The Sandbox, the blockchain-based metaverse and gaming platform, faced a significant security incident involving its cross-chain bridging infrastructure. The vulnerability allowed an unauthorized party to generate large volumes of SAND tokens without proper collateral on the Base and BNB Smart Chain networks.
Security researchers first detected unusual activity around August 21–22, 2026.
Firms such as Blockaid and PeckShield reported that an attacker had compromised permissions tied to the project’s LayerZero-based Omnichain Fungible Token (OFT) setup.
By exploiting a function known as approveAndCall, the actor gained the ability to create tokens on the secondary chains without corresponding locked SAND on Ethereum.
The Sandbox team has identified and fully contained a recent vulnerability regarding the SAND cross-chain bridge on Base and BNB Smart Chain (BSC). The impact is minimal, representing less than 0.01% of the total SAND token supply.
SAND tokens on Ethereum and Polygon are NOT…
— The Sandbox (@TheSandboxGame) August 22, 2026
Early alerts noted hundreds of millions of tokens appearing, with subsequent tallies showing roughly 14.9 billion SAND directed to a pair of addresses linked to the activity.
Broader estimates placed the face-value total of newly created tokens in the tens of billions of dollars across hundreds of transactions.
Some analyses even described far higher nominal figures distributed over multiple addresses during a multi-hour window.
Despite the scale of the unauthorized minting, the real-world financial impact remained limited.
Investigators determined that only about 14.75 million legitimately backed SAND—valued at approximately $675,000 at the time—left the Ethereum-side bridge adapter, along with a modest amount of ETH.
The Sandbox itself assessed the overall effect at less than 0.01 percent of the token’s legitimate maximum supply of 3 billion.
The project responded swiftly.
Officials confirmed they had identified and fully contained the issue.
Bridging functions to and from Base and BNB Smart Chain were disabled, effectively isolating the unbacked tokens so they could not be moved or redeemed against the Ethereum collateral.
SAND held on Ethereum and Polygon remained completely unaffected.
No individual user wallets were compromised, and the SAND locked on Ethereum that underpins all bridged tokens stayed secure.
Major exchanges reacted cautiously. South Korean platforms Upbit and Bithumb suspended SAND deposits and withdrawals.
Users were strongly advised not to buy, sell, or trade the token on the affected networks while liquidity there remained compromised.
The Sandbox said it captured a pre-incident snapshot of balances and is preparing a compensation framework for eligible liquidity providers affected by the event.
The team pledged to release a full technical post-mortem once its investigation concludes.
Community members affected by liquidity pool disruptions were directed to contact official support channels.
The episode underscores ongoing challenges with cross-chain bridges and omnichain token designs in the broader cryptocurrency ecosystem.
While the rapid isolation of the affected networks prevented wider damage, it also highlighted how permission and delegate mechanisms can become points of failure.
For SAND holders on the primary chains, the incident appears to have been successfully limited, with core infrastructure and user assets preserved. This event serves as another reminder of the importance of security reviews for multi-chain deployments as blockchain projects continue expanding their interoperability features.