The Sandbox to Repay 1:1 Bridged SAND After 14.74M Token Exploit

iconThe Defiant
Share
AI summary iconSummary
The Sandbox announced on Aug. 27 it will repay 1:1 bridged SAND on Base and BNB Chain after a DeFi exploit drained 14,742,341.84 SAND from its Ethereum vault on Aug. 22. The on-chain news revealed the repayment will come from the project’s treasury, with no new tokens minted. Over 72% of eligible balances are on two centralized exchanges, which will handle direct distributions. A claims portal for other holders is expected to open in two weeks.

The Sandbox will repay eligible holders of bridged SAND on Base and BNB Chain 1:1 in Ethereum-based SAND after an Aug. 22 exploit drained 14,742,341.84 SAND from its Ethereum vault, the project said in an Aug. 27 post-mortem.

The plan covers legitimately bridged balances recorded in a pre-incident snapshot, rather than tokens created through the unauthorized mint. The Sandbox will fund the replacements from its treasury and said no new SAND will be minted, leaving the token’s fixed 3 billion maximum supply unchanged.

Two centralized exchanges hold more than 72% of eligible balances and are expected to distribute replacement tokens directly to affected customers. Other qualifying holders will use a claims portal that The Sandbox expects to open within two weeks of the post-mortem and keep open for a further two weeks.

Configuration Flaw

On Base and BNB Chain, the SAND token contract also acted as the LayerZero bridge integration, according to The Sandbox. A configuration function allowed the attacker to register as the sole verifier of incoming bridge messages, enabling fraudulent messages to mint unbacked SAND on both networks.

The 14.74 million SAND taken from the Ethereum vault represented about 0.5% of the token’s maximum supply. The final figure was materially higher than The Sandbox’s initial estimate of less than 0.01%, which the project said reflected only what it could observe during the first hours of containment.

The company said SAND on Ethereum and Polygon was unaffected. The additional unbacked tokens minted on Base and BNB Chain were isolated and cannot be bridged to Ethereum or redeemed against the vault, while bridging on the two affected networks remains disabled.

For the attacker’s funds, The Sandbox said it had reported the wallet to TRM Labs and Chainalysis for stolen-funds tagging and worked with centralized exchanges to disable deposits and withdrawals on the affected networks.

The compromised Base and BNB Chain bridge contracts will be permanently retired. Any future bridge to either network would require newly deployed contracts.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.