A cracked golden coin on a textured surface
Crypto

The Sandbox halts SAND bridging on Base and BNB after unbacked mint exploit

Exchange transfer suspensions and a do-not-trade warning turned bridged SAND into a settlement-risk market while Ethereum and Polygon remained unaffected.

By Emma Carter9 min read

The Sandbox disabled SAND bridging to and from Base and BNB Smart Chain on Aug. 22, 2026 after an exploit enabled the minting of unbacked SAND on those networks. The shutdown, paired with exchange deposit and withdrawal halts, left Base/BNB SAND trading as a redeemability and settlement-risk instrument rather than a clean proxy for canonical SAND.

Key Takeaways

  • The Sandbox disabled SAND bridging to and from Base and BNB Smart Chain after an exploit enabled unbacked SAND minting on those networks.
  • The project warned users not to buy, sell, or trade SAND on Base/BNB due to compromised liquidity, while stating Ethereum and Polygon SAND were unaffected.
  • Blockaid put the nominal face value of unbacked SAND created at roughly $49 billion across 400+ transactions, while PeckShield tracked 14.9 billion SAND minted across two addresses, with both figures framed as nominal creation rather than confirmed losses.
  • Bithumb and Upbit suspended SAND deposits and withdrawals, and SAND fell nearly 10% intraday after the incident before sitting down 0.8% over 24 hours at the time referenced.

Bridge Shutdown Turns Base/BNB SAND Into a Settlement-Risk Market

The Sandbox’s immediate response was blunt: it disabled SAND bridging to and from Base and BNB Smart Chain after detecting an exploit that allowed unbacked SAND to be minted on those networks. That decision matters less as a headline than as a market-structure change, because it breaks the normal assumption that a bridged representation can be redeemed back to the canonical asset.

The project also told users not to buy, sell, or trade SAND on Base and BNB, explicitly citing compromised liquidity. For traders, that is the key operational detail. Once a bridge is shut and the issuer is warning against trading on the destination chains, Base/BNB SAND stops behaving like “SAND with a different gas token” and starts behaving like a potentially unredeemable claim whose price can gap away from Ethereum-based SAND.

In practice, the shutdown isolates the affected tokens on Base and BNB. If a holder cannot bridge out, then “exit liquidity” becomes whatever is left in local pools and venues on those chains, and any price you see there is as much about who is trapped as it is about SAND’s broader market.

How the Exploit Worked: approveAndCall, LayerZero Delegate Permissions, and Unbacked Minting

Blockaid flagged the exploit while it was underway and described the path in terms that will be familiar to anyone who has watched cross-chain incidents repeat: an attacker allegedly hijacked LayerZero delegate permissions through an “approveAndCall” function, then minted unbacked SAND on Base and BNB.

At a high level, the failure mode is about authorization in the cross-chain messaging and minting flow. Bridges that rely on message passing and delegated permissions are effectively running a distributed “mint on destination if the source-side conditions are satisfied” system. If an attacker can obtain or spoof the right to act as a delegate, or can abuse a combined approval-and-execution pattern like “approveAndCall,” they can push the destination chain into minting representations that were never properly collateralized.

That is why the phrase “unbacked” is doing so much work here. The risk is not just that extra tokens appear on a destination chain, it is that those tokens are not supported by the locked reserves that normally make a bridged asset redeemable. Once that happens, the bridge operator has two bad options: keep the bridge open and risk further minting and downstream contamination, or shut it and strand whatever is already on the destination chain.

The Sandbox chose the second option, disabling bridging on Base and BNB to isolate the tokens and prevent further movement or redemption through the bridge while it assesses scope.

Reconciling the Headline Numbers: $49B ‘Nominal’ vs 14.9B Tokens vs ‘<0.01% impact’

The incident’s public footprint is being shaped by three magnitude claims that do not naturally reconcile, and the gap between them is where traders should be most careful about reading “size” as “loss.”

Blockaid estimated the nominal face value of unbacked SAND created at roughly $49 billion across more than 400 transactions. The key qualifier is embedded in the same description: this is not money stolen or necessarily available to the attacker. It is a face-value calculation that applies SAND’s market price to tokens that were minted without backing, and it far exceeds the liquidity that would be required to actually sell anything close to that amount.

PeckShield separately identified 14.9 billion SAND minted across two addresses. That is a token-count framing rather than a dollar framing, and it was described as being captured at a different stage of the incident. It is still nominal creation, not a confirmed measure of realized proceeds.

Then there is The Sandbox’s own statement that the exploit represented less than 0.01% of SAND’s 3 billion token supply, which would imply fewer than 300,000 SAND when measured directly against supply. The project did not define what it meant by “impact,” and it did not reconcile that claim with the much larger nominal mint figures cited by security firms.

Two contextual anchors help keep the numbers grounded. First, SAND’s market capitalization was stated as roughly $136 million at the time referenced, which makes any multi‑billion or tens‑of‑billions “value” figure obviously a nominal construct rather than a realizable one. Second, the bridge shutdown itself caps one obvious extraction route: if the minted tokens cannot be redeemed back through the bridge, the attacker’s ability to turn them into canonical SAND depends on whatever liquidity existed locally on Base and BNB before the shutdown and before counterparties pulled.

Until a technical post-mortem clarifies what was minted, what was swapped, and what—if anything—was actually realized, the cleanest way to treat the $49 billion and 14.9 billion figures is as measures of unauthorized issuance, not as a loss tally.

Containment Status: What’s Unaffected, What’s Frozen, and Where Liquidity Broke

The Sandbox’s containment message was designed to draw a hard perimeter around the damage. It said SAND on Ethereum and Polygon was unaffected, and it stated that no user wallets were compromised. It also said the SAND locked on Ethereum to back-bridge tokens remains intact, which is the critical claim for anyone trying to distinguish “bridge representation broke” from “canonical collateral was drained.”

The operational reality, though, is that Base/BNB SAND is frozen in the sense that it cannot be moved or redeemed via the bridge while bridging is disabled. That is why the project’s do-not-trade warning matters. When liquidity is “compromised,” it is not just that spreads widen. It is that the market may be pricing a token that is no longer confidently redeemable, and that can create violent dislocations between chains even if the canonical asset is fine.

Centralized exchanges added another layer of friction. Bithumb and Upbit suspended SAND deposits and withdrawals after citing suspected security issues, which can trap traders on venue and slow down the arbitrage and inventory movements that normally stabilize price during cross-chain incidents.

Price action in the immediate window reflected that confidence shock. SAND saw a near 10% intraday drop after the incident was unveiled, and it was down 0.8% over 24 hours at the time referenced.

Signals Traders Should Track: Post‑Mortem, Snapshot/Compensation, and Exchange Transfer Restarts

The next leg of this story is procedural, and it will matter more than the initial headline numbers.

The Sandbox said it is taking a snapshot from before the incident and preparing compensation for qualifying users of the affected liquidity pools, but it has not published the snapshot timestamp or the eligibility rules and timeline. Those details determine who is made whole, who eats slippage, and whether liquidity providers on Base/BNB are treated as victims of a protocol failure or as counterparties who assumed bridge risk.

The project also said it would publish a technical post-mortem later. That document is where the incident’s competing magnitude claims either get reconciled or remain a lingering credibility problem. Traders should be looking for three concrete clarifications: the precise root cause in the LayerZero delegate-permission path, the full accounting of what was minted and where it moved, and an explanation of how the project’s “<0.01%” “impact” statement was calculated.

Finally, watch for whether and when Base/BNB SAND bridging is re-enabled, and whether liquidity and pricing on those networks normalize before any reopening. A restart without restored confidence tends to recreate the same settlement-risk trade, just with more throughput.

On the centralized side, the practical signal is simple: whether Bithumb and Upbit resume SAND deposits and withdrawals, and whether other venues expand similar restrictions. Transfer halts are not just an inconvenience. They change who can arbitrage, who can hedge, and how quickly dislocations can clear.

My Read: This Was a Liquidity-and-Confidence Shock More Than a ‘$49B Theft’—But the Bridge Trust Hit Is Real

The filing-equivalent detail in this incident is the bridge shutdown and the explicit do-not-trade warning on Base and BNB, because that is the moment bridged SAND stopped being a clean wrapper and started being a settlement-risk market. The $49 billion figure is grabbing attention, but it is best read as a nominal face-value artifact of unauthorized minting, not as a measure of extractable profit or confirmed losses, especially against a stated SAND market cap of roughly $136 million and a bridge that was quickly disabled.

The harder part is the inconsistency between the public magnitude statements. If PeckShield can point to 14.9 billion SAND minted across two addresses, and Blockaid can point to 400+ transactions with a nominal $49 billion face value, then The Sandbox’s “<0.01%” “impact” claim needs a definition that survives scrutiny. There are plausible ways those statements could coexist if “impact” is being defined narrowly, for example as net realized extraction, net effect on backing collateral, or some subset of affected pools, but none of that is confirmed yet. The threshold that matters is whether the post-mortem provides a reconciled accounting that ties minted amounts to actual on-chain flows and explains what was prevented by the shutdown versus what escaped into liquid markets.

Two scenarios follow from that. If the post-mortem shows limited realized proceeds, intact Ethereum backing, and a clear remediation of the LayerZero delegate-permission path, then this starts to look like a sharp but containable confidence event where the main damage was localized to Base/BNB liquidity and to the bridge’s reputation. If, instead, the accounting remains fuzzy, compensation terms are slow or narrow, and exchange transfer halts persist or spread, then the market will keep pricing a longer-lived trust discount into anything that depends on that bridge, even if Ethereum and Polygon SAND remain technically unaffected.

This only becomes structurally important if the post-mortem reconciles the nominal mint numbers with a credible loss and remediation story, and the bridge can restart without Base/BNB SAND trading like a separate, impaired instrument.

Sources