What The Sandbox says happened
In a statement posted to its official X account on 22 August 2026, The Sandbox said its team "identified and fully contained a recent vulnerability regarding the SAND cross-chain bridge on Base and BNB Smart Chain (BSC)." According to the company, an attacker was able to mint unbacked SAND on Base and BSC, meaning tokens that are not matched by any real SAND locked on Ethereum.
The Sandbox says it responded by switching off bridging in both directions. With that route closed, the SAND sitting on Base and BSC is now stranded on those chains, unable to leave or to be cashed back in. The company put the impact at "less than 0.01% of the total SAND token supply" and urged holders to hold off on buying, selling, or moving any SAND on the two affected chains while liquidity stays broken.
What is affected, and what is not
What matters for holders is where their tokens live. According to the company, anyone holding SAND on Ethereum or Polygon has nothing to do: those chains were not touched, no wallets were drained, and liquidity providers there are unaffected. The reserve of SAND locked on Ethereum that underpins every bridged token, it says, remains whole.
That framing fits how SAND is structured. The token has a fixed maximum supply of three billion and lives natively as an ERC-20 on Ethereum. Versions of SAND on other chains such as Base and BSC exist only because tokens are locked on Ethereum and represented elsewhere through a cross-chain bridge. The exploit hit that bridge layer, not the underlying Ethereum token, which is why the company can say the real, backed supply is unchanged even as unbacked copies were created on the two affected networks.
The numbers, in context
Blockchain security firm PeckShield reported that roughly 14.9 billion SAND was minted across two addresses on the affected networks. Security firm Blockaid described a nominal figure of around 49 billion dollars in face value spread across more than 400 transactions. That face value is not a measure of money lost. It reflects the market price of tokens that are now isolated and, by the company's account, cannot be moved or redeemed.
What the attacker could actually realise looks far more modest. On-chain analysis referenced in reporting on the incident valued the recoverable proceeds at about 675,000 dollars in tokens, alongside roughly 79.74 ETH.
Market and exchange response
Several exchanges moved to limit exposure while the situation was live. Upbit issued an investor warning and suspended SAND deposits and withdrawals, and Bithumb suspended SAND transfers. These are precautionary steps exchanges commonly take during an active incident to protect users, and they do not, in themselves, signal that the tokens held on those venues were compromised.
What comes next
The company says it has captured a balance snapshot from before the attack and is drawing up a plan to make good the qualifying providers whose pools were hit, pointing affected users to its official support address at contact@sandbox.game. It says the full scope is still under investigation and that a detailed incident report and technical post-mortem will follow. The company also cautioned people to ignore any direct messages or links in the replies to its announcement, noting that its team never messages users first.
For compliance and risk teams, the practical takeaway is familiar. Cross-chain bridges concentrate risk where value is represented on a second network, and permissioned functions such as minting are a recurring target.
RegTech.com has tracked the same pattern in other recent incidents, from a DeFi protocol drained through a chain of smart-contract bugs to a licensed crypto asset that failed an independent security review.
The source
The Sandbox's official statement, captured from its verified X account on 22 August 2026, is shown in full below.

