The Sandbox Confirms 14.7 Million SAND Drained From Ethereum Vault in Bridge Exploit

the sandbox confirms 14 7 million sand drained from ethereum vault in In Brief:

In Brief:

  • A security exploit cost The Sandbox 14,742,341.84 SAND taken from its Ethereum vault.
  • Weaknesses in the LayerZero bridge on Base and BNB Chain opened the door for the attacker to mint tokens without authorization.
  • SAND on Ethereum and Polygon was never compromised, but the episode is another reminder of how fragile cross-chain bridges remain.

Security exploit details

According to The Sandbox, the attacker pulled 14,742,341.84 SAND out of its Ethereum vault — roughly 0.5 percent of total supply. That is far above the figure floated at first, which put the loss below 0.01 percent and covered only the earliest containment window. The revised number came out of a forensic review, and the studio has framed the disclosure as part of its transparency commitment.

What caused the breach?

At the root of the problem was the SAND token’s deployment as a dual-purpose contract serving the LayerZero bridge. By abusing a configuration function, the attacker installed themselves as the only verifier for inbound bridge messages. From there they could rubber-stamp their own transactions and mint unbacked SAND on Base and BNB Chain, with no matching tokens locked up on Ethereum.

The incident has been classified as an attack against LayerZero’s Omnichain Fungible Token standard. A third-party audit had covered the SAND contract before it went live, and The Sandbox is now looking into how the flaw slipped through.

Real impact vs. perceived damage

Figures circulating for the minted tokens climbed as high as 49 billion USD, but the genuine loss comes to 14,742,341.84 SAND — the only tokens in the vault that could actually be redeemed. Everything else was unbacked mint with no redemption path.

In the wake of the attack, The Sandbox has told users not to trade SAND on Base or BNB Chain, where liquidity is no longer sound. Holdings on Ethereum and Polygon are unaffected, and no user wallets were touched.

Containment efforts

Bridging to Base and BNB Chain was switched off as the response unfolded, leaving both networks isolated. The studio flagged the attacker’s wallet to TRM Labs and Chainalysis and coordinated with centralized exchanges to halt SAND transactions. It also captured a snapshot from before the incident, which will feed into compensation plans for users affected in liquidity pools.

A full incident report is in preparation, with more on remediation to follow once it is complete. Anyone needing help is directed to contact support.

Recurring bridge vulnerabilities

Few components draw attackers as reliably as bridges do. What this case shows is the danger of merging token contracts with bridge functionality — one weak point is enough to bring down the backing model of an entire digital asset.

That matters especially for web3 gaming audiences. Multi-chain deployments have become the norm, and every additional chain brings more bridges and more verification paths to exploit. BNB Chain has already responded to the broader problem with a hardfork strengthening bridge signature verification.

Worth noting: gameplay in The Sandbox, LAND ownership, and Studio Beta on Ethereum and Polygon are all operating normally. Exposure is limited to users touching SAND on Base and BNB Chain, and The Sandbox is still urging that group to hold off on trading until a remediation plan is in place.