Odaily Planet Daily report: The Sandbox has issued an update regarding the security breach of its SAND cross-chain bridge, stating that the attacker modified the verification mechanism to forge cross-chain deposit messages and mint unsponsored SAND. The incident resulted in approximately 14.7423 million SAND being withdrawn, valued at around $697,000. Additionally, some unsponsored SAND was sold on the market for profit, leading to an overall economic impact of approximately $1.497 million, with the attacker actually gaining around $987,000.
For affected users, The Sandbox commits to compensating wallets holding legitimate bridged SAND at a 1:1 ratio with Ethereum-based SAND, based on the on-chain snapshot prior to the attack. The compensation claim process is expected to open within two weeks and will remain available for two weeks.
The Sandbox stated that the attack did not affect the supply of SAND on Ethereum or Polygon; the total supply of SAND on Ethereum remains unchanged at 3 billion, and no superadmin privileges were compromised. The vulnerability arose from a combination of a generic call function in the token contract and bridge permissions. Relevant addresses have been flagged, and the team is currently collaborating with exchanges, security agencies, and the LayerZero team.

