The Sandbox pledges 1:1 reimbursement after $700,000 bridge exploit

The Sandbox pledges 1:1 reimbursement after $700,000 bridge exploit

N
News Editor
2026-08-29 03:33:48
The Sandbox has published a report on the cross-chain bridge incident that took place on Aug. 21, saying it will reimburse eligible victims on a 1:1 basis with SAND held in the project treasury on Ethereum. The company said about 14.74 million SAND, valued at roughly $700,000, was illicitly withdrawn in the attack. It added that SAND on Ethereum and Polygon was not affected, total supply remains fixed at 3 billion tokens, and no private keys were compromised. According to the report, the exploit stemmed from a flaw in the call mechanism of SAND token contracts on Base and BNB Chain. Because the contract also functioned as a registered cross-chain bridge application, the message layer mistakenly treated token instructions as officially authorized, allowing the attacker to gain admin privileges, change verification settings, and appoint an address under their control as the sole validator. The attacker then forged cross-chain deposit messages to mint unbacked SAND without posting collateral. The Sandbox said affected bridge contracts were shut down on Aug. 22 and will be retired permanently. Coinbase and Binance, which held more than 72% of the affected balances, will receive compensation through direct coordination with the team, while eligible self-custody wallets are expected to claim through a dedicated page within two weeks.

The Sandbox said it will reimburse eligible victims on a 1:1 basis after a cross-chain bridge exploit on Aug. 21 led to the illicit withdrawal of about 14.74 million SAND, worth roughly $700,000.

The Sandbox pledges 1:1 reimbursement after $700,000 bridge exploit 2

In a report on the incident, the blockchain gaming platform said the compensation will be paid in SAND from the project treasury on Ethereum. Claims are expected to open within two weeks. The company also said SAND on Ethereum and Polygon was not affected, total supply remains at 3 billion tokens, and no keys were leaked.

Exploit traced to bridge contract configuration flaw

The report said the attack originated from a vulnerability in the call mechanism of SAND token contracts on Base and BNB Chain. The contract had been designed with a convenience feature to help users save on transaction fees. But because the same contract also served as a registered cross-chain bridge application, the message layer incorrectly treated token instructions as officially authorized.

That let the attacker obtain admin privileges and alter verification settings, setting an address under their control as the sole validator. The attacker then submitted forged cross-chain deposit messages and minted unbacked SAND without providing real collateral.

Two profit channels were used

After minting the unbacked tokens, the attacker extracted value through two routes.

In the first stage, the attacker sold the unbacked tokens in batches on a decentralized exchange on Base and used automated programs to keep drawing on replenished funds from arbitrage bots, cashing out about 327.59 WETH.

In the second stage, the attacker used forged messages to initiate reverse cross-chain transfers, burned the unbacked tokens, and withdrew real collateral from the Ethereum treasury. The investigation also found that third-party arbitrage bots unintentionally bought the unbacked tokens and redeemed them during the withdrawal process. In total, about 14.74 million SAND was taken.

Old bridge contracts to be retired permanently

The Sandbox said it shut down all contract-level cross-chain bridges on affected chains on Aug. 22, cutting off the remaining liquidity of unbacked tokens. The team said the affected legacy bridge contracts will be permanently disabled and replaced with newly deployed contracts.

The company also said compensation will come from the project treasury and that no new tokens will be minted for the reimbursement plan.

Coinbase and Binance held more than 72% of the affected balances, according to the report, and The Sandbox said it will work directly with both centralized exchanges to distribute compensation. Other eligible personal wallets will be able to submit claims through a dedicated page expected to go live within two weeks.

Short-term price volatility followed

The Sandbox said its official keys were not compromised, while the independent Polygon bridge connection and assets on Ethereum mainnet remained intact. Even so, the market saw short-term price volatility.

According to CoinGecko data cited in the report, SAND was trading at about $0.03 as of publication. The project said it will keep improving its cross-chain security architecture to support stable ecosystem operations.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
50

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.