The Sandbox will refund bridge exploit victims at a 1:1 ratio on Ethereum, covering $697,000 in SAND stolen from its cross-chain bridge.
The compensation plan covers token holders who provably held bridged SAND on Base and BNB Smart Chain at the time of the exploit, The Sandbox said in its Aug 27 post-mortem. The claim window opens within two weeks of Aug 27 and stays open for 14 days, with refunds paid in Ethereum-based SAND.
An attacker drained 14,742,341.84 SAND from the Ethereum vault after exploiting a flaw in the token contract's approveAndCall function, which doubled as the bridge's registered application. The messaging layer interpreted the attacker's instructions as direct commands from The Sandbox, letting them register their own address as administrator, rewrite verification settings, and mint unbacked SAND on Base and BSC before drawing real tokens out of the vault.
The bridge will not reopen. The Sandbox said there is no configuration of the affected contracts in which reopening is safe, because the contracts permanently allow the application to reconfigure itself and control over delegate roles is "contestable forever."
Exploit mechanics and market fallout
The attack unfolded in four steps, according to the post-mortem. The attacker first used the call feature to register their own address as authorized administrator, then rewrote verification settings so a single approval from their address confirmed a bridge message. They submitted fake deposit messages that minted SAND on Base and BSC against Ethereum deposits that never happened, then sold some fake tokens for ether and used the reverse-bridge function to draw real SAND out of the Ethereum vault.
Forensics put total economic damage at roughly $1.49 million, with the attacker walking away with about $987,000. On-chain security firms PeckShield and Blockaid noted that billions of nominal, unbacked tokens were generated within minutes, though those figures reflected face value of the illicitly minted assets rather than liquid capital siphoned from the ecosystem. The stolen volume accounted for less than 0.01 percent of the 3 billion SAND supply capped on Ethereum.
SAND was trading near $0.042 with a market cap around $123 million, per CoinMarketCap. South Korean exchanges Upbit and Bithumb suspended SAND deposits and withdrawals on Aug 22 under the country's Virtual Asset User Protection Act, citing potential spot market volatility. Ethereum-native and Polygon-based SAND were unaffected, with Polygon running through a separate bridge architecture.
The Sandbox said it shared attacker wallet addresses with blockchain analytics firms Chainalysis and TRM Labs to coordinate fund tracing and potential blacklisting across centralized exchanges. The incident adds to a stretch of bridge exploits across the sector, following MAYAChain's $1.7 million loss and BounceBit's $3 million theft, and highlights the risk concentrated in cross-chain messaging layers that trust token contracts as message senders.
This article is for informational purposes only and does not constitute investment advice.