The Sandbox said it has "identified and fully contained" a vulnerability in the SAND cross-chain bridge that allowed an attacker to mint unbacked SAND on Base and BNB Smart Chain, and has switched off bridging to and from both networks, leaving SAND on those chains isolated and unable to be moved or redeemed.
In a statement posted at 3:22 a.m. ET Saturday, the studio behind the virtual-world game told users not to buy, sell or trade SAND on Base or BSC because liquidity on those networks is compromised. It said no user wallets were compromised, that SAND on Ethereum and Polygon is unaffected, and that the SAND locked on Ethereum backing all bridged SAND is fully intact. The company put the impact at "less than 0.01% of total SAND supply."
Security firm Blockaid described the mechanism hours earlier, saying attackers hijacked LayerZero delegate permissions through a function called approveAndCall on SAND's omnichain fungible token contract on Base. An omnichain fungible token, or OFT, is the cross-chain version of a token, and its delegate role governs who is authorized to mint new units on a given chain. Blockaid put the face value minted at about $49 billion across more than 400 transactions as of 12:14 a.m. ET, and said the attack was still going.
PeckShield, in an alert published at 1:40 a.m. ET, counted 14.9 billion SAND minted across two addresses, 0xAbE0...4D22 and 0x638C...F296, holding 14.65 billion and 250 million SAND respectively, credited in repeated transfers from the null address dated Aug. 22. That figure is several times SAND's entire circulating supply of about 2.94 billion, against a 3 billion maximum, according to CoinGecko. The Sandbox has not said what its "less than 0.01%" figure measures or published a loss figure in dollars, and Blockaid's and PeckShield's totals, published an hour and a half apart, have not been reconciled.




