Crypto

SAND bridge exploit contained after unbacked token mint


The Sandbox has contained a cross-chain bridge vulnerability that allowed an attacker to mint unbacked SAND on Base and BNB Smart Chain, with the project estimating the direct impact at less than 0.01% of the token’s 3 billion supply.

Summary

  • The attacker minted unbacked SAND on Base and BNB Smart Chain through compromised bridge permissions.
  • The Sandbox disabled transfers involving both networks while keeping Ethereum and Polygon SAND unaffected.
  • Upbit and Bithumb halted SAND deposits and withdrawals after detecting a possible security incident.
  • On-chain researchers estimated that about 14.75 million Ethereum-backed SAND left the bridge adapter.
  • The Sandbox plans to compensate eligible liquidity providers based on balances recorded before the attack.

The Sandbox said it had fully contained the vulnerability affecting its SAND bridge on Base and BNB Smart Chain, adding that no user wallets were compromised and SAND held on Ethereum and Polygon remained secure.

In an August 22 statement, the metaverse project said the attacker created tokens on Base and BNB Smart Chain without the SAND needed to back them on Ethereum. The team disabled bridging to and from both networks, isolating the affected tokens and preventing them from being redeemed through the official bridge.

“All bridged SAND funds are backed by SAND locked on Ethereum, which remains entirely secure,” the project said.

Users were told not to buy, sell, or provide liquidity for SAND on Base or BNB Smart Chain while the affected deployments remain isolated. The team is also taking a snapshot from before the attack and said eligible liquidity providers would receive compensation, although it did not give a payment schedule.

How the SAND bridge exploit created unbacked tokens

Early on-chain alerts showed more than 500 million SAND minted on Base, but the reported figure climbed rapidly as the attacker continued interacting with the contract.

PeckShield later identified about 14.9 billion SAND created across two addresses. Other security researchers recorded hundreds of additional transactions, producing much larger estimates for the total number of unbacked tokens generated before the bridge was disabled.

The size of the minted amount did not represent the project’s direct financial loss. SAND created on Base or BNB Smart Chain could not increase the Ethereum token’s fixed maximum supply of 3 billion unless the attacker could use the cross-chain system to release genuine tokens locked in the Ethereum adapter.

According to blockchain forensics account BlockWatchdog, the attacker withdrew approximately 14.75 million SAND from the Ethereum adapter in less than one minute. Token sales generated about 80 ETH, valued at roughly $675,000 at the time of the transactions.

The figure helps explain why The Sandbox placed the impact below 0.01% of the total SAND supply even though the number of tokens minted on the affected networks appeared far larger. The project has not yet published a full technical report reconciling its loss estimate with the figures reported by individual on-chain researchers.

Blockaid attributed the incident to the takeover of LayerZero delegate permissions through a approveAndCall function. The security firm said the access allowed the attacker to mint tokens through the affected cross-chain contracts, though The Sandbox has not confirmed Blockaid’s proposed cause in a detailed postmortem.

Why Ethereum SAND supply has remained unchanged

LayerZero’s Omnichain Fungible Token standard uses linked contracts to move assets between blockchains. Under its adapter model, an existing token is locked on its original network while an equivalent amount is minted at the destination.

For SAND, the Ethereum adapter holds the original tokens intended to support cross-chain balances. A legitimate transfer to Base should lock SAND on Ethereum before creating the corresponding amount on Base, preserving one supply across the connected networks.

Unauthorized minting broke the backing relationship on the affected chains, but it did not rewrite the Ethereum token contract or raise its maximum supply. CoinGecko continued to show a maximum supply of 3 billion SAND, with about 2.9 billion tokens in circulation.

To stop the affected contracts from communicating with other deployments, The Sandbox removed the LayerZero peer settings for Base and BNB Smart Chain. The action cut off the official route through which unbacked tokens might otherwise have been used to claim assets held by the Ethereum adapter.

A similar difference between a bridge failure and a problem with the underlying blockchain appeared during July’s Wanchain bridge exploit. About 515 million NIGHT left Wanchain’s Cardano-side treasury, while the Midnight Foundation said its core network, validators and consensus system remained unaffected.

In another July incident, an attacker used the Verus bridge’s import path to trigger unbacked asset payouts worth about $7.54 million. Blockaid linked the attack to the same bridge contract and apparent bug class involved in an earlier May breach.

Korean exchanges restrict SAND transfers

Upbit issued a caution notice after finding signs of a possible security problem involving SAND, warning that the incident could produce sharp price movements. Bithumb separately suspended SAND deposits and withdrawals while it reviewed the issue.

Reports citing the exchange notices placed Bithumb’s suspension at 11:11 a.m. Korea Standard Time on August 22, followed by Upbit about one minute later. Trading restrictions and transfer suspensions can differ, so users must check each exchange’s notice before placing an order or attempting to move SAND.

The quick response is consistent with South Korean exchange procedures for assets facing suspected network faults, abnormal token issuance, or security incidents. Deposit restrictions can limit the chance that tokens created through a compromised network reach an exchange and are sold against unaffected balances.

SAND traded near $0.05 after the disclosure, while CoinGecko reported more than $66 million in 24-hour volume. The data provider placed the token’s market capitalization near $136 million and showed an increase of about 18% over seven days, though prices varied across trading venues.

Base users face isolated liquidity risk

For U.S. users, the immediate connection comes through Base, the Ethereum layer-2 network developed by U.S.-listed exchange Coinbase. The reported vulnerability affected The Sandbox’s cross-chain contracts deployed on Base rather than Base’s underlying network, according to the available project and security disclosures.

The Sandbox’s warning applies to anyone holding or trading the isolated Base version of SAND, including U.S. users accessing decentralized exchanges through self-custody wallets. Tokens available in Base liquidity pools may not carry the same backing as Ethereum-native SAND while the official bridge remains disabled.

The incident follows an April attack involving another LayerZero-powered asset. As crypto.news reported, LayerZero’s KelpDAO incident report said attackers stole about 116,500 rsETH worth $292 million after compromising infrastructure used by a single-verifier cross-chain configuration.

Following the KelpDAO attack, LayerZero said its verification network would stop signing messages for applications using a one-of-one verifier setup and encourage projects to adopt multiple independent verifiers. The Sandbox has not said whether its SAND configuration used the same model or whether the latest vulnerability involved LayerZero’s verification network.

The Sandbox, an Animoca Brands subsidiary that raised $93 million in 2021, said it would publish further information as its investigation proceeds. Its latest notice did not provide a date for restoring Base and BNB Smart Chain transfers or specify when compensation claims for eligible liquidity providers would open.


Source link

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button