The Sandbox says was never affected by the exploit. Upbit followed with a separate trading caution roughly half an hour later, warning that SAND’s price volatility could widen and pointing users to transaction activity on a specific Base address linked to the suspected breach.
Bithumb suspended SAND deposits and withdrawals from 11:11 a.m. KST Saturday, also citing the user-protection law, while keeping trading open and warning of possible sharp price swings. Neither exchange has given a timeline for when transfers will resume, and both said service would return once network stability is confirmed.
Despite the frozen transfers and ongoing uncertainty, SAND’s market price barely flinched. The token traded around $0.0479 at 4:12 a.m. ET on Saturday, representing an increase of roughly 4.6% within the preceding 24-hour period and roughly 22% over the previous week, putting its market capitalization near $140.8 million, according to CoinGecko figures cited in reporting on the incident. Separate data referenced more than $66 million in 24-hour trading volume and a market cap closer to $136 million, underscoring how little the exploit disrupted secondary-market pricing even as deposit and withdrawal rails stayed shut.
Compensation Plans and an Unfinished Post-Mortem
The Sandbox says it is taking a snapshot of user positions from before the attack and preparing a compensation scheme for eligible participants in the affected liquidity pools, though it has not published a payment schedule. The project has also promised a full incident report and a technical post-mortem as its investigation continues.
For now, plenty remains unresolved. Neither Upbit nor Bithumb has said when SAND transfers will reopen, and The Sandbox hasn’t confirmed Blockaid’s proposed root cause — the compromised LayerZero delegate permissions — in a detailed technical writeup of its own. Until that report lands, the gap between the studio’s “less than 0.01%” impact claim and outside researchers’ multibillion-token mint counts will likely keep fueling questions about how cross-chain bridges verify what they claim to back, and how quickly exchanges are willing to act on suspected breaches even on networks the affected project insists were never touched.
FAQ
What was the nature of the SAND token exploit?
An attacker exploited a vulnerability in The Sandbox’s cross-chain bridge to mint unbacked SAND tokens on Base and BNB Smart Chain, reportedly by hijacking LayerZero delegate permissions on SAND’s omnichain fungible token contract.
Were user wallets or the Ethereum and Polygon SAND affected?
No user wallets were compromised, and SAND tokens on Ethereum and Polygon remained secure throughout the incident, according to The Sandbox.
What actions did exchanges take in response to the vulnerability?
South Korean exchanges Upbit and Bithumb froze SAND deposits and withdrawals, citing user-protection law, with Upbit additionally halting Ethereum transactions despite that network being unaffected.
How is The Sandbox addressing the incident?
The Sandbox has disabled bridging on the affected networks, is preparing a compensation plan for liquidity providers, and has promised a full incident report and technical post-mortem once its investigation concludes.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.




Be the first to comment