The Sandbox to Compensate SAND Holders After Bridge Exploit

The Sandbox will reimburse eligible SAND holders 1:1 after an Aug. 21 bridge exploit drained about 14.7 million SAND from an Ethereum vault.

The Sandbox will reimburse eligible users on a one-for-one basis for bridged SAND compromised in an Aug. 21 bridge exploit. The project will supply Ethereum-based SAND from its treasury and confirmed no new tokens will be minted for compensation. A claims process is expected to open within about two weeks and remain available for two weeks.

The incident targeted bridge contracts that handled transfers between Ethereum and the Base and BNB Smart Chain networks. A post-mortem published by the project found a configuration flaw allowed the attacker to become the sole verifier of incoming bridge messages and to mint unbacked tokens on Base and BNB Chain.

About 14.7 million SAND were removed from an Ethereum vault during the attack, equal to roughly 0.5% of the token’s 3 billion maximum supply. The compromised bridge contracts will be permanently retired, and future bridges for Base and BNB Chain will use newly deployed contracts.

More than 339 trillion unbacked SAND tokens were minted on the two networks during the incident, the post-mortem noted. Those tokens have been isolated on their networks and cannot be bridged or redeemed. SAND balances on Ethereum and Polygon were not affected.

Two centralized exchanges hold more than 72% of eligible bridged balances and will distribute compensation directly to their affected customers, the post-mortem added. The project expects reimbursements to be funded from the treasury.

At the time of publication, SAND traded near $0.04 and had declined more than 10% over the previous seven days. The project’s response has focused on retiring the flawed bridge infrastructure and isolating the minted tokens.

Bridges move tokens between blockchains by locking assets on one chain and minting equivalent units on another, using verifiers to confirm cross-chain messages. In this case, the verifier configuration was manipulated to falsely authorize minting, according to the project’s post-mortem.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author