TLDR
- The Sandbox will repay eligible SAND holders 1:1 after an Aug. 21 bridge exploit drained about 14.7 million tokens worth roughly $700,000.
- Payments will come from The Sandbox treasury, and no new SAND will be minted to cover the loss.
- Claims are expected to open within two weeks and stay open for another two weeks after that.
- An attacker exploited a configuration flaw in the Base and BNB Chain contracts to mint more than 339 trillion unbacked SAND.
- The compromised bridge contracts will be permanently retired, and SAND on Ethereum and Polygon was not affected.
The Sandbox has told SAND holders they will be made whole after a bridge exploit hit the token on Aug. 21. The attack drained about 14.7 million SAND, worth close to $700,000, from an Ethereum vault.
The company shared the details in a post-mortem published Aug. 27. Users who held bridged SAND on Base or BNB Smart Chain before the attack will get an equal amount of SAND on Ethereum.
The Sandbox said its treasury already holds enough tokens to cover the payments. That means the fix will not raise SAND’s circulating or maximum supply.
Claims are expected to open within two weeks of the post-mortem and stay open for two more weeks after that. Two centralized exchanges hold more than 72% of the affected balances, and those platforms will send replacement tokens straight to their customers.
Other holders will need to use a claims portal once it is ready. The Sandbox did not give an exact date for when that portal will launch.
How the Exploit Happened
The Sandbox traced the attack to a configuration flaw in its SAND contracts on Base and BNB Smart Chain. The flaw let the attacker become the only verifier for incoming bridge messages.
That control let the attacker approve fake messages without normal checks. As a result, they minted SAND on Base and BNB Smart Chain even though no matching tokens were locked on Ethereum.
More than 339 trillion unbacked SAND ended up in circulation across the two networks. The Sandbox said this fake supply has been isolated and cannot be bridged back or swapped for real SAND.
SAND issued directly on Ethereum and Polygon was not touched by the flaw. The stolen 14.7 million tokens equal about 0.5% of SAND’s 3 billion token maximum supply.
Bridge Exploits Continue Across Crypto
The Sandbox will not restore the affected Base and BNB Smart Chain bridges. Both will be shut down for good, and any new bridge to those networks will need fresh contracts.
This is not the first bridge hack of the year. In June, Humanity Protocol lost more than $36 million after attackers got hold of administrative keys tied to a malware-infected developer computer.
In July, a bridge exploit tied to Wanchain hit Cardano and BNB Chain infrastructure. Security firm BlockSec said about 515 million NIGHT tokens, worth roughly $9 million at the time, were pulled from the Cardano side.
Axelar also disabled its bridge with Secret Network in June after a hack cost about $4.7 million. The company said its main protocol was not affected.
AFX lost $24.15 million in USDC through a bridge exploit in July. That attacker later converted the stolen funds into roughly 12,467.5 ETH before AFX rolled out a plan to help affected users.
Bridge attacks across crypto have caused more than $4 billion in losses since 2021, according to past crypto.news reporting. SAND was trading near $0.04 at the time of the post-mortem, down about 10.4% over the previous seven days.
The post The Sandbox to Repay SAND Holders After Bridge Exploit appeared first on Blockonomi.

2 hours ago
7






English (US) ·