Blockchain gaming project The Sandbox has announced plans to fully compensate eligible SAND holders following a security breach that affected its bridging infrastructure on Aug. 21.
The company said legitimate users who held bridged SAND on Base or BNB Smart Chain before the incident will be reimbursed on a one-for-one basis with Ethereum-based SAND.
The compensation will be funded from The Sandbox’s treasury, meaning the project will not create additional tokens to cover the losses.
Bridge vulnerability allowed attacker to mint unbacked SAND
According to The Sandbox’s post-mortem report, the exploit was linked to a configuration error in the SAND bridge contracts operating on Base and BNB Smart Chain.
The flaw allowed the attacker to effectively become the only party authorized to verify incoming bridge messages.
That access enabled the attacker to create SAND that was not backed by corresponding tokens on Ethereum and subsequently drain funds from the bridge system.
The incident resulted in approximately 14.7 million SAND being taken from an Ethereum vault.
At the time, the stolen tokens were valued at roughly $700,000.
The amount represented around 0.5% of SAND’s maximum supply of 3 billion tokens.
More than 339 trillion unbacked tokens were created
The scale of the unauthorized minting was considerably larger than the amount ultimately drained from the vault.
The Sandbox said more than 339 trillion unbacked SAND tokens were minted across Base and BNB Smart Chain during the exploit.
However, the project has isolated those tokens, preventing them from being bridged back or redeemed through the affected infrastructure.
This distinction means the enormous number of unauthorized tokens does not represent an additional claim against The Sandbox treasury.
Ethereum and Polygon SAND remained unaffected
The Sandbox stressed that SAND held on Ethereum and Polygon was not impacted by the vulnerability.
The project’s compensation plan specifically targets users who legitimately owned bridged SAND on Base or BNB Smart Chain before the exploit occurred.
Eligible holders will ultimately receive Ethereum-based SAND equivalent to the amount they previously held.
The company said two centralized exchanges account for more than 72% of the balances eligible for compensation.
Rather than requiring those customers to make individual claims, the exchanges are expected to distribute the replacement tokens directly to affected users.
Claims window expected to last four weeks
The Sandbox expects its reimbursement process to begin within approximately two weeks.
Once opened, the claims window is expected to remain available for another two weeks, giving eligible users time to complete the required process and establish their entitlement.
The arrangement is designed to restore affected users to their pre-exploit token positions without increasing SAND’s overall supply through emergency minting.
Compromised bridge contracts to be permanently retired
The Sandbox also outlined changes to its bridge infrastructure as part of its response to the incident.
The compromised contracts on Base and BNB Smart Chain will be permanently retired.
If bridging functionality is restored on either network, The Sandbox said it will deploy entirely new contracts rather than attempting to continue using the compromised infrastructure.
The move is intended to eliminate the vulnerable contracts from the project’s future bridging architecture and reduce the risk of the same configuration problem being exploited again.
SAND remains under pressure
The security incident comes as SAND continues to face weakness in the broader cryptocurrency market.
At the time of publication, SAND was trading at approximately $0.04 and had fallen 10.4% over the preceding seven days, according to CoinGecko.
The token’s price performance adds another layer of pressure for holders dealing with the aftermath of the bridge exploit, although the compensation plan is intended to protect eligible users from bearing the direct loss caused by the attack.
What’s next for affected SAND holders?
The immediate focus will be on the launch of The Sandbox’s claims system and the identification of eligible wallets and balances.
Affected users should monitor official communications from The Sandbox and, where applicable, their centralized exchanges for instructions.
Users should also exercise caution around unofficial compensation links or requests for wallet credentials, as security incidents often create opportunities for secondary scams.
Meanwhile, The Sandbox will need to rebuild its bridging infrastructure with new contracts and demonstrate that the replacement system has adequate controls before restoring similar functionality.
Summary
The Sandbox has pledged to reimburse eligible SAND holders on a 1:1 basis following an Aug. 21 bridge exploit that resulted in approximately 14.7 million SAND being drained from an Ethereum vault.
The project said the attacker exploited a configuration flaw affecting its Base and BNB Smart Chain bridge contracts, while SAND on Ethereum and Polygon remained unaffected.
Although more than 339 trillion unbacked tokens were minted, they have been isolated and cannot be redeemed or bridged.
Compensation will come from The Sandbox treasury without minting new SAND, while the compromised bridge contracts will be permanently retired and replaced with newly deployed infrastructure if future bridges are introduced.