The Sandbox Bridge Got Exploited, and Attackers Were Minting Fake SAND Before the Team Could Stop It
An attacker found a vulnerability in The Sandbox's cross-chain bridge and minted unbacked SAND tokens on both Base and BNB Smart Chain before the project could shut it down.
The Sandbox confirmed the exploit and said it has now been contained. The team put the total impact at under 0.01% of the entire SAND supply, framing the damage as minimal. But the fact that an attacker could mint tokens out of thin air on two separate chains without immediate detection is a detail that deserves more scrutiny than that figure suggests.
What Actually Happened
Cross-chain bridges work by locking tokens on one network and minting equivalent tokens on another. When that minting mechanism breaks, attackers can create supply that has no backing on the origin chain. That is exactly what happened here.
The attacker exploited the vulnerability on both Base and BNB Smart Chain. The Sandbox says SAND on Ethereum and Polygon is completely unaffected, and that no user funds were lost. The bridge has been paused while the team works through remediation.
The 0.01% figure sounds small, but context matters. SAND has a total supply of 3 billion tokens. Even a fraction of a percent represents tens of millions of tokens that briefly existed without any real backing.
Why This Pattern Keeps Repeating
Bridge exploits are not new. They have drained billions from the crypto ecosystem over the past three years, with Ronin, Wormhole, and Nomad among the most damaging. The attack surface for any protocol connecting two blockchains is significant, and The Sandbox joins a long list of projects that discovered this the hard way.
What separates this incident from the worst cases is speed of containment and scale. The Sandbox appears to have moved quickly, and the exploit did not reach the size of historical bridge disasters. But the vulnerability existed, someone found it, and they used it.
What SAND Holders Should Watch
The immediate threat appears contained, but three things are worth monitoring closely over the next 48 to 72 hours.
First, watch whether any unbacked SAND reached open market liquidity. If exploited tokens were dumped before containment, selling pressure could emerge on exchanges even after the bridge is patched.
Second, watch for a full post-mortem. How the vulnerability was introduced and how long it existed before discovery matters enormously for trust in the protocol's security posture.
Third, watch SAND price action on Ethereum and Polygon specifically. The team says those chains are clean, but market sentiment rarely separates the headlines from the technical details.
The Sandbox built a metaverse on trust. A bridge exploit, even a contained one, costs something that does not show up in a 0.01% figure.