The Sandbox to Reimburse SAND Holders After Bridge Exploit Minted 339 Trillion Unbacked Tokens

iconChainGPT
Share
AI summary iconSummary
The Sandbox is set to reimburse affected SAND holders after a DeFi exploit on August 21 allowed an attacker to mint 339 trillion unbacked tokens via a bridge vulnerability. The breach drained 14.7 million SAND, worth around $700,000, from Ethereum reserves. Holders will be repaid 1:1 using Ethereum-based SAND from the treasury. Major exchanges, controlling over 72% of impacted balances, will handle direct distributions, while others will use a claims portal. The issue stemmed from a bridge contract error. The affected bridge has been retired. This on-chain news incident adds to the over $4 billion lost in DeFi exploits since 2021.

Headline: The Sandbox will reimburse SAND holders after bridge exploit that minted 339 trillion unbacked tokens The Sandbox has committed to fully reimburse eligible SAND holders after a bridge exploit on Aug. 21 allowed an attacker to mint massive quantities of unbacked tokens on Base and BNB Smart Chain. The project’s Aug. 27 post-mortem says roughly 14.7 million SAND — about $700,000 and ~0.5% of SAND’s 3 billion max supply — was effectively drained from Ethereum-backed reserves; the attacker then produced an enormous, fraudulent supply on the destination chains. What The Sandbox is doing - The team will repay legitimate holders of bridged SAND (those who held bridged SAND on Base or BNB Smart Chain before the attack) on a 1:1 basis in Ethereum-based SAND. - Payments will come from The Sandbox treasury; no new tokens will be minted and the project says this will not increase circulating or maximum supply. - Two centralized exchanges hold more than 72% of the eligible bridged SAND balances; those exchanges will distribute replacement tokens directly to affected customers, so customers of those platforms won’t need to file individual claims. - For other holders, The Sandbox will open a claims portal once infrastructure is ready. Claims are expected to open within about two weeks of the post‑mortem and remain available for two weeks after opening, though no exact calendar date was provided. Technical root cause and impact - The exploit targeted the contracts responsible for moving SAND between Ethereum and the destination chains (Base and BNB Smart Chain). A configuration error in the SAND bridge contracts on those networks allowed the attacker to become the sole verifier for incoming bridge messages. - With control of verification, the attacker approved fraudulent messages and minted SAND on the destination chains without the corresponding tokens being locked on Ethereum. - The Sandbox reports more than 339 trillion unbacked SAND were minted across Base and BNB Smart Chain; that fraudulent supply has been isolated and cannot be bridged back to Ethereum or redeemed against legitimate SAND reserves. - SAND tokens deployed directly on Ethereum and Polygon were not affected. Why verification matters Bridge systems typically use “lock-and-mint” designs: tokens are locked on one chain and a verifier confirms that lock before a corresponding representation is minted on another chain. If the verifier is compromised or misconfigured, destination-chain assets can be created without backing value, which is precisely what occurred here. Wider context: bridges remain high-risk The Sandbox decision to permanently retire the affected bridge contracts — rather than restore them — mirrors responses to other bridge compromises this year. Rebuilding bridges with fresh contracts and keys is now standard after incidents like: - Humanity Protocol (June): >$36M drained after attackers obtained administrative keys. - Wanchain/Cardano–BNB Chain exploit (July): ~515M NIGHT tokens (~$9M) removed. - Axelar/Secret Network (June): ~$4.7M lost; Axelar disabled links. - AFX bridge (July): ~$24.15M USDC stolen via a separate bridge; AFX later proposed a goodwill plan and rebuilt infrastructure. Since 2021, bridge exploits have accounted for more than $4 billion in losses across various protocols, driven by failures in validator credentials, message verification, and smart contracts. Market reaction and next steps - The Sandbox says it already holds the Ethereum SAND needed for reimbursements. - The project will not restore the compromised Base and BNB Smart Chain bridge contracts; any future connections to those networks would require newly deployed contracts. No timetable for new bridges was given. - At the time of the post-mortem, SAND traded near $0.04, roughly 10.4% lower over the previous week. What affected users should do - If you custody SAND through one of the two large centralized exchanges that hold most of the impacted balances, watch your exchange’s announcements — those platforms will handle distributions directly. - If you held bridged SAND yourself on Base or BNB Smart Chain, monitor The Sandbox’s channels for the claims portal opening and be prepared to submit a claim during the (expected) two-week window. This incident is another reminder that cross-chain bridges remain a significant attack surface in 2026 and reinforces the importance of conservative bridge designs, secure verifier/key management, and rapid incident response.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.