The Sandbox bridge exploit created billions in unbacked SAND — but the real damage was far smaller. An attacker exploited a vulnerability in The Sandbox’s cross-chain bridge on Base (using LayerZero’s Omnichain Fungible Token setup). By hijacking delegate permissions through an approveAndCall function, they were able to mint SAND on Base and BNB Smart Chain without corresponding collateral locked on Ethereum. PeckShield reported roughly 14.9 billion SAND minted across two addresses. Blockaid put the face-value of the unbacked tokens at around $49 billion across more than 400 transactions. Those numbers reflect market price applied to tokens that had no backing — not extractable value. The actual economic loss appears closer to 14.75 million SAND drained from the Ethereum side of the bridge, converting to roughly $675,000 (about 80 $ETH ). Sandbox has disabled bridging to and from both Base and BNB Smart Chain, isolating the affected tokens so they cannot be moved or redeemed. SAND on Ethereum and Polygon was not impacted, and no user wallets were compromised. The project described the impact as under 0.01% of total supply and said it is preparing a compensation plan for affected liquidity providers based on a pre-incident snapshot. This is another reminder of how fragile cross-chain token designs can be. The ability to mint unbacked supply on secondary chains turns a local permission issue into a multi-chain liquidity problem, even when the core collateral on the home chain remains intact. The headline numbers were dramatic. The realized loss was contained ,but the operational response still required shutting down entire bridges.

