Sandbox opens SAND payouts as Cronos recovers and Ledger warns bug hunters

- The Sandbox has reopened claims for users who lost bridged SAND in August’s exploit.
- Cronos has recovered after halting its chain to contain a $75 million Tectonic attack.
- Ledger and Trezor are pushing researchers to privately report vulnerabilities before disclosure.
The Sandbox has begun accepting compensation claims from users who lost bridged SAND in an August exploit.
The move to make users whole is coming around the same time that hardware wallet makers Ledger and Trezor are warning that the next wave of bugs is arriving at a pace that is faster than what defenders can patch.
The Sandbox reopens the claim window
Sandbox shared the information on X on September 8, stating that anyone who held bridged SAND on Base or BNB Smart Chain before the August 22 exploit can now file for a full 1:1 refund paid in SAND on Ethereum.
It said that individual wallet holders need to submit a claim through the project’s portal, while users who held the token on an exchange do not have to do anything.
The Sandbox post-mortem shows the pool of funds that was lost was around $697,000, as Cryptopolitan reported. The balances on Ethereum and Polygon were never touched, and the Ethereum supply still has 3 billion tokens.
SAND currently trades around $0.041, having risen by over 2.7% in the past 24 hours. However, it is worth noting that it is currently well off its November 2021 record of $8.44.
How did the Sandbox bridge attack occur?
The post-mortem pointed fingers to the SAND token contracts on Base and BNB Smart Chain, which had been configured to double as the bridge’s registered application so users could skip extra transactions. The messaging layer read anything from that source as an order from The Sandbox.
Attackers registered their own address as administrator, loosened the settings so a single self-approval cleared a bridge message, minted SAND against deposits that never happened, and then reverse-bridged real tokens out of the Ethereum vault.
Forensics pinned the vault withdrawal at 14,742,341.84 SAND and total economic damage near $1.49 million. The Sandbox shut the bridge across all three chains on August 22.
The Sandbox team has ruled out reopening the bridge, as it says that control over the compromised contracts is “contestable forever.”
Cronos recovers after the Tectonic drain
Another project, Cronos, that suffered an exploit towards the end of August, seems to be further along in its recovery. The Crypto.com-linked chain halted block production on August 30 to contain an attack on Tectonic, its largest lending market, as Cryptopolitan reported.
An attacker reportedly inflated the thinly traded TONIC token around 100 times in 20 minutes. They then borrowed real assets against the fake value.
The freeze worked, as only about $6 million out of the roughly $75 million exposed reached Ethereum before the chain stopped, security firm PeckShield confirmed.
Crypto.com CEO Kris Marszalek said the exchange and app were never compromised. Cronos has since come back online, and Tectonic’s total value locked, which had cratered from about $122 million to under $3 million, has climbed back above $121 million.
Ledger and Trezor press for private reporting
While the platforms are working on trying to make affected users whole, two of the industry’s best-known cold wallet makers, Ledger and Trezor, have highlighted some of the security challenges that platforms have to grapple with, especially when it comes to disclosures of vulnerabilities.
Charles Guillemet, chief technology officer at Ledger, said that AI has made vulnerabilities cheap to find. In an X post, Guillemet stated that AI being introduced into the mix has also stripped defenders of the head start they once had.
He called out the fact that some researchers now publish findings before a fix exists, which he called “attention farming with someone else’s risk.”
On the process of disclosures, he urged researchers to report the issues privately and settle on a fixed timeline first, citing 90 days as a common default that flexes with severity. Trezor supported Guillemet’s comments on X, stating that they are firmly behind responsible disclosure.
Jan Komarek, Trezor’s head of security, shared his thoughts on the matter, stating, “Ninety days is a commitment on the vendor, not just on the researcher.” He added that researchers can go ahead and publish their findings if the vendor misses the window.
The push follows Coldcard thefts topping $100 million and a breach at Trezor’s shipping provider that exposed tens of thousands of customers.
If you're reading this, you’re already ahead. Stay there with our newsletter.
FAQs
Who can claim The Sandbox compensation?
Any wallet that held legitimately bridged SAND on Base or BNB Smart Chain before the August 22 exploit is eligible for a 1:1 refund in SAND on Ethereum, and users who held the token via an exchange do not need to take action.
How much did the Cronos Tectonic attack cost?
An attacker inflated the TONIC token about 100 times in 20 minutes and borrowed against it, exposing roughly $75 million, but PeckShield confirmed only about $6 million left for Ethereum before Cronos halted the chain, and Crypto.com said its app and exchange were untouched.
What are Ledger and Trezor asking security researchers to do?
Ledger CTO Charles Guillemet and Trezor security head Jan Komárek want researchers to report bugs privately and agree on a fix timeline, commonly 90 days, before going public, and to publish only if the vendor fails to ship a fix in that window.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Hannah Collymore
Hannah is a writer and editor with nearly a decade of blog writing and event reporting experience in the crypto space. At Cryptopolitan, Hannah contributes to the news page, reporting and analyzing the latest developments in DeFi, RWA, crypto regulation, AI and frontier tech industries. She graduated from Arcadia university with a degree in Business Administration.
















