The Sandbox announced it identified and contained a vulnerability in its SAND cross-chain bridge that allowed an attacker to mint unbacked SAND on Base and BNB Smart Chain (BSC). The attacker exploited the approveAndCall function on the omnichain fungible token contract through compromised LayerZero delegate permissions. The platform disabled bridging to and from both networks, isolating the affected tokens. The impact was estimated at less than 0.01% of total SAND supply. South Korean exchanges Upbit and Bithumb froze SAND transfers as a precaution, while user wallets remained uncompromised and SAND on Ethereum and Polygon stays unaffected.
Source: Read the original article

