In Brief:
- The Sandbox reports a loss of 14,742,341.84 SAND from its Ethereum vault due to a security exploit.
- The attack was facilitated by vulnerabilities in the LayerZero bridge on Base and BNB Chain, allowing unauthorized minting of tokens.
- While the exploit didn’t compromise SAND on Ethereum or Polygon, the incident underscores ongoing security concerns with cross-chain bridges.
Security exploit details
The Sandbox confirmed that an attacker siphoned 14,742,341.84 SAND, or about 0.5 percent of its total supply, from its Ethereum vault. This figure is substantially higher than the initial estimate of less than 0.01 percent, which only reflected the early containment phase. A forensic investigation revealed the updated amount, emphasizing the studio’s commitment to transparency.
What caused the breach?
The vulnerability arose from the SAND token’s deployment as a dual-purpose contract for the LayerZero bridge. The attacker exploited a configuration function to register as the sole verifier for incoming bridge messages. This allowed them to authorize transactions and mint unbacked SAND on both Base and BNB Chain without corresponding tokens locked on Ethereum.
The exploit was identified as an attack on LayerZero’s Omnichain Fungible Token standard. The SAND contract had undergone a third-party audit prior to deployment, and The Sandbox is investigating why the vulnerability was overlooked.
Real impact vs. perceived damage
Although estimates of minted tokens reached as high as 49 billion USD, the actual amount lost equates to 14,742,341.84 SAND, which represents the only redeemable tokens from the vault. The remaining amounts were minted tokens without backing, which cannot be redeemed.
Since the incident, The Sandbox has warned against trading SAND on Base and BNB Chain, noting that liquidity on those networks is compromised. SAND on Ethereum and Polygon remains secure, with no user wallets affected.
Containment efforts
Bridging to Base and BNB Chain was disabled during the response, and those networks are now isolated. The studio reported the attacker’s wallet to TRM Labs and Chainalysis and worked with centralized exchanges to suspend SAND transactions. A pre-incident snapshot has been taken to aid in compensation plans for affected liquidity pool users.
The studio is working on a full incident report and will provide further details on remediation once finalized. Users are advised to contact support for assistance.
Recurring bridge vulnerabilities
Bridges have become frequent targets within crypto security incidents. This case illustrates the risks inherent in combining token contracts with bridge functionalities, where a single point of failure can collapse an entire digital asset’s backing model.
For players in web3 gaming, this holds particular significance. The trend of multi-chain deployments means additional bridges and verification paths, introducing more points of vulnerability. As a recent countermeasure, BNB Chain implemented a hardfork to enhance bridge signature verification protocols.
Notably, The Sandbox’s game functionality, LAND ownership, and Studio Beta on Ethereum and Polygon remain unaffected. The immediate risk is confined to users interacting with SAND on Base and BNB Chain. For those users, The Sandbox continues to recommend pausing trading activities until the remediation plan takes shape.