A hacker minted up to 14.9 billion fake SAND tokens through two wallet addresses on the Base and BNB Smart Chain networks without providing any underlying collateral assets. Initial reports from research firm PeckShield regarding the token amount were immediately addressed by The Sandbox. The Web3 game developer confirmed that they have fully secured the vulnerability on the cross-chain bridge that served as the exploit’s entry point. This illegal token minting exploited a protocol loophole that allowed the perpetrator to bypass the requirement of depositing original SAND tokens as collateral on the Ethereum mainnet.
As an emergency response, The Sandbox immediately disabled all bridging functions for the Base and BNB Chain networks. This access closure aimed to isolate the unbacked token stockpile so that the hacker had no way to swap them through the project’s official bridge. The developer emphasized that user balances remain safe from the impact of the exploit. All SAND assets stored on the Ethereum and Polygon networks are confirmed to be unaffected, as their value is fully backed by tokens that remain securely locked within the Ethereum adapter.
LayerZero Loophole and Lightning-Fast Execution
Security firm Blockaid suspects that this hack stemmed from a compromise of LayerZero delegation permissions. The attacker exploited the cross-chain bridge’s security system by calling the approveAndCall function. In its blockchain execution, this fund draining process occurred within a narrow window of time.
Tracking data from BlockWatchdog shows that the hacker withdrew approximately 14.75 million original SAND from the Ethereum adapter in less than a minute. The stolen assets were not held for long, but were instead immediately dumped onto the open market by the perpetrator. From this series of flash sales, the hacker pocketed about 80 ETH in liquid funds, equivalent to $675,000 at the time of the incident.
Crypto Exchange Emergency Measures
The 14.9 billion fake SAND minted by the perpetrator exceeds the project’s total maximum supply, which has been capped at 3 billion SAND since the beginning. Although the discrepancy looks massive on paper, the direct financial loss estimate for The Sandbox ecosystem was kept below 0.01% of the original total supply, thanks to network isolation measures that cut off the hacker’s access.
However, the incident still triggered a wave of caution in the secondary crypto market. Major crypto exchanges in South Korea, such as Upbit and Bithumb, took preemptive steps by suspending deposit and withdrawal services for the SAND token. The decision to block this inflow and outflow was made to avoid the risk of price instability, preventing a worst-case scenario where the hacker might find another loophole to deposit the illegal tokens and disrupt the exchanges’ order books.
For retail traders on centralized exchanges, this service suspension serves as a stark reminder that protocol vulnerabilities always bring secondary risks. User funds within smart contracts might be safe, but their smooth trading access on local exchanges can grind to a sudden halt when a cross-chain bridge is hacked. Reported by crypto.news.
Read also: What is an NFT and How Does It Work?
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




