The Sandbox said it has "identified and fully contained" a vulnerability in the SAND cross-chain bridge that let an attacker mint unbacked SAND on Base and BNB Smart Chain, and that it has switched off bridging to and from both networks, leaving the SAND on those chains isolated and unable to be moved or redeemed.
In a statement posted at 3:22 a.m. ET Saturday, the studio behind the virtual-world game told users not to buy, sell or trade SAND on Base or BSC because liquidity on those networks is compromised. It said no user wallets were compromised, that SAND on Ethereum and Polygon is unaffected, and that the SAND locked on Ethereum backing all bridged SAND is fully intact. It put the impact at "less than 0.01% of total SAND supply."
Security firm Blockaid described the mechanism hours earlier. Attackers hijacked LayerZero delegate permissions through a function called `approveAndCall` on SAND's omnichain fungible token contract on Base, the firm said. An omnichain fungible token, or OFT, is the cross-chain version of a token, and its delegate role governs who is authorized to mint new units on a given chain. Blockaid put the face value minted at about $49 billion across more than 400 transactions as of 12:14 a.m. ET, and said the attack was still going.










