Sunday, August 23, 2026
BTC: $77,658 +0.72% ETH: $2,459 +1.77% SOL: $95.65 +1.87% XRP: $1.52 +3.34% ADA: $0.2277 +0.24%

The Sandbox Halts Base and BNB Chain Bridging After Bridge Exploit

The Sandbox metaverse project suspended SAND cross-chain bridging on Base and BNB Chain after an attacker exploited its bridge to mint unbacked tokens.

The Sandbox disabled SAND token bridging on Base and BNB Smart Chain on August 22 after an attacker used its cross-chain infrastructure to mint unbacked tokens, cutting off the affected assets and warning users to avoid trading SAND on either network.

The metaverse project said it found and “fully contained” the vulnerability, which let an attacker mint SAND on Base and BNB Chain without matching locks on Ethereum. Ethereum and Polygon were untouched. No user wallets were breached, according to Coinpaper. The Sandbox called the damage minimal.

How minimal is open to debate. The project pegged the actual impact at under 0.01% of SAND’s total supply, Coinpaper reported. On-chain data tells a different story. Blockaid estimated roughly $49 billion in face-value SAND was minted across more than 400 transactions, though that number applies market price to unbacked tokens rather than reflecting what the attacker actually pulled out, Stocktwits noted. PeckShield flagged about 14.9 billion SAND minted to two attacker addresses, roughly five times the token’s 3 billion max supply.

The gap between The Sandbox’s “minimal” framing and the sheer scale of the nominal mint comes down to the difference between real reserves and face value. The SAND locked on Ethereum that backed all bridged tokens stayed intact, The Sandbox said. The unbacked tokens landed on Base and BNB Chain, where liquidity is now suspect.

The Sandbox disabled transfers in both directions on the affected networks and told users not to buy, sell or trade SAND on Base or BNB Smart Chain. The project is preparing a snapshot from before the incident and said qualifying liquidity providers will be made whole. A full post-mortem is expected once the investigation wraps.

South Korean exchanges moved quickly. Bithumb suspended SAND deposits and withdrawals at 11:11 a.m. Korea time on August 22. Upbit followed one minute later, Coinpaper reported. Both pointed to security concerns under South Korea’s Virtual Asset User Protection Act. Upbit initially froze Ethereum-based SAND transfers too, despite The Sandbox saying the Ethereum token was never at risk.

The exploit ran through LayerZero-powered bridge infrastructure, Stocktwits reported. That same framework was behind the April 2026 KelpDAO incident, when attackers tied to North Korea’s Lazarus Group drained nearly $290 million in rsETH by forging a cross-chain message. LayerZero later admitted it had let its own verification network secure high-value assets, a choice it called a mistake.

Bridge exploits have been a recurring headline through 2026. Coinpaper noted several bridge-related incidents during July, when reported crypto theft reached $247.4 million. A Coreum bridge flaw allowed nearly 200,000 XRP to be drained without compromising XRP Ledger validator keys. Harmony halted its bridge after a suspected unauthorized mint of roughly 4 billion ONE tokens.

SAND was down 0.6% over 24 hours but up over 16% on the week, Stocktwits reported. Traders, as ever, disagree on whether that resilience reflects confidence in containment or simply thin liquidity on the affected chains.

What remains unclear: the exact dollar value the attacker walked away with, the technical mechanics of the mint, whether the attacker has been identified, and when bridging will resume on Base and BNB Chain. The Sandbox has not set a timeline.