The Sandbox Company Commits to Opening a 1:1 Compensation System Within Two Weeks

cryptonews.ruОпубліковано о 2026-08-27Востаннє оновлено о 2026-08-27

Анотація

The Sandbox has announced a 1:1 compensation plan for users affected by an August 21st bridge exploit. Eligible users, who held bridged $SAND tokens on Base and BNB Smart Chain (BSC) at the time of the attack, lost approximately $697,000. Compensation will be paid in Ethereum-based $SAND, with a claims window opening within two weeks of August 27th and lasting two weeks. Payouts are expected at least one month after the claims process ends. The company blamed a vulnerability in the token contracts on Base and BSC, which allowed an attacker to exploit bridge messaging and steal nearly $1.49 million. The cross-chain bridge remains permanently closed as the contract configuration is deemed irreparably unsafe. Ethereum and Polygon $SAND holders were unaffected.

Early this morning, Sandbox users affected by the August 21st attack received good news: the project announced a 1:1 compensation plan, which will be paid in the Ethereum-based version of $SAND.

According to a statement from The Sandbox company, it will open a two-week application period for compensation within two weeks after the information is published on August 27th.

The compensation plan only applies to token holders who are proven to have held bridged $SAND tokens on the Base and BNB Smart Chain (BSC) networks at the time of the hack. Collectively, this group of holders lost approximately $697,000.

When Will $SAND Holders Receive Compensation?

According to The Sandbox, affected users will have to wait at least a month before receiving their compensation.

  • The application process will begin within two weeks after August 27th.
  • The application window will remain open for another two weeks.

Refunds will be made in the form of Ethereum-based $SAND, and only holders of bridged $SAND on the Base and BSC platforms at the time of the leak will be eligible.

Holders of the Ethereum version of $SAND were entirely spared the incident, as the supply volume in the network remains 3 billion tokens. The Polygon-based version of $SAND was also unaffected, as it operates through a separate bridge.

"Balances in both chains remain unchanged, and no action is required from the user," The Sandbox company explained in its analysis of the incident's cause.

Sandbox Blames Token Contract Vulnerability

Sandbox stated that the vulnerability was not related to keys under its control, instead pointing to the $SAND token contracts on the Base and BSC platforms.

As the post-mortem analysis showed, the token contract was configured to simultaneously act as a registered application for the bridge. The issue was that the message relay layer interpreted any input from this side as direct instructions from The Sandbox itself.

This scheme was supposed to allow users to avoid extra transactions. Instead, attackers exploited the loophole and caused economic damage totaling nearly $1.49 million in four stages.

  • First, they used a call function to register their own address as an authorized administrator.
  • Upon gaining admin rights, they rewrote the verification settings so that only one confirmation from their own address was sufficient to validate a message on the bridge.
  • Then they sent fake deposit messages, resulting in $SAND being issued on the Base and BSC platforms for Ethereum deposits that never actually occurred.
  • Finally, they sold some of the counterfeit tokens for Ether and used the reverse bridge function to extract real $SAND from the Ethereum vault.

According to forensic analysis, the amount directly withdrawn from the vault was 14,742,341.84 $SAND. The attacker made off with approximately $987,000.

The Bridge Remains Closed

The Sandbox company closed the bridge at the contract level for all three chains, and according to its report, no $SAND left the network since 02:21 UTC on the same day. In the first public notification published on August 22nd, the vulnerability was described as "fully contained," with the damage being less than 0.01% of the total $SAND supply.

The company did not hold out hope for a temporary bridge restart. Because the affected contracts allow the application to be continuously reconfigured, control over delegate roles "can be contested forever," and any attempt to reclaim them could be thwarted by anyone willing to pay for gas.

The company noted in its statement: "There is no configuration of these contracts where reopening the bridge would be safe."

The incident initially caused market panic. Cryptopolitan reported that blockchain data analytics firm Lookonchain detected a supposed "infinite mint attack" and estimated the volume of created $SAND tokens at over 500 million.

South Korean exchanges Upbit and Bithumb restricted $SAND deposits and withdrawals and warned traders of volatility. $SAND was trading around $0.042, with a market cap of around $123 million.

Пов'язані питання

QWhat compensation plan did The Sandbox announce for users affected by the August 21st attack?

AThe Sandbox announced a 1:1 compensation plan, to be paid out in the Ethereum-based version of $SAND.

QWhich token holders are eligible for The Sandbox's compensation?

AOnly token holders who can prove they owned bridged $SAND tokens on the Base and BNB Smart Chain (BSC) networks at the time of the hack are eligible.

QWhat was the root cause of the vulnerability exploited in the attack, according to The Sandbox?

AAccording to The Sandbox, the vulnerability stemmed from the bridged $SAND token contracts on Base and BSC, where the messaging layer mistakenly interpreted certain inputs as direct instructions from The Sandbox itself.

QWhat is the status of the bridge involved in the incident?

AThe bridge has been disabled at the contract level on all three chains (Ethereum, Base, BSC), and The Sandbox stated there is no safe configuration to reopen it.

QHow did the attackers exploit the vulnerability in the bridge contract?

AThe attackers used a call function to register their address as an authorized administrator, altered validation settings to require only their approval, sent fake deposit messages to mint fraudulent $SAND on Base/BSC, and then used the bridge's redeem function to steal real $SAND from the Ethereum treasury.

Пов'язані матеріали

Торгівля

Спот
活动图片