The Sandbox, a blockchain gaming platform, has committed to repaying eligible SAND token holders on a 1:1 basis following a bridge exploit on August 21 that resulted in the loss of approximately 14.7 million SAND tokens, valued at roughly $700,000, from an Ethereum vault.
According to a post-mortem published by the company, users who legitimately held bridged SAND on Base or BNB Smart Chain prior to the attack will receive an equivalent amount of Ethereum-based SAND. The compensation will be funded from The Sandbox's treasury, with no new tokens being minted to cover the loss.
The claims process is expected to open within two weeks and remain available for an additional two weeks. Two centralized exchanges holding more than 72% of the eligible balances will distribute compensation directly to their affected customers.
Nature of the Exploit
The Sandbox disclosed that the attacker exploited a configuration flaw in SAND's Base and BNB Chain contracts. This vulnerability allowed the attacker to become the sole verifier of incoming bridge messages and mint unbacked tokens. The drained tokens represent approximately 0.5% of SAND's 3 billion maximum supply.
While more than 339 trillion unbacked SAND tokens were minted across the two networks, these tokens have been isolated and cannot be bridged or redeemed. SAND holdings on Ethereum and Polygon networks remained unaffected by the exploit.
Contract Remediation
The compromised bridge contracts will be permanently retired. The Sandbox stated that any future bridges to Base or BNB Chain will utilize newly deployed contracts, addressing the configuration vulnerabilities that enabled the exploit.


