Sandbox Bridge Exploit Mints 500M Unbacked SAND on Base and BSC
The Sandbox discovered and contained a vulnerability in its cross-chain bridge affecting Base and BNB Smart Chain after an attacker minted approximately 500 million unbacked SAND tokens. The project halted bridging on both networks and stated the impact represents less than 0.01% of total SAND...
Sandbox Bridge Exploit Mints 500M Unbacked SAND on Base and BSC
The Sandbox contained a vulnerability in its cross-chain bridge after an attacker minted approximately 500 million unbacked SAND tokens across Base and BNB Smart Chain, the project confirmed this week.
The team halted bridging on both affected networks following discovery. Ethereum and Polygon deployments remained unaffected. The Sandbox characterized the total impact as less than 0.01% of SAND's circulating supply, a figure that reflects how quickly the team closed the vulnerability before broader damage could occur.
"The Sandbox said it has contained a vulnerability in the SAND cross-chain bridge on Base and BNB Smart Chain after an attacker minted unbacked tokens on both networks. The project put the impact at under 0.01% of the total SAND supply."
The Sandbox, official statement
Five hundred million tokens sounds alarming in isolation. SAND's total supply runs into the tens of billions, making the minted amount negligible relative to on-chain totals. The attacker exploited a flaw in the bridge's minting logic on two chains, but the core Ethereum contract, where the canonical SAND supply is anchored, remained intact.
South Korean exchanges Upbit and Bithumb froze SAND transfers under local user-protection law, a standard precautionary move when a token faces a security event. Upbit's response was notably broad: it halted deposits and withdrawals on Ethereum despite that network being entirely unaffected by the exploit. Such over-reach frustrates users but reflects the conservative posture Korean exchanges adopted after regulators scrutinized the sector following the Terra-LUNA collapse in 2022.
Bridge exploits have caused some of the worst losses in DeFi history. The Ronin bridge hack in March 2022 drained $625 million. Poly Network lost $611 million in August 2021. Nomad shed $190 million in August 2022. What separates the Sandbox incident from those precedents is speed of containment. In each prior case, attackers had hours or days to drain funds before teams could respond. Here, the window closed before minted tokens caused measurable market disruption.
The structural concern persists. Cross-chain bridges require trust assumptions that single-chain protocols do not. They hold or control large asset pools, and their minting logic must be airtight across every chain they touch. A flaw in one chain's implementation can be exploited independently of others, which is exactly what happened here. The Sandbox's Base and BSC bridge had a different vulnerability profile than its Ethereum or Polygon bridges, and the attacker found it.
The incident does not represent a failure of SAND's core tokenomics, given the negligible supply impact. But it adds to a long list of reminders that bridge security remains unsolved. Projects deploying canonical tokens across multiple chains must audit each bridge implementation separately, not assume that a secure Ethereum contract implies secure deployments elsewhere. The Sandbox's rapid response sets the right model. The fact that a response was needed at all is what the industry still needs to fix.



