The Sandbox has suspended cross-chain transfers on Base and BNB Smart Chain after an exploit in its SAND bridge deployment allowed an attacker to mint large amounts of unbacked tokens. The company said the abnormal tokens have been isolated and that SAND on Ethereum and Polygon was not affected.

Exploit tied to bridge permissions
According to security firm Blockaid, the attacker may have used the approveAndCall function to hijack LayerZero delegate permissions. That access would have given the attacker privileged control over the cross-chain contract, making it possible to mint tokens on other chains without a corresponding amount of Ethereum-based SAND being locked.
At an early stage of the incident, on-chain monitors found that more than 500 million SAND had been minted abnormally on Base. PeckShield later said two addresses received about 14.9 billion SAND. While the attack was still unfolding, Blockaid estimated that more than 400 transactions had produced unbacked SAND with a notional value of roughly $49 billion based on market prices at the time.
Notional value was far above actual loss
The report said the multibillion-dollar figure reflected the face value of the improperly minted tokens at prevailing market prices, not The Sandbox’s realized loss. Once large amounts of SAND were minted out of thin air, on-chain systems would still price them at market rates, but available liquidity would not be enough to absorb that scale of new supply. That also meant the unbacked tokens would be difficult to sell at normal prices.
According to tracking by on-chain researchers, about 14.75 million Ethereum-backed SAND left the bridge adapter during the attack. Some of those tokens were sold for about 80 ETH, worth roughly $675,000 at the time. The Sandbox said the direct impact was below 0.01% of SAND’s 3 billion total supply and that it is still waiting for a full technical report to reconcile differences across chain data.
That is why early claims that $500 million had been stolen were described as inaccurate. The report said the $500 million figure mainly came from the initial observation that more than 500 million SAND had been minted abnormally, while the actual asset loss still requires confirmation through the company’s investigation.
Base and BNB Smart Chain bridge functions halted
After detecting the issue, The Sandbox shut down bidirectional bridge functions for Base and BNB Smart Chain. That move prevents unbacked SAND on the affected networks from being transferred or redeemed through the official bridge system. The company also urged users to pause SAND trading on Base and BNB Smart Chain and avoid supplying funds to related liquidity pools.

The Sandbox said the locked assets on Ethereum that back cross-chain SAND remain intact, user wallets were not breached, and SAND on Ethereum and Polygon was unaffected. The team has taken a snapshot based on the state before the attack and plans to provide a compensation proposal for eligible affected liquidity providers. A timetable has not yet been announced.
South Korea’s major exchanges Upbit and Bithumb also moved quickly. After detecting a potential security issue, both restricted SAND deposits and withdrawals and warned investors that price swings could be severe.
SAND briefly fell nearly 10%
After the incident became public, SAND at one point fell close to 10% intraday. The decline later narrowed after The Sandbox said the vulnerability had been contained. With the unbacked tokens isolated on the affected networks, the immediate risk of those tokens directly impacting SAND supply on Ethereum has also been reduced.
The incident has renewed scrutiny of permission management in cross-chain bridges. The report noted that LayerZero’s OFT architecture typically works by locking tokens on the native chain and minting an equivalent amount on the destination chain. If delegate or similar administrative permissions are taken over by an attacker, that collateral relationship can break down.
The Sandbox has not yet released a full investigation report. Questions remain over how the vulnerability formed, the size of the final asset outflow, and when bridge services on Base and BNB Smart Chain will resume.

