The Sandbox has released its post-incident analysis of the Aug. 22 exploit, saying the attacker abused a vulnerability in contracts tied to crosschain configuration on Base and BNB Smart Chain (BSC). According to the report, 14,742,341.84 SAND were taken from an Ethereum vault, equal to about 0.5% of the token’s maximum supply. The company estimated the economic impact at roughly $1.4968 million, with about $987,000 actually retained by the attacker.
The Sandbox said Ethereum mainnet and Polygon were not affected. It also warned users not to buy or send SAND on Base or BNB Smart Chain until further notice. Contracts deployed on those two networks have been permanently disabled and will not be reopened.
The company said it has reported the attacker’s wallet addresses to blockchain analytics firms TRM Labs and Chainalysis, and has also contacted relevant exchanges directly. Separately, The Sandbox announced a reimbursement plan for wallets that were legitimately holding bridged SAND on Base or BSC before the incident. Those holders will be compensated on a 1:1 basis with Ethereum-based SAND. The reimbursement will be funded by The Sandbox treasury, with no new tokens minted. The claim process is expected to open within the next two weeks and remain available for two weeks.
The Sandbox has published a post-incident analysis of its Aug. 22 exploit, saying the attacker used a vulnerability in contracts related to crosschain configuration on Base and BNB Smart Chain (BSC) to drain 14,742,341.84 SAND from an Ethereum vault.
The report said the stolen amount accounted for about 0.5% of the token’s maximum supply. The estimated economic impact was about $1.4968 million, of which roughly $987,000 was actually retained by the attacker. Ethereum mainnet and Polygon were not affected.
Base and BNB Smart Chain contracts permanently shut down
The Sandbox said users should not buy or send SAND on Base or BNB Smart Chain until further notice. Contracts deployed on Base and BNB Smart Chain have been permanently disabled and will not be reopened.
The company also said it has reported the attacker’s wallet addresses to blockchain analytics firms TRM Labs and Chainalysis, and has directly contacted relevant exchanges.
Reimbursement to be made in Ethereum-based SAND
The Sandbox also announced a compensation plan for wallets that were legitimately holding bridged SAND on Base or BSC before the incident. Eligible holders will be reimbursed on a 1:1 basis in Ethereum-based SAND.
The reimbursement will come from The Sandbox treasury, and no new tokens will be issued. The claims process will open within the next two weeks and will remain open for two weeks.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.