LF Wallet promotion offering up to 1,000,000 LF rewards with Google Play and App Store download options.Sponsored
Base Daily News
LF Wallet promotion offering up to 1,000,000 LF rewards with Google Play and App Store download options.Sponsored
Base

The Sandbox Contains SAND Bridge Vulnerability Affecting Base and BSC

The Sandbox contained a SAND bridge vulnerability affecting Base and BNB Smart Chain, with unbacked tokens minted before bridging was disabled.

6 min read
The Sandbox Contains SAND Bridge Vulnerability Affecting Base and BSC

The Sandbox has contained a vulnerability in its SAND cross-chain bridge that allowed an attacker to mint unbacked SAND tokens on Base and BNB Smart Chain (BSC).

The metaverse gaming platform said it identified and contained the issue and described the overall impact as minimal, estimating that the affected amount represented less than 0.01% of SAND’s total supply.

The incident was isolated to specific cross-chain infrastructure. According to The Sandbox, SAND on Ethereum and Polygon was not affected, while SAND locked on Ethereum as backing for bridged tokens remained secure.

LF Wallet promotion offering up to 1,000,000 LF rewards with Google Play and App Store download options.Sponsored

The Sandbox Disables SAND Bridging on Base and BSC

After detecting the vulnerability, The Sandbox disabled SAND bridging to and from Base and BNB Smart Chain.

The emergency measure was intended to prevent additional unbacked SAND from moving across the affected networks and to isolate the compromised bridge infrastructure.

The Sandbox also advised users to avoid buying, selling or providing liquidity for SAND on Base and BSC while the investigation continues.

The project's official announcement said that SAND on Ethereum and Polygon remained unaffected.

The Sandbox official website

Billions of Unbacked SAND Were Reportedly Minted

The incident initially generated significant concern because blockchain security firms reported extremely large amounts of SAND being created.

PeckShield reported that approximately 14.9 billion SAND had been minted across two attacker-controlled addresses. That figure is several times greater than SAND's stated maximum supply of 3 billion tokens.

Blockaid separately reported that unbacked SAND with a nominal value of nearly $49 billion had been minted across more than 400 transactions.

However, the reported $49 billion figure should not be interpreted as $49 billion being stolen.

The figure represents the nominal market value assigned to newly minted tokens. Unbacked tokens created on an affected network are fundamentally different from legitimate SAND withdrawn from the project's underlying reserves.

The Actual Loss Appears to Be Much Smaller

On-chain analysis cited in reports surrounding the incident indicates that approximately 14.75 million SAND, worth roughly $675,000 at the time, may have been extracted from Ethereum-side bridge reserves, alongside around 80 ETH.

These figures have not been independently confirmed by The Sandbox, so the final financial impact could change once the project's investigation and technical post-mortem are completed.

The distinction is important because the attacker could create a huge nominal amount of SAND without being able to convert all of those tokens into legitimate assets.

The Sandbox itself said the overall impact was below 0.01% of total SAND supply, suggesting that the amount of legitimate value affected was substantially smaller than the headline figures associated with the minting activity.

How the SAND Bridge Vulnerability Worked

The incident centered on the cross-chain implementation of SAND, rather than the core SAND supply on Ethereum.

Security researchers reportedly identified an issue involving the LayerZero-powered omnichain token infrastructure deployed on Base. The attacker allegedly exploited permissions surrounding an approveAndCall mechanism, allowing unauthorized minting of SAND.

In a normal cross-chain system, newly issued tokens on a destination network should correspond to assets locked or otherwise accounted for on the source network.

A vulnerability in that process can break the relationship between the two representations of the asset.

That is what makes bridge vulnerabilities particularly dangerous: an attacker does not necessarily need to compromise the underlying blockchain. Exploiting the mechanism that authorizes cross-chain minting can be enough to create a large amount of unbacked liquidity.

Base and BSC Were the Affected Networks

The vulnerability specifically affected SAND's cross-chain deployments connected to Base and BNB Smart Chain.

Base is Ethereum's Layer 2 network developed by Coinbase and has become one of the largest ecosystems for on-chain applications, DeFi and consumer-focused blockchain projects.

Base official website

The incident therefore highlights an important risk for projects expanding token liquidity across multiple networks: each additional deployment introduces additional contracts, permissions and bridging infrastructure that must be secured.

The Sandbox said the affected bridges were disabled following the incident.

Ethereum and Polygon SAND Remain Unaffected

The Sandbox emphasized that the vulnerability did not compromise the core SAND ecosystem on Ethereum or Polygon.

According to the project's disclosure:

  • Ethereum SAND was not affected.

  • Polygon SAND was not affected.

  • SAND locked on Ethereum as bridge backing remained secure.

  • Bridging on Base and BSC was disabled.

  • The project said user wallets were not compromised.

  • The Sandbox is preparing a compensation plan for eligible liquidity providers.

The project also said it was taking a snapshot of positions from before the incident to help determine which liquidity providers may qualify for compensation.

South Korean Exchanges Suspend SAND Transfers

The incident also affected centralized exchanges operating in South Korea.

Upbit and Bithumb temporarily suspended SAND deposits and withdrawals following the security incident.

Such exchange restrictions are common during major token-security events because exchanges need to prevent potentially compromised or unbacked assets from entering or leaving their platforms while the situation is investigated.

The incident therefore demonstrates how a vulnerability limited to a particular blockchain deployment can have consequences across the wider trading ecosystem.

What the Base Incident Means for Cross-Chain Security

The SAND incident highlights a broader challenge facing multichain applications.

Projects increasingly deploy tokens across Ethereum, Layer 2 networks and alternative blockchains to reach users and liquidity. However, cross-chain deployments require additional infrastructure for:

  • Token minting and burning

  • Message verification

  • Bridge authorization

  • Liquidity management

  • Cross-chain accounting

  • Smart-contract permissions

A weakness in any one of these components can create an imbalance between legitimate token supply and the amount represented on another network.

For Base in particular, the incident reinforces the importance of auditing bridge contracts and token permissions as more consumer applications and gaming projects expand onto the network.

The Sandbox Plans Post-Mortem and Compensation

The Sandbox said it will publish a full incident report and technical post-mortem explaining the vulnerability and the measures taken to contain it.

The project is also working on a compensation plan for eligible liquidity providers affected by the incident.

The final report should help clarify several outstanding questions, including how the attacker obtained the ability to mint SAND, how much legitimate value was ultimately extracted and what changes will be made to the bridge infrastructure.

Until those details are released, users should remain cautious when interacting with SAND on Base and BSC.

What Happens Next for SAND on Base?

The immediate priority is preventing further exploitation and ensuring that the cross-chain supply of SAND is correctly reconciled.

The Sandbox will likely need to complete its investigation, assess affected liquidity providers and implement additional security controls before normal bridging activity resumes.

For Base users, the key development to watch is confirmation from The Sandbox that SAND bridging has been fully secured and officially restored.

Until then, users should avoid relying on unofficial bridges or attempting to interact with contracts associated with the affected infrastructure.

Conclusion

The Sandbox has contained a vulnerability affecting the SAND cross-chain bridge on Base and BNB Smart Chain, after attackers reportedly gained the ability to mint large quantities of unbacked tokens.

While security researchers reported billions of SAND being created, the amount of legitimate value apparently extracted was far smaller. The Sandbox estimates that the overall impact was below 0.01% of SAND's total supply and says that SAND on Ethereum and Polygon remained unaffected.

The incident nevertheless highlights the risks of cross-chain token infrastructure. A vulnerability in a bridge or minting mechanism can create massive amounts of nominally valuable tokens even when the underlying asset reserves remain largely intact.

For the Base ecosystem, the episode is another reminder that multichain growth must be matched by strong contract security, permission controls and independent auditing.

The upcoming post-mortem and compensation plan should provide a clearer picture of the exploit and the safeguards being introduced to prevent a repeat incident.

Disclaimer

This article is for informational purposes only and does not constitute financial, investment, or trading advice. Cryptocurrency markets are highly volatile and carry significant risk. Always conduct your own research (DYOR) and consult a qualified financial advisor before making investment decisions. Past performance does not guarantee future results.

Stay on top of Base

Onchain culture, Base DeFi, and Coinbase ecosystem news delivered daily.

No spam, ever. Unsubscribe in one click.

Related Base News

Comments (0)

Comments are reviewed before publishing.

No comments yet. Be the first.

LF Wallet promotion offering up to 1,000,000 LF rewards with Google Play and App Store download options.Sponsored