0x3db2a7823db2…3db2a785
Sandbox Bridge Exploit Mints 14.9 Billion SAND Tokens
An attacker minted 14.9 billion SAND through The Sandbox's cross-chain bridge, and Coinbase has moved to delist SAND futures following the unauthorized supply issuance.
Outputs
An attacker minted 14.9 billion SAND tokens through The Sandbox's cross-chain bridge
The exploit created unauthorized new supply rather than draining existing user funds
Coinbase is delisting SAND futures contracts in the wake of the incident
The unauthorized issuance exceeds SAND's standard circulating supply by a wide multiple
An attacker exploited The Sandbox's cross-chain bridge to mint 14.9 billion SAND tokens, an unauthorized issuance that ranks among the largest supply-inflation events tied to a bridge compromise at a major gaming protocol. The figure was first reported by news.Bitcoin.com, which confirmed both the mint and a parallel delisting action by Coinbase.
The scale of the mint is the core fact. At 14.9 billion tokens, the unauthorized issuance exceeds the SAND token's standard circulating supply by a wide multiple, meaning the attacker did not steal existing user funds but created new tokens out of thin air through the bridge contract. Supply-inflation exploits of this type differ operationally from treasury drains: they leave the total-supply ledger inflated even if the attacker's tokens are later frozen or burned at centralized venues.
What did Coinbase do?
Coinbase has moved to delist SAND futures from its platform, according to the same report. The delisting limits a key derivatives venue for the token on the exchange and signals that the operator's listing-review process flagged the integrity of SAND's supply following the bridge incident. For a token with deep ties to a single corporate issuer, an exchange delisting futures contracts removes a hedging and price-discovery instrument for institutional participants, not merely a retail trading pair.
Why does a bridge mint matter more than a hack?
Bridges hold custodial authority over wrapped or mirrored assets on at least one chain. When an attacker compromises the bridge's signing or mint logic, they can authorize the creation of tokens directly, bypassing the collateral checks that are supposed to back every bridged unit. The operational consequence for The Sandbox is twofold: the team must invalidate or freeze the fraudulent supply across every venue that lists SAND, and it must rebuild trust in the bridge infrastructure itself before cross-chain flows can safely resume.
For holders, the immediate risk is dilution. If the attacker converts any portion of the 14.9 billion tokens to other assets before containment, the sell pressure falls on the existing holder base. If exchanges and the issuer coordinate quickly, the damage can be capped at the bridge level, but that coordination depends on each venue's willingness to halt deposits and flag tainted addresses.
What happens next?
The Sandbox team faces a containment window measured in hours, not days. Expect an incident post-mortem with contract addresses, a freeze or blacklist of attacker-controlled wallets at major exchanges, and a supply-reconciliation plan before the bridge reopens. Coinbase's futures delisting takes effect per its standard notice schedule, and other venues listing SAND derivatives will likely run their own listing reviews as details of the exploit become public.
via Google News - Crypto Hack Exploit (Source)