The Sandbox users affected in the August 21 attack received positive news early today when the project committed to a 1:1 compensation plan to be paid out in the Ethereum version of $SAND.
According to The Sandbox’s announcement, it will open a two-week compensation claim window within two weeks of its August 27 disclosure.
The compensation plan only covers token holders who provably held bridged $SAND on Base and BNB Smart Chain (BSC) at the time of the exploit. Together, that group of holders lost roughly $697,000.
When will $SAND holders receive compensation?
According to The Sandbox, affected users will have to wait at least one month to actually receive their compensation.
- The claim process will open within two weeks of August 27.
- The claim window will be open for another two weeks.
The refund will be sent as Ethereum-based $SAND, with only holders of bridged $SAND on Base and BSC at the time of the breach eligible.
Holders of the Ethereum version of $SAND were completely spared in the incident, with the chain’s supply still at 3 billion tokens. Polygon-based $SAND also did not have any exposure because it runs through a separate bridge.
“Balances on both chains are intact and no user action is required,” The Sandbox clarified in its post-mortem.
The Sandbox blames exploit on token contracts
The Sandbox said the flaw did not come from any keys it controls on its side, pointing at the $SAND token contracts on Base and BSC instead.
Per the post-mortem, the token contract was set up to double as the bridge’s registered application. The problem was that the messaging layer interpreted any input from that direction as direct instructions from The Sandbox itself.
That setup was supposed to spare users extra transactions. Instead, attackers exploited the loophole to cause nearly $1.49 million in total economic damage in four steps.
- They first used the call feature to register their own address as the authorized administrator.
- With admin rights, they rewrote the verification settings so a single approval from their own address was enough to confirm a bridge message.
- They then submitted fake deposit messages, which minted $SAND on Base and BSC against Ethereum deposits that never happened.
- Finally, they sold some of the fake tokens for ether and used the reverse-bridge function to draw real $SAND out of the Ethereum vault.
Forensics put the direct vault withdrawal at 14,742,341.84 $SAND. The attacker walked away with roughly $987,000.
The bridge stays shut
The Sandbox closed the bridge at the contract level across all three chains on August 22 at 05:26 UTC, and says no $SAND has left since 02:21 UTC that day. Its first public notice, posted August 22, called the vulnerability “fully contained” and put the hit at under 0.01% of total $SAND supply.
The company did not stoke any hopes of reopening the bridge in the interim. Because the affected contracts permanently allow the application to reconfigure itself, control over the delegate roles is “contestable forever,” and any attempt to reclaim them could be undone by anyone willing to pay gas.
In its words, “There is no configuration of these contracts in which reopening the bridge is safe.”
The episode first surfaced as a market scare. Cryptopolitan reported on August 22 that on-chain firm Lookonchain flagged a suspected “infinite mint attack” and estimated more than 500 million $SAND had been created.
South Korean exchanges Upbit and Bithumb restricted $SAND deposits and withdrawals and warned traders of volatility. $SAND was trading near $0.042 with a market cap around $123 million, per CoinMarketCap.