South Korea · Crypto Briefing
Sandbox pauses Base and BNB Chain bridging after exploit mints billions of unbacked SAND tokens
Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.
◌ Single Source
The Web3 gaming platform contained a cross-chain bridge vulnerability that generated nearly $49 billion in face-value minting activity, though actual losses appear far smaller.
Key facts
- The Sandbox disclosed on August 22 that a malicious actor exploited a vulnerability in its SAND cross-chain bridge on Base and BNB Smart Chain, prompting the gaming platform to suspend all
- The Web3 gaming platform contained a cross-chain bridge vulnerability that generated nearly $49 billion in face-value minting activity, though actual losses appear far smaller
- Approximately 14.9 billion SAND were minted to specific addresses during the exploit
- But the real amount that appears to have been transferred to usable wallets is closer to 14.75 million SAND
Summary
Via dreamfarmagency.com. The Sandbox disclosed on August 22 that a malicious actor exploited a vulnerability in its SAND cross-chain bridge on Base and BNB Smart Chain, prompting the gaming platform to suspend all cross-chain transfers and freeze the token’s functionality on both networks. The attacker leveraged LayerZero’s Omnichain Fungible Token (OFT) standard to mint unbacked SAND tokens by compromising bridge delegate permissions through the approveAndCall function. Approximately 14.9 billion SAND were minted to specific addresses during the exploit.