SAND Bridge Exploit Contained After Unbacked Token Mint

9 min read
4 views
Aug 22, 2026

An attacker minted massive unbacked SAND on Base and BNB Smart Chain. The project says the real hit stayed under 0.01 percent of supply, yet liquidity providers still face questions. What happens next for holders remains unclear.

Financial market analysis from 22/08/2026. Market conditions may have changed since publication.

Have you ever watched a bridge get shut down mid-crossing because someone figured out how to walk across without paying the toll? That roughly describes what happened with The Sandbox’s SAND token this week. An attacker found a way to mint unbacked tokens on Base and BNB Smart Chain, and the project moved fast to contain the damage. I’ve been following these cross-chain stories for a while, and this one stands out for how quickly the team isolated the problem while insisting the core Ethereum supply stayed untouched.

What Really Happened With The SAND Bridge Exploit

Early on August 22, alerts started lighting up across on-chain monitoring tools. Someone had managed to create SAND tokens on two secondary networks without locking the equivalent amount on Ethereum. The numbers looked alarming at first glance. Reports mentioned hundreds of millions, then billions of tokens appearing out of thin air. Yet the actual financial hit, according to the project, stayed surprisingly small.

The Sandbox stated that the vulnerability affected only the cross-chain bridge deployments on Base and BNB Smart Chain. No user wallets were compromised. SAND sitting on Ethereum and Polygon remained completely secure. The team disabled transfers involving the two affected networks and told users not to buy, sell, or provide liquidity for those isolated versions of the token.

In my view, the most important detail is the distinction between unbacked minting and actual loss of locked assets. Creating tokens on a secondary chain does not automatically drain the original supply. The attacker still needed a path to redeem those tokens against the real SAND held in the Ethereum adapter. That path was cut off.

How The Unbacked Tokens Appeared

Security researchers tracked the activity in real time. One firm noted roughly 14.9 billion SAND minted across two addresses. Other observers recorded hundreds of additional transactions that pushed the total even higher before the bridge was fully disabled. Those figures sound catastrophic until you remember that the maximum supply of SAND on Ethereum is fixed at three billion tokens.

The minted tokens on Base and BNB Smart Chain existed outside that hard cap. They could not increase the official circulating supply unless the attacker successfully used the bridge to unlock genuine Ethereum-based SAND. Blockchain forensics accounts later estimated that about 14.75 million SAND left the Ethereum adapter in under a minute. Sales of that amount generated around 80 ETH, roughly 675,000 dollars at the time.

That number explains why The Sandbox described the direct impact as less than 0.01 percent of the total three billion supply. The visual scale of the minting was huge. The extractable value was not. Still, the gap between the eye-catching on-chain numbers and the project’s loss estimate leaves room for questions until a full technical report appears.

All bridged SAND funds are backed by SAND locked on Ethereum, which remains entirely secure.

The project has not yet released a detailed postmortem that reconciles every researcher’s count with its own figures. Until then, the 14.75 million figure stands as the most concrete measure of tokens that actually moved out of the adapter.

Possible Root Cause Of The Vulnerability

One security firm pointed to a takeover of LayerZero delegate permissions through an approveAndCall function. That access apparently allowed the attacker to mint through the affected cross-chain contracts. The Sandbox has not publicly confirmed this exact mechanism in a formal write-up, so the explanation remains provisional for now.

Cross-chain systems that rely on linked contracts and adapters carry inherent complexity. Under the Omnichain Fungible Token model, an existing token is locked on its home network while an equivalent amount is minted at the destination. When that locking step can be bypassed, the backing relationship breaks. The secondary tokens become unbacked even though the original contract on Ethereum stays intact.

I’ve seen similar patterns in other bridge incidents this year. A July case involving a different protocol saw hundreds of millions of tokens leave a treasury on one side while the core network itself remained unaffected. Another incident used an import path to trigger unbacked payouts. The common thread is that the bridge, not the underlying blockchain, was the weak point.

Why Ethereum SAND Supply Stayed The Same

This part matters more than many headlines suggested. The Ethereum token contract was never rewritten. Its maximum supply of three billion remained unchanged. Circulating supply figures continued to hover near 2.9 billion. Data providers kept displaying the same hard cap.

To stop any further communication between the compromised deployments and the rest of the system, The Sandbox removed the LayerZero peer settings for Base and BNB Smart Chain. That single action severed the official route that unbacked tokens might have used to claim assets still held by the Ethereum adapter.

Think of it as closing the toll booth after someone has already driven through with a fake ticket. The road itself is still solid. The fake tickets just no longer work.


Immediate Response From The Project

The Sandbox moved quickly. It disabled bridging to and from the two affected networks, isolated the unbacked tokens, and issued a clear warning to users. Anyone holding or trading the Base or BNB Smart Chain versions of SAND was told to stand down. Providing liquidity on those chains was also discouraged while the deployments remained cut off.

The team took a snapshot of balances from before the attack. Eligible liquidity providers will receive compensation based on that snapshot, although no payment timeline has been announced yet. Further updates are promised as the investigation continues. No date has been set for restoring transfers on the two networks.

Perhaps the most reassuring message for everyday holders was the repeated statement that no user wallets were compromised and that SAND on Ethereum and Polygon stayed secure. In a space where bridge exploits often lead to total losses of locked funds, that distinction carries weight.

Korean Exchanges React Fast

Two major South Korean platforms suspended SAND deposits and withdrawals shortly after the news broke. One issued a caution notice after detecting signs of a possible security problem and warned that the incident could produce sharp price swings. The other paused transfers while reviewing the situation.

The timing was tight. Notices went out within a minute of each other during the morning of August 22 local time. Trading restrictions and deposit suspensions can differ across platforms, so users still need to check individual notices before attempting any moves.

This kind of rapid response is consistent with how those exchanges typically handle assets facing abnormal token issuance or suspected network faults. Limiting deposits reduces the chance that tokens created through a compromised path reach the exchange and get sold against unaffected balances.

Price Action And Market Reaction

SAND traded near 0.05 dollars after the disclosure. Twenty-four-hour volume climbed above 66 million dollars. Market capitalization sat around 136 million dollars, with a roughly 18 percent gain over the prior seven days, though prices varied across venues. Later data showed a 24-hour decline of a few percentage points while the seven-day figure remained positive.

Volume spikes after security news are common. Some traders sell first and ask questions later. Others see a contained incident as a buying opportunity. The fact that the project framed the impact as under 0.01 percent of supply likely limited the downside compared with more severe bridge failures.

Still, anyone holding the isolated Base version faces a different reality. Liquidity pools on that network may no longer reflect the same backing as the Ethereum-native token while the official bridge stays disabled. That creates a temporary but real risk for users interacting with those pools through self-custody wallets.

Broader Context Of Cross-Chain Risks

This incident did not occur in isolation. An earlier attack this year involving another LayerZero-powered asset saw attackers steal a significant amount of a different token after compromising infrastructure tied to a single-verifier setup. Following that event, the protocol team indicated it would stop signing messages for applications using one-of-one verifier configurations and encourage multi-verifier designs.

The Sandbox has not stated whether its SAND setup used the same model or whether the latest vulnerability involved the verification network itself. Until the full technical report lands, that remains an open question. What is clear is that complexity in cross-chain messaging continues to create attack surfaces even when the underlying blockchains stay secure.

In my experience covering these stories, the projects that recover best are the ones that communicate early, isolate quickly, and compensate affected parties without over-promising timelines. The Sandbox appears to be following that playbook so far. The missing pieces are the detailed postmortem and the compensation schedule for liquidity providers.

What Holders Should Do Right Now

If you hold SAND on Ethereum or Polygon, the project’s message is that those tokens were never at risk. No action is required beyond normal portfolio management. If you hold the Base or BNB Smart Chain versions, the advice is clearer: do not buy, sell, or add liquidity until further notice.

Liquidity providers who were active on the affected networks before the attack should watch for the snapshot-based compensation process. The project has confirmed that eligible parties will be covered, but the exact claim window and payment method remain unspecified.

  • Avoid interacting with isolated Base or BNB Smart Chain SAND deployments
  • Monitor official project channels for the compensation announcement
  • Verify any exchange notices before attempting deposits or withdrawals
  • Treat secondary-chain prices as potentially disconnected from the main token until bridging resumes

Exchange users in particular should double-check whether their platform has lifted any temporary restrictions. Deposit halts can linger longer than the underlying issue if the exchange wants extra confirmation that the risk has fully passed.

Lessons From Similar Incidents

Bridge exploits have become one of the more expensive categories of crypto security failures. The pattern often looks the same: an attacker finds a way to mint or unlock assets without the proper backing, drains whatever is accessible, and leaves the protocol scrambling to contain the damage and reassure users.

What separates a recoverable event from a catastrophic one is usually the speed of the response and the amount of capital that actually left the system. In this case, the combination of a relatively modest extractable amount and a rapid isolation of the compromised peers kept the direct impact small by industry standards.

That does not mean the incident was cost-free. Liquidity providers on the affected chains face temporary disruption. Users who bought the unbacked tokens after the minting began may hold assets that cannot be redeemed through the official bridge. Trust in the secondary-chain deployments will take time to rebuild even after transfers are restored.

Perhaps the most interesting aspect is how clearly the project drew the line between the bridge and the underlying token. By emphasizing that Ethereum and Polygon SAND remained secure, The Sandbox tried to prevent a broader confidence crisis in the asset itself. Whether that message fully lands will depend on the quality of the eventual postmortem and the fairness of the compensation process.

Looking Ahead For The Sandbox Ecosystem

The Sandbox is a long-running metaverse project under the Animoca Brands umbrella. It raised significant capital years ago and has continued building its virtual world and token economy. A contained bridge issue of this size is unlikely to derail the broader roadmap, but it does highlight the ongoing operational risk of maintaining multi-chain deployments.

Restoring Base and BNB Smart Chain transfers will require more than simply re-enabling the peer settings. The contracts will need review, permissions will need tightening, and users will need clear guidance on how to handle any residual unbacked tokens. The compensation process for liquidity providers will also be watched closely as a signal of how the team treats affected parties.

Until those steps are complete, the safest posture for most holders is patience. Ethereum and Polygon SAND appear unaffected. The secondary-chain versions remain isolated by design. The project has promised further information as the investigation proceeds. In a market that often moves on incomplete information, waiting for the official technical report is usually the better trade.

Cross-chain bridges remain one of the more powerful and more fragile pieces of crypto infrastructure. When they work, they expand utility and liquidity. When they fail, they create exactly the kind of asymmetric risk seen here: large numbers of unbacked tokens appearing on one side while only a fraction of the real value can be extracted on the other. Containing that risk quickly is the difference between a footnote and a crisis. On this occasion, the containment appears to have succeeded.

The story is not finished. A full accounting of the permissions that were compromised, the exact sequence of transactions, and the final compensation amounts will matter for long-term confidence. For now, the main takeaway is that the core SAND supply on its primary networks stayed intact, the vulnerable bridges were shut down, and the direct loss stayed well below one-hundredth of one percent of total supply. That is a better outcome than many similar incidents have produced.

Holders should keep an eye on official updates, avoid the isolated deployments, and treat any secondary-chain pricing as provisional until bridging resumes. The next chapter will depend on how transparently the project closes the remaining open questions. In the meantime, the bridge is closed, the main tokens are still standing, and the market is already moving on to the next headline.

You are as rich as what you value.
— Hebrew Proverb
Author

Steven Soarez passionately shares his financial expertise to help everyone better understand and master investing. Contact us for collaboration opportunities or sponsored article inquiries.

Related Articles

?>