- The Sandbox’s SAND was hit by a bridge exploit on Base and BNB Chain on August 22, 2026, minting SAND with a face value near $49 billion, though only about $675,000 was actually converted to cash.
- Upbit formally designated SAND/KRW and SAND/BTC as an “investment caution” item on August 24 at 15:00 KST; Bithumb applied its own caution tag the same week.
- Both exchanges will decide by early October whether to lift the designation or move toward delisting, the same review step that cleared Taiko earlier this year but ended in delisting for BONK and Loopring.
South Korea’s two largest crypto exchanges have escalated their response to The Sandbox’s bridge exploit from an emergency deposit freeze into a formal review that could end in delisting.
A Formal Review, Not Just a Freeze
Upbit designated SAND/KRW and SAND/BTC as an official investment caution item on August 24 at 15:00 KST, citing the “possibility of user damage” tied to the unresolved security incident. Bithumb issued its own caution notice around the same time. Both exchanges had already suspended SAND deposits and withdrawals within minutes of the exploit on August 22, but this week’s move is a separate, heavier step: a formal review period, running through late September into early October, at the end of which each exchange decides whether to restore normal trading or terminate it.

That review step is not a formality. Upbit ran the same process on Taiko earlier this year after a bridge exploit there and eventually lifted the caution once the network resolved it. BONK and Loopring went through the identical process and came out delisted. Which way SAND goes now depends on whether The Sandbox can show exchanges, before their review windows close, that the exploit is genuinely resolved and not just paused.
How the Bridge Was Compromised
The exploit itself minted a startling amount of SAND on paper. An attacker hijacked delegate permissions on SAND’s cross-chain bridge contract on Base, using a function called approveAndCall, and used them to mint tokens with no backing on Base and BNB Smart Chain. Blockaid, which flagged the attack live, later clarified the root cause sat in The Sandbox’s own bridge contract rather than in LayerZero’s underlying messaging protocol. Over roughly five hours, the minting reached 329.24 trillion SAND across more than 700 transactions, a face value near $49 billion at SAND’s market price.

The $49 Billion Number Nobody Actually Lost
Almost none of that figure reflects real damage. The Sandbox said its Ethereum reserve, which backs every bridged SAND token, was never touched, so SAND on Ethereum and Polygon stayed fully redeemable throughout. Its multisig zeroed out the compromised bridge connections and stranded the unbacked tokens on Base and BNB Smart Chain, where they cannot be moved or redeemed. Of the mint, on-chain tracing shows the attacker actually converted only around 80 ETH, worth roughly $675,000, into real value before the contracts were frozen. That gap between the paper mint and the cash extracted is why The Sandbox describes the impact as under 0.01% of SAND’s total supply, and it is also the detail Upbit and Bithumb’s caution notices do not resolve on their own: a caution tag responds to the fact that a bridge was compromised, not to how much money actually left.
The Sandbox says it is taking a pre-incident snapshot of affected liquidity pools and preparing a compensation plan for qualified LP providers on Base and BSC, directing affected users to its support channel. It has not yet published the fuller technical post-mortem it promised. Until that report lands and both exchanges complete their review, roughly six weeks out, SAND’s Korean listings carry the same uncertainty a caution tag has carried into a delisting before.
Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.
To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.















