The Sandbox said on 22 August 2026 that it had identified and fully contained a vulnerability in the SAND cross-chain bridge on Base and BNB Smart Chain (BSC), after an attacker minted large volumes of unbacked SAND on those networks while Ethereum and Polygon SAND stayed intact.
What The Sandbox confirmed
In an 22 August statement on X, quoted in full by crypto.news and covered the same day by CoinDesk, the Animoca Brands metaverse project said:
- The vulnerability on the Base and BSC SAND bridges was identified and fully contained.
- Direct impact was less than 0.01% of SAND’s roughly 3 billion maximum supply.
- SAND on Ethereum and Polygon was not affected.
- No user wallets were compromised.
- Bridging to and from Base and BSC is disabled, isolating the affected deployments so unbacked tokens cannot redeem through the official bridge.
- “All bridged SAND funds are backed by SAND locked on Ethereum, which remains entirely secure.”
- Users should not buy, sell, trade, or provide liquidity for SAND on Base or BSC while those deployments stay isolated.
- The team is taking a pre-attack snapshot and preparing compensation for eligible liquidity-pool users, with a full technical post-mortem still to come.
That is the project’s public line. Treat the loss percentage and the “fully contained” claim as company statements until the promised post-mortem lands with on-chain reconciliation.
How the mint worked (and why the huge numbers mislead)
SAND’s multi-chain setup uses LayerZero’s Omnichain Fungible Token (OFT) pattern: lock SAND in an Ethereum adapter, mint a matching balance on a destination chain. A healthy bridge keeps one economic supply across networks. An unhealthy one can mint on the far side without a matching lock.
Security firm Blockaid, cited by crypto.news and CoinDesk, attributed the break to a takeover of LayerZero delegate permissions through an approveAndCall path on the SAND OFT contracts (especially on Base). That access let the attacker mint destination-chain SAND without backing it on Ethereum. The Sandbox has not yet published a detailed root-cause confirmation of Blockaid’s write-up.
On-chain alerts moved fast:
- Early flags showed 500 million+ SAND minted on Base.
- PeckShield later reported about 14.9 billion SAND minted across two addresses.
- Some face-value tallies (market price × unbacked tokens) ran into the tens of billions of dollars. Those figures are not stolen treasury and not liquidatable value; they count paper tokens on isolated chains.
The number that matches The Sandbox’s “under 0.01%” framing is the real Ethereum-backed drain. Blockchain forensics account BlockWatchdog, per crypto.news, estimated about 14.75 million SAND — roughly $675,000 worth — left the Ethereum adapter in under a minute, and that about 79.7 ETH was realised selling it. Those two figures are not the same number: with ether trading around $2,400–$2,500 that weekend, 79.7 ETH is nearer $195,000. The gap between what left the adapter and what the attacker actually banked is slippage — the cost of dumping that much of a mid-cap token into available liquidity at once. Unbacked Base/BSC tokens could not raise Ethereum’s fixed max supply; CoinGecko continued to show a 3 billion cap with about 2.9 billion circulating.
To finish the cut-off, The Sandbox removed LayerZero peer settings for Base and BSC so the compromised contracts could no longer talk to other deployments through the official path.
Exchanges react, users should too
South Korea’s Upbit and Bithumb suspended SAND deposits and withdrawals on 22 August after spotting a suspected security issue, according to the same-day reporting. Notices placed Bithumb’s pause around 11:11 a.m. KST, with Upbit following about a minute later. Spot trading can remain open even when transfers are frozen, so check each venue’s own notice before you try to move coins.
For anyone holding SAND (including LatAm traders who keep multi-chain balances on Bitso, Binance, or a self-custody wallet), the practical filter is simple:
- Ethereum and Polygon SAND are the deployments The Sandbox says stayed backed and unaffected.
- Base and BSC SAND are the deployments the project told you not to trade or LP into while bridges stay off.
- Do not chase “cheap” SAND on the isolated chains; unbacked inventory is the whole point of the warning.
- Wait for the project’s post-mortem and any LP compensation details before you treat Base/BSC liquidity as repaired.
Bridge risk is not a LatAm-only story, but it hits the same way every region learns it: the token ticker looks identical in the wallet UI while the chain underneath is what actually failed. If your portfolio tool collapses every SAND balance into one number, expand the chain column before you rebalance.
Takeaway
On 22 August 2026, The Sandbox froze Base and BNB Smart Chain bridging for SAND after an OFT-permission exploit minted huge volumes of unbacked tokens on those networks, while the project and independent reporters said Ethereum-locked backing and Polygon balances held. The scary billion-token mint counts and the sub-million-dollar real drain can both be true; they measure different things.
Until the post-mortem and LP snapshot land, treat Base/BSC SAND as compromised inventory, verify any exchange deposit/withdrawal pause on the venue’s own notice, and keep chain-level balances in view rather than a single ticker total. This is incident reporting, not advice to buy, sell, or hold SAND.



