{"id":22818,"date":"2026-08-22T21:01:41","date_gmt":"2026-08-22T21:01:41","guid":{"rendered":"https:\/\/cryptoted.net\/index.php\/2026\/08\/22\/sand-bridge-exploit-contained-after-unbacked-token-mint\/"},"modified":"2026-08-22T21:01:41","modified_gmt":"2026-08-22T21:01:41","slug":"sand-bridge-exploit-contained-after-unbacked-token-mint","status":"publish","type":"post","link":"https:\/\/cryptoted.net\/index.php\/2026\/08\/22\/sand-bridge-exploit-contained-after-unbacked-token-mint\/","title":{"rendered":"SAND bridge exploit contained after unbacked token mint"},"content":{"rendered":"<p> <br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/media.crypto.news\/2023\/10\/crypto-news-Platypus-regains-90-of-funds-from-exploit01.webp\" \/><\/p>\n<div>\n<p class=\"is-style-lead\">The Sandbox has contained a cross-chain bridge vulnerability that allowed an attacker to mint unbacked SAND on Base and BNB Smart Chain, with the project estimating the direct impact at less than 0.01% of the token\u2019s 3 billion supply.<\/p>\n<div id=\"cn-block-summary-block_70d393e0b998418a324f1c18759e62bb\" class=\"cn-block-summary\">\n<p>\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/p>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>The attacker minted unbacked SAND on Base and BNB Smart Chain through compromised bridge permissions.<\/li>\n<li>The Sandbox disabled transfers involving both networks while keeping Ethereum and Polygon SAND unaffected.<\/li>\n<li>Upbit and Bithumb halted SAND deposits and withdrawals after detecting a possible security incident.<\/li>\n<li>On-chain researchers estimated that about 14.75 million Ethereum-backed SAND left the bridge adapter.<\/li>\n<li>The Sandbox plans to compensate eligible liquidity providers based on balances recorded before the attack.<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>The Sandbox said it had fully contained the vulnerability affecting its SAND bridge on Base and BNB Smart Chain, adding that no user wallets were compromised and SAND held on Ethereum and Polygon remained secure.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">The Sandbox team has identified and fully contained a recent vulnerability regarding the SAND cross-chain bridge on Base and BNB Smart Chain (BSC). The impact is minimal, representing less than 0.01% of the total SAND token supply.<\/p>\n<p>SAND tokens on Ethereum and Polygon are NOT\u2026<\/p>\n<p>\u2014 The Sandbox (@TheSandboxGame) <a rel=\"nofollow\" href=\"https:\/\/x.com\/TheSandboxGame\/status\/2091063415649251821?ref_src=twsrc%5Etfw\">August 22, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>In an August 22 <a href=\"https:\/\/x.com\/TheSandboxGame\/status\/2091063415649251821\" target=\"_blank\" rel=\"nofollow\">statement<\/a>, the metaverse project said the attacker created tokens on Base and BNB Smart Chain without the SAND needed to back them on Ethereum. The team disabled bridging to and from both networks, isolating the affected tokens and preventing them from being redeemed through the official bridge.<\/p>\n<p>\u201cAll bridged SAND funds are backed by SAND locked on Ethereum, which remains entirely secure,\u201d the project said.<\/p>\n<p>Users were told not to buy, sell, or provide liquidity for SAND on Base or BNB Smart Chain while the affected deployments remain isolated. The team is also taking a snapshot from before the attack and said eligible liquidity providers would receive compensation, although it did not give a payment schedule.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<h2 class=\"wp-block-heading\">How the SAND bridge exploit created unbacked tokens<\/h2>\n<p>Early on-chain alerts showed more than 500 million SAND minted on Base, but the reported figure climbed rapidly as the attacker continued interacting with the contract.<\/p>\n<p>PeckShield later identified about 14.9 billion SAND created across two addresses. Other security researchers recorded hundreds of additional transactions, producing much larger estimates for the total number of unbacked tokens generated before the bridge was disabled.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\"\/>\n<p>The size of the minted amount did not represent the project\u2019s direct financial loss. SAND created on Base or BNB Smart Chain could not increase the Ethereum token\u2019s fixed maximum supply of 3 billion unless the attacker could use the cross-chain system to release genuine tokens locked in the Ethereum adapter.<\/p>\n<p><a href=\"https:\/\/x.com\/BlockWatchdog\/status\/2091049803627045075\" target=\"_blank\" rel=\"nofollow\">According<\/a> to blockchain forensics account BlockWatchdog, the attacker withdrew approximately 14.75 million SAND from the Ethereum adapter in less than one minute. Token sales generated about 80 ETH, valued at roughly $675,000 at the time of the transactions.<\/p>\n<p>The figure helps explain why The Sandbox placed the impact below 0.01% of the total SAND supply even though the number of tokens minted on the affected networks appeared far larger. The project has not yet published a full technical report reconciling its loss estimate with the figures reported by individual on-chain researchers.<\/p>\n<p>Blockaid attributed the incident to the takeover of LayerZero delegate permissions through a <code>approveAndCall<\/code> function. The security firm said the access allowed the attacker to mint tokens through the affected cross-chain contracts, though The Sandbox has not confirmed Blockaid\u2019s proposed cause in a detailed postmortem.<\/p>\n<h2 class=\"wp-block-heading\">Why Ethereum SAND supply has remained unchanged<\/h2>\n<p>LayerZero\u2019s Omnichain Fungible Token standard uses linked contracts to move assets between blockchains. Under its adapter model, an existing token is locked on its original network while an equivalent amount is minted at the destination.<\/p>\n<p>For SAND, the Ethereum adapter holds the original tokens intended to support cross-chain balances. A legitimate transfer to Base should lock SAND on Ethereum before creating the corresponding amount on Base, preserving one supply across the connected networks.<\/p>\n<p>Unauthorized minting broke the backing relationship on the affected chains, but it did not rewrite the Ethereum token contract or raise its maximum supply. CoinGecko continued to show a maximum supply of 3 billion SAND, with about 2.9 billion tokens in circulation.<\/p>\n<p>To stop the affected contracts from communicating with other deployments, The Sandbox removed the LayerZero peer settings for Base and BNB Smart Chain. The action cut off the official route through which unbacked tokens might otherwise have been used to claim assets held by the Ethereum adapter.<\/p>\n<p>A similar difference between a bridge failure and a problem with the underlying blockchain appeared during July\u2019s <a href=\"https:\/\/crypto.news\/wanchain-cardano-bridge-exploit-drains-515m-night-worth-9m\/\" target=\"_blank\">Wanchain bridge exploit<\/a>. About 515 million NIGHT left Wanchain\u2019s Cardano-side treasury, while the Midnight Foundation said its core network, validators and consensus system remained unaffected.<\/p>\n<p>In another July incident, an attacker used the Verus bridge\u2019s import path to trigger <a href=\"https:\/\/crypto.news\/verus-ethereum-bridge-hacked-again-for-7-54m-after-may-exploit\/\" target=\"_blank\">unbacked asset payouts<\/a> worth about $7.54 million. Blockaid linked the attack to the same bridge contract and apparent bug class involved in an earlier May breach.<\/p>\n<h2 class=\"wp-block-heading\">Korean exchanges restrict SAND transfers<\/h2>\n<p>Upbit issued a caution notice after finding signs of a possible security problem involving SAND, warning that the incident could produce sharp price movements. Bithumb separately suspended SAND deposits and withdrawals while it reviewed the issue.<\/p>\n<p>Reports citing the exchange notices placed Bithumb\u2019s suspension at 11:11 a.m. Korea Standard Time on August 22, followed by Upbit about one minute later. Trading restrictions and transfer suspensions can differ, so users must check each exchange\u2019s notice before placing an order or attempting to move SAND.<\/p>\n<p>The quick response is consistent with South Korean exchange procedures for assets facing suspected network faults, abnormal token issuance, or security incidents. Deposit restrictions can limit the chance that tokens created through a compromised network reach an exchange and are sold against unaffected balances.<\/p>\n<p>SAND traded near $0.05 after the disclosure, while CoinGecko reported more than $66 million in 24-hour volume. The data provider placed the token\u2019s market capitalization near $136 million and showed an increase of about 18% over seven days, though prices varied across trading venues.<\/p>\n<h2 class=\"wp-block-heading\">Base users face isolated liquidity risk<\/h2>\n<p>For U.S. users, the immediate connection comes through Base, the Ethereum layer-2 network developed by U.S.-listed exchange Coinbase. The reported vulnerability affected The Sandbox\u2019s cross-chain contracts deployed on Base rather than Base\u2019s underlying network, according to the available project and security disclosures.<\/p>\n<p>The Sandbox\u2019s warning applies to anyone holding or trading the isolated Base version of SAND, including U.S. users accessing decentralized exchanges through self-custody wallets. Tokens available in Base liquidity pools may not carry the same backing as Ethereum-native SAND while the official bridge remains disabled.<\/p>\n<p>The incident follows an April attack involving another LayerZero-powered asset. As crypto.news reported, LayerZero\u2019s <a href=\"https:\/\/crypto.news\/layerzero-details-292m-kelpdao-exploit-and-tightens-bridge-security\/\" target=\"_blank\">KelpDAO incident report<\/a> said attackers stole about 116,500 rsETH worth $292 million after compromising infrastructure used by a single-verifier cross-chain configuration.<\/p>\n<p>Following the KelpDAO attack, LayerZero said its verification network would stop signing messages for applications using a one-of-one verifier setup and encourage projects to adopt multiple independent verifiers. The Sandbox has not said whether its SAND configuration used the same model or whether the latest vulnerability involved LayerZero\u2019s verification network.<\/p>\n<p>The Sandbox, an Animoca Brands subsidiary that raised $93 million in 2021, said it would publish further information as its investigation proceeds. Its latest notice did not provide a date for restoring Base and BNB Smart Chain transfers or specify when compensation claims for eligible liquidity providers would open.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/crypto.news\/sand-bridge-exploit-contained-unbacked-token-mint\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Sandbox has contained a cross-chain bridge vulnerability that allowed an attacker to mint unbacked SAND on Base and BNB Smart Chain, with the project estimating the direct impact at less than 0.01% of the token\u2019s 3 billion supply. Summary The attacker minted unbacked SAND on Base and BNB Smart Chain through compromised bridge permissions. [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":21749,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"tdm_status":"","tdm_grid_status":"","footnotes":""},"categories":[23],"tags":[],"kronos_expire_date":[],"class_list":["post-22818","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto"],"_links":{"self":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts\/22818","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/comments?post=22818"}],"version-history":[{"count":0,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts\/22818\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/media\/21749"}],"wp:attachment":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/media?parent=22818"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/categories?post=22818"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/tags?post=22818"},{"taxonomy":"kronos_expire_date","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/kronos_expire_date?post=22818"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}