Back Cryptorank The Sandbox Contains Bridge Exploit After Unbacked SAND Minted on Base and BSC
The Sandbox contained a vulnerability in its SAND cross-chain bridge after attackers minted unbacked SAND on Base and BNB Smart Chain, with Blockaid flagging roughly $49 billion face-value minted across ~400 transactions while the project says impact is under 0.01% of total supply and that Ethereum and Polygon balances are intact. Bridging to Base and BSC has been disabled and Korean CEXs Bithumb and Upbit halted SAND deposits and withdrawals; the team warned users not to trade isolated liquidity, is preparing compensation for affected LPs, and the incident highlights recurring bridge security risks in crypto and DeFi.
See what traders are focused on
The Sandbox said it has contained a vulnerability in the SAND cross-chain bridge on Base and BNB Smart Chain after an attacker minted unbacked tokens on both networks.
The project put the impact at under 0.01% of the total SAND supply. It said that tokens on Ethereum (ETH) and Polygon (POL) are unaffected and that no user wallets were compromised.
Blockaid flagged the incident on Saturday. The firm said attackers hijacked LayerZero delegate permissions through the approveAndCall function.
“~$49B face-value SAND minted so far across ~400+ txs,” Blockaid said .
#PeckShieldAlert Seems like The @TheSandboxGame ( $SAND ) got exploited. 14.9B $SAND minted across 2 addresses: 0xAbE0…4D22 & 0x638C…F296 pic.twitter.com/a5Jgym87gR
The team said that it has disabled bridging to and from Base and BSC, cutting off any route to move or redeem the minted supply. It said the SAND locked on Ethereum , which backs all bridged tokens, remains intact.
“An attacker was able to mint unbacked SAND on Base and BSC. We have disabled bridging to and from both networks, so SAND on Base and BSC is currently isolated and cannot be moved or redeemed,” the post read.
The project told holders not to buy, sell, or trade SAND on either network, warning that liquidity there is compromised. It is taking a pre-incident snapshot and preparing compensation for qualifying liquidity providers, with a full post-mortem promised.
Meanwhile, Bithumb suspended SAND deposits and withdrawals at 11:11 a.m. KST, and Upbit followed one minute later. Both cited suspected security incidents under South Korea’s Virtual Asset User Protection Act.
Upbit imposed a halt on the Ethereum version of SAND, which the project has since said was never at risk.
The incident fits a wider pattern . DefiLlama has logged 17 separate exploits so far this month, most of them small, with bridges again the recurring weak point.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
