Key facts
- The Sandbox will repay users affected by a bridge exploit that drained approximately $700,000 worth of SAND tokens.
- Eligible SAND holders on Base and BNB Chain will receive Ethereum-based SAND from the project's treasury.
- The compensation will not involve minting new tokens.
- The claims process is expected to open within two weeks and last for two weeks.
- The exploit targeted a configuration flaw in SAND’s Base and BNB Chain contracts.
- Approximately 14.7 million SAND tokens were drained, representing 0.5% of the total supply.
Blockchain gaming platform The Sandbox has committed to a 1:1 repayment for eligible SAND holders following a bridge exploit on August 21 that resulted in the loss of approximately $700,000 worth of tokens.
The exploit, which drained 14.744 SAND from an Ethereum vault, targeted configuration flaws in the SAND contracts on Base and BNB Chain. The attacker was able to mint unbacked tokens by becoming the sole verifier of incoming bridge messages.
According to The Sandbox, users who legitimately held bridged SAND on Base or BNB Chain prior to the attack will receive an equivalent amount of Ethereum-based SAND. This compensation will be funded from the project's treasury, and no new tokens will be minted. The compromised bridge contracts will be permanently retired, with future bridges on Base or BNB Chain utilizing newly deployed contracts.
The claims process is scheduled to open within two weeks and will remain accessible for an additional two weeks. The Sandbox noted that over 72% of eligible balances are held by two centralized exchanges, which will directly distribute compensation to their affected customers.
While over 339 trillion unbacked SAND were minted on the affected networks, these tokens have been isolated and cannot be bridged or redeemed. SAND on Ethereum and Polygon remained unaffected by the incident. At the time of reporting, SAND was trading around $0.04, marking a 10.4% decrease over the preceding seven days.