The Sandbox shut down cross-chain bridging on Base and BNB Smart Chain on Saturday. An apparent exploit let an attacker mint unbacked SAND tokens on both networks. On-chain security firm Blockaid pegged the face value near $49 billion across roughly 400 transactions.
Impact stayed under 0.01% of total SAND supply, the web3 gaming platform said. No user wallets were compromised, according to a post on X by The Sandbox team. Tokens on Ethereum and Polygon were unaffected. The SAND locked on Ethereum backing all bridged tokens remains intact.
“An attacker was able to mint unbacked SAND on Base and BSC,” the Sandbox team wrote on X. “We have disabled bridging to and from both networks, so SAND on Base and BSC is currently isolated and cannot be moved or redeemed.” A separate post said the team had “identified and fully contained” the vulnerability and called the impact “minimal.”
The attack hit the SAND cross-chain OFT on Base. That is a LayerZero token contract. Blockaid said the attacker hijacked LayerZero delegate permissions via the approveAndCall function, bypassing normal controls to mint tokens with no underlying collateral. PeckShield tracked 14.9 billion SAND appearing across two addresses tied to the attack, labeled 0xAbE0…4D22 and 0x638C…F296. Coinpedia cited separate on-chain data showing roughly 500 million SAND created at one point, about 17% of the token’s 3 billion supply. Blockaid, PeckShield, and CertiK all flagged the incident on Saturday.
The $49 billion figure is face value. Not stolen funds. It reflects what the unbacked tokens would be worth at full market price. The gap between that headline number and the “under 0.01%” claim comes down to exit liquidity. Thin order books on Base and BSC meant most of the minted SAND had no real buyers. Some funds did move. Roughly 79.74 ether (ETH), worth about $675,000, was reportedly converted from the Ethereum OFT adapter, according to on-chain data cited by Coinpedia.
Sandbox later said it had “fixed” the security issue. Blockaid’s initial alert landed around the same time and described the attack as still ongoing.
Two Korean exchanges halted SAND operations within minutes of each other. Bithumb suspended deposits and withdrawals at 11:11 a.m. KST, according to CryptoRank. Upbit followed one minute later. Both cited a suspected security incident under South Korea’s Virtual Asset User Protection Act. Upbit extended its freeze to the Ethereum version of SAND, which Sandbox has said was never at risk.
The company is taking a pre-incident snapshot and preparing compensation for eligible liquidity providers. A full post-mortem has been promised. No timeline set for resuming bridging on Base and BNB Chain.
Open questions remain. The total dollar value of realized losses beyond the roughly $675,000 in ETH reportedly converted. How LayerZero delegate permissions were compromised. Whether the attacker sold minted tokens before bridging was halted. The attacker’s identity has not been disclosed.
SAND traded up 4.76% at $0.0476 on Saturday. Volume climbed more than 400%, per market data cited by Coinpedia. Holders, as ever, are divided. DefiLlama has logged 17 separate exploits so far in August 2026. Bridges keep showing up as the point of failure.


