Sandbox to Refund Victims of $697K Bridge Exploit
The Sandbox has announced that it will fully refund users affected by a recent bridge exploit that saw the theft of $697,000 in SAND tokens on August 22. The team has confirmed that the attack was caused by a vulnerability in the approveAndCall function of the SAND token contract, which allowed the attacker to modify verification parameters and drain funds from the Ethereum vault.
The compromised contracts have been permanently shut down due to technical limitations that prevent guaranteeing their long-term security. Users with verified SAND holdings on Base and BNB Smart Chain will receive tokens on Ethereum at a 1:1 ratio as part of the direct compensation measure.
The incident saw the attacker mint billions of nominal, unbacked SAND tokens within minutes, but these figures reflected the face value of the illicitly minted assets rather than the actual liquid capital siphoned from the ecosystem. The stolen volume accounted for less than 0.01% of the total 3 billion SAND supply capped on the Ethereum network.