NewsCryptoThe Sandbox Commits to 1:1 Compensation Plan for Bridged SAND Exploit Victims

The Sandbox Commits to 1:1 Compensation Plan for Bridged SAND Exploit Victims

Author: Cryptopolitan·

Key Takeaways

  • The Sandbox will compensate eligible victims of the August 21 bridge exploit at a 1:1 ratio in Ethereum-based SAND, with a two-week claim window opening within two weeks of the August 27 announcement.
  • Only holders who can prove they held bridged SAND on Base or BNB Smart Chain at the time of the exploit qualify, a group that lost about $697,000 combined, while Ethereum and Polygon SAND holders were unaffected.
  • The attacker exploited a design flaw in the Base and BSC SAND token contracts to become administrator, mint fake tokens, and withdraw about 14.7 million SAND worth roughly $987,000 from the Ethereum vault, causing nearly $1.49 million in total damage.
  • The bridge has remained closed at the contract level across all three chains since August 22, and The Sandbox says no configuration would allow a safe reopening because control over delegate roles is permanently contestable.
  • The incident initially sparked fears of an 'infinite mint attack' after Lookonchain estimated more than 500 million SAND had been created, prompting South Korean exchanges Upbit and Bithumb to restrict SAND deposits and withdrawals.
The Sandbox Commits to 1:1 Compensation Plan for Bridged SAND Exploit Victims

Users of The Sandbox affected by the August 21 exploit received positive news on August 27, when the project committed to a 1:1 compensation plan to be paid out in the Ethereum version of SAND.

In its announcement on X, The Sandbox said it will open a two-week compensation claim window within two weeks of its August 27 disclosure. Eligibility is limited to token holders who can provably demonstrate they held bridged SAND on Base and BNB Smart Chain (BSC) at the time of the exploit. Collectively, that group of holders lost roughly $697,000.

The promise of reimbursement matters because the affected tokens were tied to bridge activity rather than the main Ethereum supply, which the company says remained intact. By limiting eligibility to provable bridged balances and paying out in Ethereum-based SAND, The Sandbox is trying to restore user holdings without reopening the compromised bridge.

When will SAND holders receive compensation?

According to The Sandbox, affected users will have to wait at least one month before they actually receive their funds. The claim process will open within two weeks of August 27, and the claim window will then remain open for another two weeks. The refund will be sent as Ethereum-based SAND, with only holders of bridged SAND on Base and BSC at the time of the breach eligible.

Holders of the Ethereum version of SAND were completely spared in the incident, with the chain's supply still standing at 3 billion tokens. Polygon-based SAND also had no exposure because it runs through a separate bridge.

"Balances on both chains are intact and no user action is required," The Sandbox clarified in its post-mortem.

The Sandbox blames the exploit on token contracts

The Sandbox said the flaw did not originate from any keys it controls on its side, pointing instead at the SAND token contracts on Base and BSC. Per the post-mortem, the token contract was set up to double as the bridge's registered application, an arrangement intended to spare users extra transactions. The problem was that the messaging layer interpreted any input coming from that direction as direct instructions from The Sandbox itself.

Attackers exploited the loophole to cause nearly $1.49 million in total economic damage in four steps:

  1. They first used the call feature to register their own address as the authorized administrator.
  2. With admin rights, they rewrote the verification settings so that a single approval from their own address was enough to confirm a bridge message.
  3. They then submitted fake deposit messages, which minted SAND on Base and BSC against Ethereum deposits that never happened.
  4. Finally, they sold some of the fake tokens for ether and used the reverse-bridge function to draw real SAND out of the Ethereum vault.

Forensics put the direct vault withdrawal at 14,742,341.84 SAND. The attacker walked away with roughly $987,000.

The bridge stays shut

The Sandbox closed the bridge at the contract level across all three chains on August 22 at 05:26 UTC, and says no SAND has left since 02:21 UTC that day. Its first public notice, posted August 22, called the vulnerability "fully contained" and put the hit at under 0.01% of total SAND supply.

The company did not raise hopes of reopening the bridge in the interim. Because the affected contracts permanently allow the application to reconfigure itself, control over the delegate roles is "contestable forever," and any attempt to reclaim them could be undone by anyone willing to pay gas.

"There is no configuration of these contracts in which reopening the bridge is safe," the company said.

The episode first surfaced as a market scare. Cryptopolitan reported on August 22 that on-chain firm Lookonchain flagged a suspected "infinite mint attack" and estimated that more than 500 million SAND had been created. South Korean exchanges Upbit and Bithumb restricted SAND deposits and withdrawals and warned traders of volatility. SAND was trading near $0.042 with a market cap around $123 million, per CoinMarketCap.