The Sandbox will fully reimburse victims of the August 21–22 cross-chain bridge exploit after an attacker drained 14,742,341.84 SAND tokens, worth roughly $697,000, from the Ethereum vault. According to the project’s post-mortem published Aug. 27, users who legitimately held bridged SAND on Base or BNB Smart Chain before the attack will receive Ethereum-based SAND at a 1:1 ratio.
The compensation will be paid from The Sandbox treasury without minting new tokens, leaving SAND’s circulating and maximum supply unchanged. Claims are expected to open within two weeks and remain available for another 14 days. Two centralized exchanges account for more than 72% of eligible SAND balances and will distribute replacement tokens directly to affected customers.
The exploit targeted a configuration flaw involving the approveAndCall function and a bridge verification setup on Base and BNB Smart Chain. The attacker became the sole verifier for incoming bridge messages, approving fraudulent messages without normal authorization, and minted more than 339 trillion unbacked SAND across the destination networks. The fraudulent supply was isolated and cannot be bridged back to Ethereum or redeemed against legitimate reserves. On-chain security firms including PeckShield and Blockaid noted the huge nominal minting, but analysts clarified that these figures represented face value rather than liquid capital extracted.
The compromised bridge contracts will be permanently retired. SAND on Ethereum and Polygon was not affected because Polygon uses an independent bridge architecture. Following the incident, South Korean exchanges Upbit and Bithumb temporarily suspended SAND deposits and withdrawals, and The Sandbox shared attacker addresses with Chainalysis and TRM Labs. At the time of the post-mortem, SAND was trading near $0.04, down about 10.4% over the previous seven days.