Early this morning, Sandbox users affected by the August 21st attack received good news: the project announced a 1:1 compensation plan, which will be paid in the Ethereum-based version of $SAND.
According to a statement from The Sandbox company, it will open a two-week application period for compensation within two weeks after the information is published on August 27th.
The compensation plan only applies to token holders who are proven to have held bridged $SAND tokens on the Base and BNB Smart Chain (BSC) networks at the time of the hack. Collectively, this group of holders lost approximately $697,000.
When Will $SAND Holders Receive Compensation?
According to The Sandbox, affected users will have to wait at least a month before receiving their compensation.
- The application process will begin within two weeks after August 27th.
- The application window will remain open for another two weeks.
Refunds will be made in the form of Ethereum-based $SAND, and only holders of bridged $SAND on the Base and BSC platforms at the time of the leak will be eligible.
Holders of the Ethereum version of $SAND were entirely spared the incident, as the supply volume in the network remains 3 billion tokens. The Polygon-based version of $SAND was also unaffected, as it operates through a separate bridge.
"Balances in both chains remain unchanged, and no action is required from the user," The Sandbox company explained in its analysis of the incident's cause.
Sandbox Blames Token Contract Vulnerability
Sandbox stated that the vulnerability was not related to keys under its control, instead pointing to the $SAND token contracts on the Base and BSC platforms.
As the post-mortem analysis showed, the token contract was configured to simultaneously act as a registered application for the bridge. The issue was that the message relay layer interpreted any input from this side as direct instructions from The Sandbox itself.
This scheme was supposed to allow users to avoid extra transactions. Instead, attackers exploited the loophole and caused economic damage totaling nearly $1.49 million in four stages.
- First, they used a call function to register their own address as an authorized administrator.
- Upon gaining admin rights, they rewrote the verification settings so that only one confirmation from their own address was sufficient to validate a message on the bridge.
- Then they sent fake deposit messages, resulting in $SAND being issued on the Base and BSC platforms for Ethereum deposits that never actually occurred.
- Finally, they sold some of the counterfeit tokens for Ether and used the reverse bridge function to extract real $SAND from the Ethereum vault.
According to forensic analysis, the amount directly withdrawn from the vault was 14,742,341.84 $SAND. The attacker made off with approximately $987,000.
The Bridge Remains Closed
The Sandbox company closed the bridge at the contract level for all three chains, and according to its report, no $SAND left the network since 02:21 UTC on the same day. In the first public notification published on August 22nd, the vulnerability was described as "fully contained," with the damage being less than 0.01% of the total $SAND supply.
The company did not hold out hope for a temporary bridge restart. Because the affected contracts allow the application to be continuously reconfigured, control over delegate roles "can be contested forever," and any attempt to reclaim them could be thwarted by anyone willing to pay for gas.
The company noted in its statement: "There is no configuration of these contracts where reopening the bridge would be safe."
The incident initially caused market panic. Cryptopolitan reported that blockchain data analytics firm Lookonchain detected a supposed "infinite mint attack" and estimated the volume of created $SAND tokens at over 500 million.
South Korean exchanges Upbit and Bithumb restricted $SAND deposits and withdrawals and warned traders of volatility. $SAND was trading around $0.042, with a market cap of around $123 million.





