Crypto

The Sandbox to reimburse SAND holders after 14.7M token bridge exploit



The Sandbox has pledged to reimburse eligible SAND holders 1:1 after an Aug. 21 bridge exploit drained about 14.7 million tokens worth roughly $700,000 from an Ethereum vault.

Summary

  • The Sandbox will repay eligible SAND holders 1:1 after an Aug. 21 bridge exploit drained about 14.7 million tokens worth $700,000.
  • Compensation will come from The Sandbox treasury without minting new SAND, with claims expected to open within two weeks.
  • The attacker exploited a configuration flaw in the Base and BNB Chain contracts to mint more than 339 trillion unbacked SAND.
  • The compromised bridge contracts will be permanently retired, while SAND on Ethereum and Polygon was unaffected.

According to The Sandbox’s Aug. 27 post-mortem, users who legitimately held bridged SAND on Base or BNB Smart Chain before the attack will receive an equivalent amount of Ethereum-based SAND. The project plans to cover the payments from its treasury without minting new tokens.

Claims are expected to open within two weeks and remain available for another two weeks. Two centralized exchanges account for more than 72% of the eligible SAND balances, and The Sandbox said the exchanges will distribute replacement tokens directly to affected customers.

The Sandbox will repay SAND holders from its treasury

The repayment plan covers legitimate bridged SAND balances that existed on Base and BNB Smart Chain before the exploit. Eligible users will receive SAND issued on Ethereum, replacing the tokens affected by the compromised bridge infrastructure.

The Sandbox said its treasury already holds the tokens required for the process, meaning the compensation will not increase SAND’s circulating or maximum supply. Users who held eligible balances through the two centralized exchanges handling most of the affected tokens will not need to submit individual claims.

For other holders, the project plans to launch a claims portal once the required infrastructure is ready. The two-week submission period is expected to begin within two weeks of the post-mortem, though the project did not provide a specific opening date.

The compensation plan follows an attack that targeted the contracts responsible for moving SAND between Ethereum and Base and BNB Smart Chain. While the exploiter was able to create an enormous quantity of unbacked SAND on the destination networks, the project said the damage to assets backing legitimate bridged tokens amounted to about 14.7 million SAND.

The stolen amount represented roughly 0.5% of SAND’s maximum supply of 3 billion tokens.

Configuration flaw gave the attacker control of bridge verification

The Sandbox traced the incident to a configuration problem in the SAND contracts deployed on Base and BNB Smart Chain. The flaw allowed the attacker to become the sole verifier for incoming bridge messages, giving the address the ability to approve fraudulent messages without the authorization normally required by the bridge.

With control of that verification process, the attacker could mint SAND on the destination chains even though corresponding tokens had not been legitimately locked on Ethereum.

More than 339 trillion unbacked SAND tokens were eventually minted across Base and BNB Smart Chain, according to the post-mortem. The Sandbox said the fraudulent supply has since been isolated and cannot be bridged back to Ethereum or redeemed against legitimate SAND reserves.

SAND deployed directly on Ethereum and Polygon was not affected by the configuration flaw.

The distinction between legitimate and unbacked tokens is central to the reimbursement process because bridge systems commonly depend on assets being locked on one network before a corresponding representation is issued elsewhere. A crypto.news explainer published Aug. 3 detailed how lock-and-mint and related bridge designs rely on verification mechanisms to ensure destination-chain assets remain backed by value held elsewhere.

Crypto.news previously reported that bridge exploits have resulted in more than $4 billion in losses since 2021, with failures involving validator credentials, message verification and smart contracts among the methods attackers have used to compromise cross-chain infrastructure.

Compromised SAND bridges will be permanently retired

Following the Aug. 21 attack, The Sandbox decided not to restore the affected Base and BNB Smart Chain bridge contracts. Both will instead be permanently retired.

Any future bridge connecting SAND with either network would require newly deployed contracts, according to the project. The Sandbox did not provide a timetable for restoring bridge access to Base or BNB Smart Chain.

Similar decisions to isolate or replace compromised bridge infrastructure have followed several attacks this year. In June, Humanity Protocol disclosed losses exceeding $36 million after attackers obtained administrative keys and took control of bridge systems spanning Ethereum and BNB Smart Chain.

The attackers in that incident were able to drain tokens from the Ethereum bridge and mint additional H tokens on BNB Smart Chain. A subsequent forensic investigation traced the compromised keys to a malware-infected developer machine that contained backups for seven private keys.

Another bridge incident in July hit Wanchain infrastructure connecting Cardano and BNB Chain. Blockchain security firm BlockSec said roughly 515 million NIGHT tokens were removed from the Cardano-side treasury in the Wanchain bridge exploit, worth about $9 million at the time. Midnight said its core network remained secure and described the incident as isolated to the bridge infrastructure.

Bridge exploits have continued through 2026

Cross-chain infrastructure has faced a series of attacks during 2026 involving different verification and security failures.

Axelar disabled bridge connections with Secret Network in June after an exploit resulted in approximately $4.7 million in losses. The incident affected Axelar-bridged assets on Secret Network while Axelar said its core protocol remained unaffected.

A month later, AFX suffered a $24.15 million USDC loss through a bridge operated by the trading protocol. The affected infrastructure was separate from Arbitrum’s native bridge, and the attacker subsequently moved the stolen USDC to Ethereum before converting it into about 12,467.5 ETH.

AFX later prepared a goodwill plan for users after its investigation linked the attack to a social engineering campaign that compromised internal development infrastructure. The protocol said it rebuilt key infrastructure and introduced new security measures following the incident.

The Sandbox’s reimbursement process is expected to begin once its claims system is ready. Eligible balances held through the two centralized exchanges will be handled directly by those platforms, while remaining holders will have two weeks to submit claims after the portal opens.

SAND was trading near $0.04 at the time of the post-mortem, down about 10.4% over the previous seven days.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *