Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

tradingview+1beincryptobeincrypto+1The Sandbox , a metaverse gaming platform, halted cross-chain bridging on Base and BNB Smart Chain on Saturday after an attacker exploited the project's SAND token bridge in an "infinite mint" attack, creating billions of unbacked tokens that on-chain security firms valued at roughly $49 billion in face terms.
The Sandbox said on Saturday that it had "identified and fully contained" the vulnerability, estimating the impact at under 0.01% of the total SAND supply. The project said no user wallets were compromised, and SAND on Ethereum and Polygon remained unaffected.x
But blockchain security firm PeckShield flagged 14.9 billion SAND minted across two attacker addresses — roughly five times the token's 3 billion maximum supply. Blockaid, which first flagged the incident, said attackers hijacked LayerZero delegate permissions through the "approveAndCall" function, minting approximately $49 billion in face-value SAND across more than 400 transactions. The "$49 billion" figure reflects the market price applied to unbacked tokens rather than funds the attacker actually extracted.tradingview+2
The Sandbox disabled bridging to and from both Base and BSC BNB , isolating the minted tokens so they cannot be moved or redeemed. The team warned users not to buy, sell, or trade SAND on either network and said it was taking a pre-incident snapshot to prepare compensation for affected liquidity providers.beincrypto+1
South Korean exchanges moved quickly to protect users. Bithumb suspended SAND deposits and withdrawals at 11:11 a.m. KST, with Upbit following one minute later, both citing suspected security incidents under South Korea's Virtual Asset User Protection Act. Upbit imposed a halt on the Ethereum version of SAND, which The Sandbox has said was never at risk.beincrypto
Despite the scale of the exploit, SAND's price remained relatively stable, declining less than 1% over 24 hours while holding gains of more than 16% on the week.stocktwits
The exploit marks the latest incident involving LayerZero-powered bridging infrastructure in 2026. In April, attackers linked to North Korea's Lazarus Group drained nearly $290 million from KelpDAO's LayerZero bridge by forging a cross-chain message. LayerZero later acknowledged it "made a mistake" by allowing its own verification network to secure high-value assets in a vulnerable configuration.tradingview
The Sandbox said a full post-mortem would follow, with affected users directed to contact support at [email protected].x