started · updated
The Sandbox to reimburse SAND holders after $700,000 bridge exploit
The Sandbox has announced a 1:1 reimbursement plan for SAND holders following a cross-chain bridge exploit on August 21. The attack targeted bridge infrastructure connected to the Base and BNB Smart Chain networks, resulting in the unauthorized withdrawal of approximately 14.74 million SAND from the Ethereum-based vault. This amount represents roughly 0.5% of the token’s 3 billion maximum supply and was valued at approximately $700,000 at the time of the incident.
The exploit occurred due to a configuration vulnerability in the SAND token contracts deployed on Base and BNB Chain. An attacker was able to register themselves as the sole validator for bridge messages, allowing them to mint unbacked SAND and subsequently withdraw actual collateral from the Ethereum vault.
To compensate affected users, The Sandbox will use funds from its treasury to provide Ethereum-based SAND to eligible holders. The project emphasized that no new tokens will be minted, ensuring the total supply remains unchanged. More than 72% of the affected balances are held by centralized exchanges, specifically Coinbase and Binance, which will distribute compensation directly to their users. Individual wallet holders can claim their reimbursement through an official page that is expected to open within two weeks of the post-mortem report's release.
The compromised bridge contracts will be permanently retired, and any future bridge services on these networks will require the deployment of new contracts. Ethereum and Polygon-based SAND assets were not affected by this incident.
Entities
BNB Chain · BNB Smart Chain · Base · Binance · Coinbase · The Sandbox