The Sandbox has released a post-incident report on its Aug. 22 exploit, saying an attacker abused a vulnerability in contracts tied to cross-chain configuration on Base and BNB Smart Chain (BSC) and stole 14,742,341.84 SAND from its Ethereum treasury. The project said the amount represented about 0.5% of maximum supply. It estimated the total economic impact at roughly $1.4968 million, with about $987,000 actually retained by the attacker.
The company said Ethereum mainnet and Polygon were not affected. It also warned users not to buy or send SAND on Base or BNB Smart Chain until further notice. Contracts deployed on Base and BSC have been permanently disabled and will not be reopened.
The Sandbox added that it has reported the attacker wallet addresses to blockchain analytics firms TRM Labs and Chainalysis, and has also contacted relevant exchanges directly. For remediation, the firm said wallets that legally held bridged SAND on Base or BSC before the incident will be compensated on a 1:1 basis with Ethereum-based SAND. The reimbursement will be funded by The Sandbox treasury with no new token issuance. A claims process is set to open within the next two weeks and will remain available for two weeks.
The Sandbox has published a post-mortem on the Aug. 22 exploit, saying the attacker used a vulnerability in contracts related to cross-chain configuration on Base and BNB Smart Chain (BSC) to steal 14,742,341.84 SAND from the project’s Ethereum treasury. The company said the amount accounted for about 0.5% of the token’s maximum supply. It estimated the economic impact at about $1.4968 million, of which roughly $987,000 was actually retained by the attacker.
Networks affected and contract shutdown
According to the report, Ethereum mainnet and Polygon were not affected. The Sandbox said users should not buy or send SAND on Base or BNB Smart Chain until further notice. It also said the contracts deployed on Base and BSC have been permanently disabled and will not be reopened.
Tracing efforts and compensation plan
The Sandbox said it has reported the attacker wallet addresses to blockchain analytics firms TRM Labs and Chainalysis, and has directly contacted relevant exchanges.
On compensation, the company said wallets that legally held bridged SAND on Base or BSC before the incident will be reimbursed on a 1:1 basis in Ethereum-based SAND. The funds will come from The Sandbox treasury, with no new token issuance. The claims process will open within the next two weeks and remain open for two weeks.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.