The Sandbox ($SAND) has been hit by a serious cross-chain exploit, and the numbers coming out of the incident are pretty wild.
The attacker appears to have compromised delegate permissions connected to the LayerZero-based SAND infrastructure on Base and BNB Chain. This allowed unauthorized minting of SAND through the affected OFT contracts.
Billions of SAND were then minted across hundreds of transactions. Some reports put the nominal value of the newly created tokens at nearly $49B, but this is important: $49B was NOT stolen. Those were unbacked tokens created through the exploit and didn’t represent $49B of real value.
The attacker did manage to extract real value, with early analysis pointing to around 14.75M SAND plus roughly 79.7 ETH.
The Sandbox has since contained the incident and suspended SAND bridging to and from Base and BNB Chain. Ethereum and Polygon SAND were reportedly not affected, and the team says the underlying Ethereum backing remains intact.
If you’re holding SAND on Base or BNB Chain, I’d be very careful right now. Avoid interacting with suspicious contracts or unofficial bridges until the situation is fully resolved.
What makes this incident interesting is that the token itself wasn’t necessarily “hacked.” The bigger problem was the cross-chain infrastructure and the permissions controlling how SAND could be minted and moved between networks.
The main thing I’m watching now is the attacker wallets, where the newly minted SAND is moving, how much liquidity was actually extracted, and what The Sandbox reveals in its final post-mortem.

This is a good reminder that in cross-chain crypto, the security of the bridge and its permissions can be just as important as the security of the token itself.