The Sandbox Suspends Cross-Chain Bridging Following Unauthorized SAND Token Minting
According to Crypto Briefing and Yellow.com, The Sandbox has suspended SAND bridging on Base and BNB Smart Chain after an attacker exploited a vulnerability in the token bridge.

The incident allowed nearly 14.9 billion unbacked SAND tokens to be minted, although the amount that appears to have reached usable wallets was far smaller. For Web3 gaming users, the immediate issue is not the headline supply figure but whether assets on each network still have valid backing and transferability.
The bridge failed at the permission layer
The affected system used LayerZero’s Omnichain Fungible Token standard, which allows a token to operate across several blockchains without relying on a conventional lock-and-mint bridge. The reported attack targeted the Base-side OFT implementation and the permissions controlling token creation.
According to the reports, the attacker obtained administrative rights through the approveAndCall function. That permission path allowed new SAND to be minted on Base and BNB Smart Chain without a corresponding amount locked on Ethereum. LayerZero itself was not reported as compromised.
This is the relevant failure mode: the bridge did not merely move existing assets incorrectly. It accepted an unauthorized state change at the minting layer. Once that control plane is compromised, on-chain balances can increase without increasing the reserves that are supposed to support them.
The nominal figures are easy to misread. On-chain monitoring estimated almost $49 billion in face-value minting activity, while approximately 14.9 billion SAND were reportedly created across two addresses. Crypto Briefing reported that roughly 14.75 million SAND appeared to have moved into usable wallets. The Sandbox assessed the direct impact at less than 0.01% of the token’s total supply.
Those numbers describe different layers of the incident. The large mint figure represents unauthorized issuance. The smaller transferred amount is closer to the liquidity and settlement risk facing other participants.
What users should verify before touching SAND
The Sandbox has isolated the affected tokens on Base and BNB Smart Chain. Reports say they are non-transferable and non-redeemable against Ethereum-backed reserves. The project warned users not to trade them because the tokens have no backing and are unlikely to be honored.
That makes the practical decision binary: SAND on the affected networks should not be treated as equivalent to backed SAND elsewhere. Users holding or receiving an asset on Base or BNB Smart Chain need to verify the network and contract context before attempting a transfer, swap or redemption. A displayed balance is not proof that the balance can settle through the bridge.
Ethereum and Polygon SAND were reported as unaffected. That does not restore the halted bridge, but it separates the reported exposure by network. South Korea’s Upbit and Bithumb suspended SAND deposits and withdrawals after the disclosure, indicating that exchange-level settlement was also restricted.
The Sandbox said no user funds were lost and no wallets were compromised, framing the incident as an infrastructure exploit rather than a user-account breach. That distinction matters. It does not make the affected bridge safe to use; it means the reported attack path was aimed at the token system’s administrative and minting controls, not at individual wallet keys.
Liquidity providers face a separate accounting problem. The project said it is preparing compensation for eligible providers using a pre-incident snapshot of affected pools. Until that review is completed, liquidity positions and post-exploit balances should not be assumed to represent recoverable value.
The scalability verdict
The incident is contained in the operational sense: bridging was halted, affected tokens were isolated, and redemption was disabled. The broader architecture remains under scrutiny because the exploit reached the mint authority through a function designed to support token operations.
The next material checkpoint is the promised technical report. It is expected to detail the attack vector, response timeline and wider implications for the system. Until that information is released, the key question is not how many tokens were printed on paper. It is whether the bridge can prove that mint permissions, reserve accounting and cross-chain state transitions are independently constrained.
For now, the verdict is clear: SAND remains a live gaming asset, but the Base and BNB Smart Chain bridge path has failed its scalability test. Cross-chain throughput is irrelevant when authorization latency and state validation permit unbacked issuance.