The Sandbox to Repay Users After $700,000 Bridge Exploit
The Sandbox has committed to repaying users affected by The Sandbox exploit that occurred on August 21, when a bridge vulnerability drained approximately 14.744 million SAND tokens—worth about $700,000—from an Ethereum vault. The gaming platform announced it will compensate eligible SAND holders on a 1:1 basis, drawing funds from its treasury without minting new tokens.
How The Sandbox Exploit Happened
The Sandbox exploit stemmed from a configuration flaw in SAND’s Base and BNB Smart Chain contracts. The vulnerability allowed an attacker to become the sole verifier of incoming bridge messages, enabling them to mint unbacked tokens. In total, about 14.7 million SAND tokens were drained—equivalent to roughly 0.5% of the token’s 3 billion maximum supply. While over 339 trillion unbacked SAND was minted across the two networks, those tokens have been isolated and cannot be bridged or redeemed, limiting the damage.

Repayment Plans Following The Sandbox Exploit
Users who legitimately held bridged SAND on Base or BNB Smart Chain before the attack will receive compensation in Ethereum-based SAND. The claims process is expected to open within two weeks and remain available for another two weeks. Two centralized exchanges holding more than 72% of eligible balances will distribute compensation directly to affected customers. SAND on Ethereum and Polygon remained unaffected by the incident. The compromised bridge contracts will be permanently retired, with any future bridges using newly deployed contracts.
المصدر: Cointelegraph