Sandbox Bridge Exploit Mints 14.9 Billion Unbacked SAND as Coinbase Moves to Delist SAND Futures
Key Takeaways
- •The Sandbox confirmed that its token bridge was exploited to mint 14.9 billion unbacked SAND tokens without collateral on the source chain.
- •The unauthorized mint is larger than SAND’s designed 3 billion maximum supply, making the incident unusually severe.
- •Coinbase signaled it will delist SAND futures, reducing a regulated venue for hedging and directional trading.
- •The combined bridge exploit and futures delisting create both supply-integrity concerns and lower derivatives liquidity for SAND.
- •The article says traders are watching for confirmation that the unbacked tokens have been isolated and for further exchange responses.

The Sandbox has confirmed an exploit of its token bridge that resulted in the unauthorized minting of 14.9 billion SAND tokens — a supply shock that landed at the same moment Coinbase moved to delist SAND futures. The incident ranks among the more consequential smart-contract failures for a major metaverse token and underscores how cross-chain infrastructure remains the weakest link in Web3 security. SAND is the utility token of The Sandbox, the Animoca Brands-backed virtual-world platform where it is used to buy LAND parcels and in-world assets, stake, and vote on governance, so supply-integrity questions cut across the platform's entire economy.
What happened in the Sandbox bridge hack
The Sandbox confirmed that an exploit of its token bridge led to the creation of 14.9 billion unbacked SAND, according to crypto.news. The team said the incident was contained, but the minted tokens were not backed by collateral on the source chain.
Bridges operate by holding locked tokens on one chain and minting equivalent representations on another. When the minting authority is compromised, an attacker can produce tokens with no corresponding deposit, diluting the circulating supply and threatening the peg between wrapped and native assets.
Unauthorized minting matters because it attacks tokenomics directly rather than a single wallet. The scale is unusual even by exploit standards: 14.9 billion tokens is roughly five times the 3 billion maximum supply SAND was designed with, meaning the unbacked mint alone exceeds the token's entire intended cap. A bridge that can be tricked into issuing that much SAND undermines confidence in every wrapped SAND balance until the team accounts for and neutralizes the unbacked supply. Bridge failures have repeatedly proven to be the highest-severity class of on-chain incident — Ronin Network lost about $625 million in March 2022, Poly Network about $611 million in 2021, and Wormhole about $325 million in February 2022 — and blockchain analytics firm Chainalysis attributed roughly $2 billion of 2022's crypto thefts to cross-chain bridge hacks, the largest single category that year. It is a pattern that echoes broader hacking enforcement cases now moving through the courts.
Why Coinbase's futures delisting adds pressure to SAND
Coinbase signaled the delisting of SAND futures through its markets channel, in a post on X. The move removes a regulated venue for hedging and directional exposure precisely when traders most want to manage risk around the token.
Delistings reduce access and thin out derivatives liquidity. Fewer venues for futures mean wider spreads and less capacity to short or hedge, conditions that can amplify volatility in the underlying spot market as positions unwind or migrate elsewhere.
The combination of an active bridge exploit and a futures delisting compounds uncertainty. Holders face both a supply-integrity question from the minting event and a liquidity question from the loss of a major derivatives listing — a dual overhang that leaves little room for a clean recovery narrative. Exchanges have generally treated unbacked mints as grounds for suspending deposits of the affected asset until the issuer verifies supply integrity, which frames the question other venues now face with their own SAND listings.
SAND also trades on other venues internationally, with exchanges such as Bithumb publishing notices tied to the token. Traders monitoring the situation will be watching for confirmation that the unbacked SAND has been isolated, for a technical post-mortem from the team, and for any further exchange responses following Coinbase's decision.
Broader implications for cross-chain security
The episode is a reminder that as protocols wire in more automated cross-chain logic — including the oracle- and agent-driven bridging designs increasingly proposed for on-chain AI systems — the security surface expands faster than the auditing that covers it. After the 2022 bridge losses, independent audits, expanded validator oversight, real-time monitoring and bug bounty programs became baseline expectations for bridge operators, and that standard now frames how any return of The Sandbox's bridge would be judged. Any decentralized AI stack that relies on bridged assets for compute payments or data settlement inherits the same minting-authority risk The Sandbox just demonstrated, a governance problem that regulators exploring crypto innovation sandboxes will eventually have to address.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.