Crypto World

The Sandbox Commits to 1:1 Refund After $700K Bridge Exploit

Published

on

The Sandbox has moved to unwind losses from a bridge exploit that hit SAND holders using the Base and BNB Smart Chain networks. In a post-mortem published this week, the blockchain gaming platform said it will repay eligible users 1:1 in Ethereum-based SAND after an Aug. 21 attack drained 14.744 SAND—valued at roughly $700,000 at the time—from an Ethereum vault.

The project emphasized that compensation will be funded from The Sandbox treasury, with no new SAND tokens minted. The reimbursement process is expected to begin within two weeks and remain open for an additional two-week window, while two centralized exchanges are set to distribute funds directly to customers who hold eligible bridged balances.

Key takeaways

  • The Sandbox will compensate eligible SAND holders who had bridged tokens on Base or BNB Smart Chain with an equal amount of Ethereum-based SAND.
  • Payments will come from The Sandbox treasury, explicitly without minting new tokens.
  • The claims window is expected to open within two weeks and run for two weeks after that.
  • The attacker’s method involved a configuration flaw that enabled control of bridge message verification, allowing minting of unbacked tokens.
  • Compromised bridge contracts will be permanently retired; future bridges will use newly deployed contracts.

Bridge exploit triggers treasury-backed reimbursement

According to The Sandbox’s post-mortem, the Aug. 21 incident stemmed from an exploit involving the SAND bridge infrastructure connected to Base and BNB Smart Chain. The company said the attacker drained 14.744 SAND from an Ethereum vault, which at the time was worth about $700,000.

To make affected users whole, The Sandbox stated it will repay users who “legitimately held bridged SAND” on those networks with a 1:1 amount of SAND on Ethereum. Compensation will be sourced from the project’s treasury, and the company said it will not mint new tokens to fund the reimbursement.

For operational execution, The Sandbox indicated that the claims process should start within two weeks and continue for two more weeks. It also said two centralized exchanges hold more than 72% of eligible balances and will distribute compensation directly to their customers, reducing the need for all users to submit individual claims.

Advertisement

What the attacker did—and what was affected

The post-mortem describes the root cause as a configuration flaw in SAND’s bridge-related contracts on Base and BNB Chain. The issue allowed the attacker to become the sole verifier of incoming bridge messages—an abnormal condition that enabled the minting of unbacked tokens.

The Sandbox confirmed that the drained amount was about 14.7 million SAND tokens. While that figure is large in absolute terms, the company noted it represented approximately 0.5% of SAND’s 3 billion maximum supply.

The impact was not uniform across all networks connected to SAND. Although the exploit resulted in more than 339 trillion unbacked SAND being minted on the two impacted networks, The Sandbox said those tokens have been isolated. In its description, the unbacked tokens cannot be bridged or redeemed, limiting the practical risk of continued circulation.

Separately, the company said SAND on Ethereum and Polygon was unaffected.

Advertisement

Compromised contracts retired; future bridges to use new deployments

Beyond compensating users, The Sandbox said it would address the technical vulnerability at the source. The compromised bridge contracts will be permanently retired, according to the post-mortem.

The company added that any future bridges from Base or BNB Chain would rely on newly deployed contract versions. That change matters for users because it reduces the chance that attackers can reuse the same misconfiguration or interface behavior to repeat similar minting and drainage patterns.

At the same time, the arrangement leaves an important question for holders: how quickly and transparently new bridge contract deployments can be audited, monitored, and integrated across exchanges and user workflows. While the immediate risk of redeemable tokens appears constrained by The Sandbox’s statement that unbacked tokens are isolated, bridge security typically depends on ongoing contract monitoring and operational checks—especially when liquidity and user balances are concentrated across centralized platforms.

Market reaction and what holders should monitor

At the time The Sandbox published the update, SAND was trading at roughly $0.04, down 10.4% over the prior seven days, according to CoinGecko.

Advertisement

Token-price moves around major exploits can reflect broader investor concerns—ranging from temporary liquidity issues to general trust in bridge infrastructure—rather than only the direct magnitude of drained funds. In this case, the project’s plan to reimburse eligible holders 1:1 using treasury funds is designed to blunt that uncertainty, particularly for users who bridged via Base or BNB Smart Chain.

Looking ahead, the key variables for impacted SAND holders will be whether eligible balances are identified accurately by the exchanges and the project, how smoothly the claims process runs for the remaining users, and whether the newly deployed bridge contracts are integrated without introducing new failure modes. The coming weeks should also clarify whether any additional operational or technical findings emerge after the initial post-mortem.

For now, users should watch the start of the reimbursement window and follow The Sandbox’s guidance on eligibility, while monitoring any updates on the newly deployed bridge contract approach—because that is where long-term bridge safety will be tested after an exploit like this.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Advertisement

Source link

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version