The Sandbox Says It Contained Bridge Exploit That Minted Unbacked SAND on Base and BSC
Key Takeaways
- •The Sandbox said it contained a bridge exploit that minted unbacked SAND on Base and BNB Smart Chain.
- •The incident affected bridge infrastructure and created SAND that was not backed by collateral locked on the origin chain.
- •The project paused bridging on the affected networks after the exploit was identified.
- •The available information does not indicate a flaw in the native SAND contract on Ethereum.
- •The exact amount minted and the status of any supply reconciliation have not been confirmed in the current evidence.

The Sandbox said it contained a bridge exploit that minted unbacked SAND on Base and BNB Smart Chain (BSC), an asset-integrity incident that touched the token's cross-chain supply rather than a single wallet or a routine transfer. SAND is the native token of The Sandbox, a virtual-world gaming platform where users build and monetize voxel-based experiences, and it is issued as an ERC-20 token on Ethereum, with bridged representations of the asset circulating on other networks.
What Happened in the SAND Bridge Exploit
The incident hit the bridge infrastructure connecting SAND across chains — not an ordinary token transfer — and resulted in the creation of SAND tokens that were not backed by collateral locked on the origin chain, as reported by The Defiant.
The unbacked SAND was minted on both Base and BSC, spanning two separate networks where the bridged representation of the token circulates. Base is the Ethereum layer-2 network launched by Coinbase, while BNB Smart Chain is the EVM-compatible chain associated with Binance; bridged deployments on both let SAND move between ecosystems without going through a centralized exchange. The Sandbox stated that it contained the exploit, a claim that originates from the project itself rather than an independent audit, per co-founder Sebastien Borget in a post on X. The Sandbox's official account also addressed the incident on X.
The project subsequently halted bridging activity across the affected networks, pausing the movement of SAND over the Base and BNB Chain bridges. Pausing a bridge severs the mint path it depends on, which is why it is the standard first move in this class of incident, buying time while supply is reconciled.
Why Unbacked Cross-Chain Minting Is a Risk Event
Unbacked minting breaks the core invariant of a bridge: every wrapped or bridged unit is supposed to be redeemable against collateral locked on the source chain. When tokens appear without that backing, the bridged supply no longer reconciles with the canonical supply, creating an accounting mismatch.
Cross-chain bridges have historically been among the costliest points of failure in crypto: the 2022 Ronin Network exploit drained roughly $600 million, Wormhole lost about $320 million the same year, and Chainalysis attributed the majority of funds stolen in crypto hacks in 2022 to bridge attacks. That track record is why unbacked mints on any bridge draw immediate attention from security teams regardless of the token involved.
Because the mints landed on both Base and BSC, the risk is not isolated to one liquidity pool or one deployment. Attacker-minted SAND that reaches an AMM can be sold against real liquidity, draining honest LPs and transferring the loss to depositors and holders of the bridged asset.
The threat surface here is the bridge layer specifically. The available information does not establish any flaw in the underlying SAND contract on its native chain, so the exploit should be read as a cross-chain messaging or mint-authority failure rather than a compromise of the base token itself. Security firm Blockaid flagged activity tied to the incident in its own post on X.
What to Watch After Containment
Containment is a claim about stopping the bleeding, not proof of full remediation. The open questions are whether the unbacked SAND is burned, how the project reconciles bridged supply against locked collateral, and when — or whether — bridging resumes on each chain.
A credible post-mortem should account for the exact minted amount, the mint-authority path the attacker used, and the reconciliation of supply across Base and BSC. None of those figures are confirmed in the current evidence, and readers should treat any specific loss numbers circulating elsewhere as unverified until the project publishes an incident report.
The most concrete near-term signal will be the bridge restart status per network, since a resumed bridge implies the mint-authority defect has been closed and supply has been reconciled.