Sandbox SAND Bridge Exploit Mints $49 Billion in Fake Tokens Across Base and BSC
Key Takeaways
- •A flaw in The Sandbox's SAND cross-chain bridge allowed an attacker to mint unbacked tokens on Base and BNB Smart Chain, and the project says the vulnerability has been fully contained.
- •Blockchain security firm Blockaid identified roughly $49 billion in face-value fake SAND across more than 400 transactions, a figure reflecting the market value of minted tokens rather than assets stolen from the protocol.
- •The Sandbox shut down all bridging and unbridging between Base and BSC and advised users not to buy, sell, or trade SAND on those networks given impaired liquidity.
- •Ethereum and Polygon deployments were not affected, no user wallets were compromised, and the SAND locked on Ethereum as collateral remains intact.
- •A compensation plan based on a pre-incident snapshot is being prepared for affected liquidity providers, while the investigation, technical post-mortem, and final compensation terms remain pending.

The Sandbox has confirmed and contained a vulnerability in its SAND cross-chain bridge that allowed an attacker to mint unbacked SAND tokens on Base and BNB Smart Chain (BSC). Base is a Coinbase-incubated Ethereum Layer-2 network, while BNB Smart Chain is the EVM-compatible blockchain operated by Binance. SAND — the native token of The Sandbox, an Ethereum-based metaverse gaming platform — normally reaches both chains only by being locked as collateral and minted in equivalent amounts. Blockchain security firm Blockaid identified approximately $49 billion in face-value fake SAND across more than 400 transactions, while the project says the incident represents less than 0.01% of the total SAND token supply.
Bridge Exploit Triggers Emergency Shutdown
According to The Sandbox, the flaw affected the cross-chain bridge infrastructure linking SAND on BSC and Base, meaning an attacker could mint SAND tokens without the backing asset normally required for bridged supply. Bridges of this lock-and-mint design hold the original tokens in reserve on the source chain, so breaking the link between locked collateral and minted supply allows new tokens to be created without any backing.
The project disclosed the incident on X:
The Sandbox team has identified and fully contained a recent vulnerability regarding the SAND cross-chain bridge on Base and BNB Smart Chain (BSC). The impact is minimal, representing less than 0.01% of the total SAND token supply. SAND tokens on Ethereum and Polygon are NOT…
— The Sandbox (@TheSandboxGame), August 22, 2026 (X post)
In response, the project shut down all bridging and unbridging activity between the two networks. As a result, SAND currently held on Base and BSC is isolated: it cannot be transferred back through the bridge or redeemed through the affected cross-chain routes. Halting bridge traffic is a standard containment measure, since the unbacked tokens remain transferable on the destination chains regardless of the bridge's status.
Traders also received a clear warning from The Sandbox, which advised users not to purchase, sell, or trade SAND on either Base or BSC given the state of liquidity on those networks.
The Sandbox said its Ethereum and Polygon deployments were not affected, that no user wallets were compromised, and that the SAND locked on the Ethereum side — the collateral that backs valid bridged tokens — remains intact.
$49 Billion Figure Reflects the Scale of Fake Token Minting
The largest number was reported by blockchain security firm Blockaid, which identified approximately $49 billion in SAND minted at face value through more than 400 transactions.
The figure does not represent the value of assets lost or pulled from the protocol. Rather, it reflects the market value of the large quantity of unbacked tokens created as part of the exploit. That distinction is significant: the attacker-minted SAND carries no reserve backing from the legitimate cross-chain supply and cannot be treated as legitimate liquidity. In practice, unbacked mints damage pooled liquidity rather than locked reserves — any fake tokens sold into Base or BSC pools would come at the expense of the liquidity providers on the other side of those pools, which is the exposure the project's planned compensation targets.
An investigation is ongoing, and The Sandbox said a detailed incident report and technical post-mortem will follow.
Compensation Plan Targets Affected Liquidity Providers
Preparation for a compensation plan is underway, including a snapshot of the Sandbox ecosystem taken prior to the incident. The plan will target BSC users in selected liquidity pools on Base. The project has not yet released the final compensation package or the total amount that may be made available.
The Sandbox stated that there is nothing for regular SAND holders on Ethereum and Polygon to do.
The incident once again brings security concerns around cross-chain infrastructure to the fore. Bridges have repeatedly ranked among crypto's costliest attack surfaces — the Ronin Bridge breach drained more than $600 million in March 2022, Wormhole lost roughly $320 million weeks earlier, and Chainalysis estimated that bridge exploits accounted for about 69% of funds stolen in crypto hacks that year. The Sandbox's immediate focus is to contain the affected networks, analyze the extent of the incident, and repay eligible liquidity providers, with the technical post-mortem, the final compensation terms and eligible pools, and the eventual reopening of Base and BSC bridging as the open items to watch.