The Sandbox to repay bridge-exploit victims 1:1 after $697K SAND theft

- The Sandbox will compensate anyone who held legitimately bridged SAND on Base or BNB Smart Chain 1:1 with Ethereum SAND.
- The claim window opens within two weeks and stays open for two weeks more.
- The bridge remains permanently closed because The Sandbox says the compromised contracts can never be safely reopened.
The Sandbox users affected in the August 21 attack received positive news early today when the project committed to a 1:1 compensation plan to be paid out in the Ethereum version of SAND.
According to The Sandbox’s announcement, it will open a two-week compensation claim window within two weeks of its August 27 disclosure.
The compensation plan only covers token holders who provably held bridged SAND on Base and BNB Smart Chain (BSC) at the time of the exploit. Together, that group of holders lost roughly $697,000.
When will SAND holders receive compensation?
According to The Sandbox, affected users will have to wait at least one month to actually receive their compensation.
- The claim process will open within two weeks of August 27.
- The claim window will be open for another two weeks.
The refund will be sent as Ethereum-based SAND, with only holders of bridged SAND on Base and BSC at the time of the breach eligible.
Holders of the Ethereum version of SAND were completely spared in the incident, with the chain’s supply still at 3 billion tokens. Polygon-based SAND also did not have any exposure because it runs through a separate bridge.
“Balances on both chains are intact and no user action is required,” The Sandbox clarified in its post-mortem.
The Sandbox blames exploit on token contracts
The Sandbox said the flaw did not come from any keys it controls on its side, pointing at the SAND token contracts on Base and BSC instead.
Per the post-mortem, the token contract was set up to double as the bridge’s registered application. The problem was that the messaging layer interpreted any input from that direction as direct instructions from The Sandbox itself.
That setup was supposed to spare users extra transactions. Instead, attackers exploited the loophole to cause nearly $1.49 million in total economic damage in four steps.
- They first used the call feature to register their own address as the authorized administrator.
- With admin rights, they rewrote the verification settings so a single approval from their own address was enough to confirm a bridge message.
- They then submitted fake deposit messages, which minted SAND on Base and BSC against Ethereum deposits that never happened.
- Finally, they sold some of the fake tokens for ether and used the reverse-bridge function to draw real SAND out of the Ethereum vault.
Forensics put the direct vault withdrawal at 14,742,341.84 SAND. The attacker walked away with roughly $987,000.
The bridge stays shut
The Sandbox closed the bridge at the contract level across all three chains on August 22 at 05:26 UTC, and says no SAND has left since 02:21 UTC that day. Its first public notice, posted August 22, called the vulnerability “fully contained” and put the hit at under 0.01% of total SAND supply.
The company did not stoke any hopes of reopening the bridge in the interim. Because the affected contracts permanently allow the application to reconfigure itself, control over the delegate roles is “contestable forever,” and any attempt to reclaim them could be undone by anyone willing to pay gas.
In its words, “There is no configuration of these contracts in which reopening the bridge is safe.”
The episode first surfaced as a market scare. Cryptopolitan reported on August 22 that on-chain firm Lookonchain flagged a suspected “infinite mint attack” and estimated more than 500 million SAND had been created.
South Korean exchanges Upbit and Bithumb restricted SAND deposits and withdrawals and warned traders of volatility. SAND was trading near $0.042 with a market cap around $123 million, per CoinMarketCap.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
FAQs
Who is eligible for The Sandbox's 1:1 compensation?
Every wallet that held legitimately bridged SAND on Base or BNB Smart Chain immediately before the incident will be repaid the same amount in SAND on Ethereum, according to The Sandbox's post-mortem.
How much SAND was stolen and what was it worth?
Forensic analysis found the attacker withdrew 14,742,341.84 SAND worth about $697,000, part of a total economic impact The Sandbox estimates at roughly $1.49 million.
Are SAND holders on Ethereum and Polygon affected?
No. Ethereum SAND was untouched and its supply remains at 3 billion tokens, while Polygon uses a separate bridge with no exposure to the compromised contracts, so balances on both chains are intact and no action is needed.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Hannah Collymore
Hannah is a writer and editor with nearly a decade of blog writing and event reporting experience in the crypto space. At Cryptopolitan, Hannah contributes to the news page, reporting and analyzing the latest developments in DeFi, RWA, crypto regulation, AI and frontier tech industries. She graduated from Arcadia university with a degree in Business Administration.
















