EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

The Sandbox promises to announce a 1:1 compensation plan within two weeks

2026-08-28 00:23:19
Bookmark

The Sandbox announced compensation plan: Affected users will receive 1:1 compensation

Earlier today, the Sandbox project party brought positive news to affected users in the August 21 attack-promising to compensate at a 1:1 ratio and using the Ethereum version of SAND token payment. According to the announcement issued by Sandbox Games, the project party will open a two-week compensation application window within two weeks after the information is disclosed on August 27.

This compensation plan only covers users who held bridging SAND tokens on the Base chain and the BNB intelligent chain (BSC) at the time of the attack and could provide proof. This group lost approximately $697,000 in total.

When will SAND holders receive compensation?

Sandbox Games stated that affected users will have to wait at least one month before they can actually receive compensation. The application process will start within two weeks after August 27, and the application window will be open for another two weeks. Refunds will be issued in the form of Ethereum-based SAND tokens and will only be made available to users holding bridging SAND on the Base and BSC chains at the time of the attack. Holders of the Ethereum version of SAND were completely unaffected by this incident, and the supply of the chain is still 3 billion pieces. Polygon-based SAND is also unaffected because it runs through a separate bridge channel.

Sandbox Game clarified in post-mortem analysis: "The balances on both chains are intact and users do not need to take any action."

Sandbox game attributes attack to token contract vulnerability

Sandbox Games points out that the vulnerability does not come from any key it controls, but points to SAND token contracts on the Base and BSC chains. Based on post-mortem analysis, the token contract was set up to also serve as a bridging registered application. The problem is that the messaging layer interprets any input from that direction as direct instructions from the sandbox game itself. This setting was intended to save users extra transactions, but attackers took advantage of this vulnerability and caused a total of approximately $1.49 million in financial losses in four steps.

First, attackers used the "call" function to register their own addresses as authorized administrators; after gaining administrator privileges, they rewritten the verification settings so that the bridge message could be confirmed with only a single approval of their own addresses; then, they submitted fake deposit messages and minted SAND tokens out of thin air on the Base and BSC chains, but the corresponding Ethereum deposit never occurred; Finally, they sold some of the fake tokens in exchange for ether, and used the reverse bridging function to extract real SAND tokens from the Ethereum vault. Forensic analysis showed that the direct treasury withdrawal volume was 14,742,341.84 SAND, and the attacker ultimately made a profit of approximately US$987,000.

Bridge channels continue to be closed

Sandbox games closed bridge channels on all three chains at the contract level at 05:26 UTC on August 22, and stated that no SAND tokens have flowed out since 02:21 UTC on that day. In its first public notice issued on August 22, the project party stated that the vulnerability was "fully controlled" and pointed out that the loss was less than 0.01% of SAND's total supply.

The project party currently does not have any hope of reopening the bridge channel. Because the affected contracts permanently allow apps to reconfigure themselves, control of the delegated role is "always in dispute" and any attempt to regain control can be overruled by anyone willing to pay Gas fees. In the words of the project: "There is no configuration for these contracts that can safely reopen the bridge."

The incident initially surfaced in the form of market panic. On August 22, on-chain analytics company Lookonchain flagged a suspected "infinite casting attack" and estimated that more than 500 million SAND chips had been created. South Korean exchanges Upbit and Bithumb immediately restricted SAND's charging and mentioning transactions and issued volatility warnings to users. At the time, SAND was trading at approximately US$0.042, with a market value of approximately US$123 million.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP