EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

SAND Bridge vulnerability controlled after unsecured token minting

2026-08-23 00:38:15
Bookmark

The Sandbox project has controlled a cross-chain bridge vulnerability. Attackers have forged unsupported SAND on Base and BNB intelligent chains.

The Sandbox project has successfully controlled a cross-chain bridge vulnerability that allowed attackers to forge SAND tokens on Base and BNB intelligent chains that are unsupported by actual assets. According to the project party's assessment, the direct impact of this incident is less than 0.01% of the total number of tokens (3 billion).

Event Overview

The attacker created unsupported SAND on the Base and BNB intelligent chains through compromised bridging privileges. The sandbox project has disabled money transfers involving both networks, while SAND on Ethereum and Polygon has not been affected. Upbit and Bithumb exchanges suspended SAND's recharge and withdrawal services after detecting possible security incidents. On-chain researchers estimate that approximately 14.75 million SAND supported by Ethereum have left the bridge adapter. The sandbox project plans to compensate eligible liquidity providers based on account balances before the attack.

Vulnerability Details and Impact Assessment

The sandbox project stated that it has completely controlled the vulnerabilities affecting its SAND bridging function on Base and BNB smart chains, and emphasized that user wallets have not been compromised and that SAND tokens on Ethereum and Polygon are still safe.

The Metaverse project stated in a statement on August 22 that the attackers created tokens on Base and BNB smart chains, but did not lock the corresponding number of SAND on Ethereum as support. The project party has disabled the bridging function with these two networks, isolating affected tokens and preventing them from being redeemed through official bridging channels. The project party pointed out: "All SAND funds that pass through the bridge are supported by SAND locked on Ethereum, and this part of the funds is completely safe."

Users are advised not to buy, sell or provide liquidity to SAND on Base or BNB intelligent chains while affected deployments are quarantined. The team is taking a snapshot of the attack before it occurred and said eligible liquidity providers will be compensated, but has not announced a specific payment schedule.

How attacks cause unsupported tokens

Early on-chain warnings showed that more than 500 million SAND were minted on Base, but the number reported climbed rapidly as attackers continued to interact with contracts. PeckShield later identified that approximately 14.9 billion SAND were created in two addresses. Other security researchers recorded hundreds of additional transactions and came up with a larger estimate of the total number of unsupported tokens generated before bridging was disabled.

The number of coins minted does not represent a direct financial loss to the project. SAND created on Base or BNB smart chains cannot increase the fixed maximum supply of 3 billion chips on Ethereum unless an attacker can use a cross-chain system to release real tokens locked in Ethereum adapters.

According to blockchain forensics agency BlockWatchdog, the attacker extracted approximately 14.75 million SAND from the Ethereum adapter in less than a minute. The token sale generated approximately 80 Ethereum (ETH) units worth approximately US$675,000 based on the transaction price at the time. This number helps explain why the sandbox project assessed the impact as less than 0.01% of SAND's total supply, despite the seemingly large number of tokens minted on the affected networks. The project party has not yet released a complete technical report to reconcile its loss estimates with the values reported by researchers across the chain.

Blockaid attributed the incident to an attacker taking over Delegate privileges from LayerZero through the approveAndCall function. The security company said this authority allows attackers to minte tokens through affected cross-chain contracts. However, the sandbox project has not yet confirmed Blockaid's reasons in a detailed post-mortem analysis.

Why SAND supply on Ethereum remains unchanged

LayerZero's full-chain homogenization token standard uses connected contracts to transfer assets between different blockchains. Under its adapter model, existing tokens are locked in their original network, while an equal amount of tokens is minted in the target network. For SAND, the Ethereum adapter holds original tokens used to support cross-chain balances. For a legal transfer to Base, SAND should be locked on Ethereum, and then the corresponding amount should be created on Base, so as to maintain the same total supply between connected networks.

Unauthorized minting undermined the supporting relationships on the affected chain, but did not rewrite the token contracts on Ethereum or increase its maximum supply. CoinGecko still shows SAND's maximum supply of 3 billion pieces, of which approximately 2.9 billion are in circulation. To prevent affected contracts from communicating with other deployments, the sandbox project removed the LayerPeer settings for Base and BNB intelligent chains. The move cuts off official channels, otherwise unsupported tokens could be used to claim assets held by Ethereum adapters.

Similar differences between bridge failures and underlying blockchain problems also appeared in the Wanchain Bridge attack in July. About 515 million NIGHT tokens left Wanchain's Cardano side treasury at the time, and the Midnight Foundation said its core network, validators and consensus systems were unaffected. In another July incident, attackers used an import path bridged by Verus to trigger unsupported asset payments worth approximately $7.54 million. Blockaid linked the attack to the same bridging contract and a bug apparently similar to the May vulnerability.

Korea Exchange restricts SAND transfers

Upbit issued a warning notice after discovering signs of possible safety issues with SAND, warning that the incident could trigger sharp price fluctuations. Bithumb separately suspended SAND's recharge and withdrawal services and reviewed the incident. Reports citing exchange notices showed that Bithumb suspended service at 11:11 a.m.(Korean Standard Time) on August 22, followed by Upbit for about a minute. There may be differences between transaction restrictions and transfer suspensions, so users need to check the announcements of each exchange before placing an order or attempting to transfer SAND.

This rapid response is in line with the Korea Exchange's processing process for assets facing suspected network failures, abnormal token issuance, or security incidents. Deposit limits reduce the likelihood that tokens created through compromised networks will enter the exchange and be traded with unaffected balances.

After the incident was disclosed, SAND was trading at close to US$0.05, and CoinGecko reported 24-hour trading volume of more than US$66 million. The data platform sets the market value of the token at approximately US$136 million and shows an increase of approximately 18% in the past seven days, but prices vary among trading platforms.

Base users face liquidity risk

For U.S. users, the direct connection lies in Base, the Ethereum Layer 2 network developed by U.S. listed exchange Coinbase. Based on existing projects and security disclosures, the vulnerability reported this time affects sandbox cross-chain contracts deployed on Base, not Base's underlying network. The Sandbox Project's warnings apply to any user holding or trading a quarantined version of Base SAND, including U.S. users who access a decentralized exchange through a self-managed wallet. During the official bridging ban period, tokens available in the Base liquidity pool may not have the same support as Ethereum native SAND.

This incident occurred after another attack involving LayerZero assets. According to previous reports, LayerZero's KelpDAO incident reported that attackers stole approximately 116,500 rsETH worth $292 million after breaching the infrastructure used in a single verifier cross-chain configuration. After the KelpDAO attack, LayerZero said its authentication network would stop signing messages for applications that use one-on-one verifiers settings and encouraged projects to use multiple independent verifiers. The sandbox project has not yet stated whether its SAND configuration uses the same model or whether the latest vulnerability involves LayerZero's verification network.

As a subsidiary of Animoca Brands, the sandbox project raised US$93 million in 2021. The project party said it would release more information as the investigation progresses. Its latest announcement did not provide a specific date for resuming Base and BNB smart chain transfers, nor did it specify when eligible liquidity providers could submit compensation applications.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP