Sandbox bridge exploit lets hackers mint $49 billion in fake SAND

A vulnerability tucked inside The Sandbox’s cross-chain bridge briefly let an attacker conjure billions of unbacked SAND tokens out of thin air, setting off a scramble across South Korean exchanges before the metaverse studio said it had shut the breach down. The Sandbox bridge exploit, which hit deployments on Base and BNB Smart Chain in the early hours of August 22, 2026, has left security researchers and the project itself disagreeing sharply over how much damage was actually done.
Key takeaways
- The Sandbox says it fully contained a vulnerability in its SAND cross-chain bridge that let an attacker mint unbacked tokens on Base and BNB Smart Chain.
- Bridging between both affected networks has been disabled; The Sandbox says no user wallets were hit and that SAND on Ethereum and Polygon remains secure.
- Security firm Blockaid estimated roughly $49 billion in minted fake SAND across more than 400 transactions, while PeckShield counted 14.9 billion SAND minted across two addresses.
- The Sandbox itself puts the real impact at less than 0.01% of total SAND supply, a figure it has not fully reconciled with outside researchers’ numbers.
- Upbit and Bithumb froze SAND deposits and withdrawals in South Korea under the country’s Virtual Asset User Protection Act, with Upbit also suspending Ethereum transfers despite that chain being unaffected.
The Sandbox Contains a Cross-Chain Bridge Vulnerability
The Sandbox says the breach is over: the studio behind the virtual-world game announced it had “identified and fully contained” the flaw that allowed an attacker to mint unbacked SAND on Base and BNB Smart Chain. In a statement posted around 3:22 a.m. ET on Saturday, the team told users not to buy, sell, trade or provide liquidity for SAND on either network while the affected deployments remain isolated.
… Continue reading the full article at the original source below.


