Upbit, Bithumb place SAND under caution after bridge exploit

South Korean crypto exchanges Upbit and Bithumb have designated The Sandbox’s SAND token as an investment caution asset after security concerns linked to the project remained unresolved following a cross-chain bridge incident.
Summary
- Upbit and Bithumb designated SAND as an investment caution asset over unresolved security concerns.
- The Sandbox said a bridge vulnerability allowed unbacked SAND to be minted on Base and BNB Smart Chain.
- Upbit will review SAND through late September and could remove, extend or escalate the warning.
- The Sandbox said Ethereum and Polygon SAND balances and user wallets were unaffected.
According to Upbit’s Aug. 24 announcement, the exchange placed SAND under its trading caution framework after determining that an unexplained or unresolved security incident involving a virtual asset wallet or distributed ledger could expose users to potential losses.
The designation applies to SAND’s Korean won and Bitcoin markets, while deposits and withdrawals have already been suspended since Aug. 22 at 11:12 a.m. KST. Trading remains available during the review period.
Bithumb issued a separate designation at 3 p.m. KST on Aug. 24, citing confirmed security incidents such as hacking involving virtual asset wallets or distributed ledgers where the cause has not been identified or the problem has not been fully resolved. The exchange had halted SAND deposits and withdrawals at 11:11 a.m. KST on Aug. 22 after detecting signs of a possible security problem.
SAND warning follows abnormal token minting
Two days before the formal caution designations, Bithumb said it had detected abnormal token minting activity involving the SAND smart contract on Base and warned users that the incident could increase price volatility.
The Sandbox later said it had identified and contained a vulnerability affecting its SAND cross-chain bridge on Base and BNB Smart Chain. According to the project, an attacker had been able to mint unbacked SAND on the two networks, prompting the team to disable bridging to and from both chains.
The project estimated the actual impact at less than 0.01% of SAND’s total supply and said SAND held on Ethereum and Polygon was unaffected. It also said no user wallets had been compromised and that the SAND locked on Ethereum to back legitimate bridged tokens remained secure.
With bridging disabled, The Sandbox said SAND on Base and BNB Smart Chain had been isolated and could not be moved or redeemed through the affected bridge. The team advised users against buying, selling or trading SAND on the two networks while liquidity remained affected.
Security firm Blockaid separately said attackers had hijacked LayerZero delegate permissions through the approveAndCall function used by SAND’s omnichain token setup. The firm reported that a large nominal amount of unbacked SAND had been minted across hundreds of transactions, although the face value of newly created tokens did not represent the project’s reported financial loss.
The Sandbox has also taken a snapshot of balances from before the incident and is preparing a compensation plan for eligible liquidity providers affected on Base and BNB Smart Chain. A full incident report and technical post-mortem are expected after the investigation is completed.
Upbit could end SAND trading support if concerns remain
Upbit has scheduled its initial SAND review period from Aug. 24 at 3 p.m. KST through the fifth week of September, running from Sept. 28 to Oct. 4.
During that period, the exchange will review the reasons behind the caution designation under its digital asset trading support termination policy. Depending on the findings, Upbit can remove the warning, extend the review or decide to terminate trading support.
A security concern that has not been completely resolved can result in trading support being withdrawn, according to the exchange. Any extension or termination decision will be published separately with the applicable schedule.
SAND deposits made after the caution notice was published will not be credited to user accounts and will instead qualify for return processing. The token has also been removed from assets available for new borrowing applications under Upbit’s coin lending service, although existing loans can remain active until their original maturity dates.
Upbit said SAND withdrawals will be the first transfer service restored when the current suspension ends. Deposits will not automatically reopen at the same time and will instead be handled under the procedure applicable to assets already designated for trading caution.
Bithumb is working on a slightly different review schedule. Its notice said a decision on extending or removing the designation, or ending trading support, is expected during the first week of October, specifically between Sept. 28 and Oct. 2. The schedule can change depending on the exchange’s internal review.
Bithumb also said the caution status can be removed before the review period ends if the underlying reasons are resolved.
Korean exchanges have used similar reviews after exploits
The SAND action follows previous cases in which South Korean exchanges placed tokens under caution while assessing a project’s response to a security breach.
In July, crypto.news reported that Upbit removed its warning on Taiko after reviewing information supplied by the layer-2 project about a June bridge exploit and the security measures introduced afterward.
TAIKO had initially been placed under warning on June 22 after Upbit identified a security incident involving systems used to issue, transfer or store the asset. Deposits were blocked during the review while existing balances could still be traded.
After a 32-day review, Upbit said the project had provided information covering the cause of the breach and subsequent security measures, allowing the exchange to determine that the reason for the warning had been resolved. Bithumb removed its TAIKO warning on the same day and prepared to restore deposits.
Security incidents have also led to more severe outcomes when Korean exchanges were not satisfied with a project’s remediation.
Earlier this year, Flow Foundation and Dapper Labs sought a court order after Upbit, Bithumb and Coinone moved to end FLOW trading support following a December 2025 exploit.
The Flow incident involved a protocol-level vulnerability that allowed an attacker to create duplicated tokens and extract about $3.9 million in value. Flow later said user balances were not affected, while validators and exchange partners took emergency measures to contain the incident and recover funds.
Despite the later remediation work, the Korean exchanges moved toward delisting FLOW, prompting the foundation and Dapper Labs to ask the Seoul Central District Court to suspend the trading termination while additional evidence was reviewed.
Security controls remain under regulatory scrutiny
Security incidents at South Korean trading platforms have also drawn attention from domestic regulators under the country’s Virtual Asset User Protection Act.
South Korea’s Financial Supervisory Service began a formal sanctions process against Upbit operator Dunamu in July over a November 2025 wallet breach that affected Solana-based assets.
The FSS action followed an inspection into whether the exchange had met its obligations under the user protection law. Korean reports cited in the July coverage put the affected amount at 44.5 billion won, while Upbit said after the incident that customer losses would be covered with company funds.
Following the breach, Upbit moved assets into cold wallets, suspended deposits and withdrawals and began tracing the stolen funds. Regulators subsequently examined both the security failure and how the exchange disclosed the incident to users.

