The Sandbox confirmed a bridge exploit on Aug. 21 that allowed an attacker to mint 14.9 billion unbacked SAND tokens on Base and BNB Smart Chain. Blockchain security firm Peckshield identified the unauthorized mint across two distinct addresses.

The attacker manipulated the cross-chain bridge's minting mechanism, creating SAND tokens without corresponding collateral locked on Ethereum, the source chain. The Sandbox's bridge infrastructure normally locks SAND on one network and mints an equivalent, fully backed amount on the destination chain. This 1:1 backing model broke during the exploit.

The scale is staggering: 14.9 billion unbacked tokens represent nearly five times SAND's total supply of 3 billion across all networks. The fabricated tokens had no underlying asset support.

The Sandbox disabled bridging on both Base and BSC immediately after detection, blocking further token movement. Genuine SAND tokens held on Ethereum and Polygon remained secure. User wallets and Ethereum-locked assets backing the token were unaffected. The company said less than 0.01 percent of SAND's total supply in backing terms was at risk.

Mint-based attacks exploit smart contract minting functions rather than directly stealing locked collateral. In early 2026, a Polkadot bridge exploit minted 1 billion unauthorized DOT tokens. Another incident created roughly 13.76 million unbacked ALPH tokens on the Alephium bridge. Bridge exploits have caused over $320 million in losses across crypto during the first half of 2026.

The Sandbox is preparing a compensation plan for liquidity providers affected by the unbacked minting. The platform advised users to avoid trading SAND on Base or BSC until bridges are fully restored and verified. SAND was trading near $0.039 this week.