In Brief:
- An attacker drained 14,742,341.84 SAND, about 0.5% of max supply and roughly $697,000, from The Sandbox (official site)’s Ethereum vault through a bridge configuration flaw on Base and BNB Smart Chain, the project said in its post-mortem.
- No private keys were stolen. A legacy
approveAndCallfunction let the attacker take over LayerZero delegate rights and mint unbacked SAND with no matching Ethereum deposit. - The Sandbox said the official claim process for affected holders goes live next week, with eligibility, timeline and instructions to be published on X and the project blog.
The Sandbox has published its post-mortem on the Aug. 22 exploit, and the root cause was a configuration failure rather than a compromised key.
An attacker withdrew 14,742,341.84 SAND from the Ethereum vault, roughly $697,000 and about 0.5% of the 3 billion maximum supply. SAND on Ethereum and Polygon was never affected, and total Ethereum supply remains 3,000,000,000 tokens.
SAND exploit compensation update
– the official claim process for holders affected by the August 22 exploit will be live next week.
– full details (eligibility, timeline, and how to claim) will be published in an article on X and on The Sandbox blog.The SandboxView on X ↗
How the mint worked
The first unbacked mint landed Aug. 21 at 23:41 UTC. The opening was a convenience feature in the SAND token contract: an approveAndCall function, an older ERC-20 extension that bundles an approval and a follow-on contract call into one transaction.
By routing a crafted payload through the token contract, the attacker manipulated the delegate mechanism on the omnichain fungible token deployment and registered itself as administrator of the bridge. That made the attacker the sole verifier of incoming bridge messages. Once the delegate was taken, the contract no longer needed a legitimate burn on Ethereum to authorize a mint on Base or BSC.
Blockaid, which traced the delegate hijack through approveAndCall on the Base contract, described the cause as an application-level configuration issue rather than a fault in LayerZero itself.
The post-mortem is blunt on the point that nothing was stolen in the conventional sense. The bridge configuration was changed by the token contract acting on instructions the attacker generated.
The attacker knew the vault balance
Thirty-nine blocks after the first unbacked mint, the attacker created 14,743,364.21 SAND. The vault held 14,743,464.21 SAND at that moment, putting the mint exactly 100 tokens below the target.
Those tokens were bridged to Ethereum and the vault was emptied across six withdrawals, the last one also sized to leave 100 SAND behind. But the plan lost part of its take. An unrelated arbitrage bot had bought some of the unbacked SAND and redeemed 642,471.52 SAND about 48 minutes earlier, so the attacker collected 14,095,483.66 SAND and came up 647,880.55 short.
No SAND has left the vault since Aug. 22 at 02:21 UTC. The Sandbox closed the bridge at contract level on all three chains at 05:26 UTC that day, stripped the LayerZero peer settings for Base and BSC through governance and retired the compromised contracts.
“An attacker was able to mint unbacked SAND on Base and BSC. We have disabled bridging to and from both networks, so SAND on Base and BSC is currently isolated and cannot be moved or redeemed,” the project said in its first statement on the incident.
What the headline numbers missed
PeckShield flagged roughly 14.9 billion SAND abnormally minted while the attack was running. That figure counts tokens generated, not assets taken out of the system, and the gap between the two is most of the difference between the early estimates and the forensic result.
Total economic impact came to about $1,496,784 by the project’s accounting. The largest single piece, around $760,000, fell on traders in a Base decentralized exchange pool rather than on bridge users.
The Sandbox reported the attacker’s wallet to TRM Labs. The addresses have also been flagged with Chainalysis and SEAL.
Who gets paid
Every wallet holding legitimately bridged SAND on Base or BSC immediately before the incident will be compensated 1:1 in SAND on Ethereum. Entitlements come from balances at Base block 50,283,176 and BSC block 117,321,965, fixed before the first unauthorized mint, so nothing a holder did afterward changes the amount owed.
Compensation is funded from the treasury. No new SAND will be minted.
Two exchanges hold more than 72% of the affected balance and will be repaid directly, so their users don’t need to file anything. Everyone else claims from the wallet that held the SAND at the snapshot, and the project said claiming requires only a transaction from that wallet, with no token approvals, no off-chain message signing and nothing sent anywhere. The window stays open 14 days. Holders who miss it keep the entitlement, which will be made available on Base and BSC once replacement contracts are deployed.
The Sandbox said neither it nor Animoca Brands will message holders asking them to recover, swap or unlock SAND, and that any recovery process demanding a wallet connection or a transfer of funds should be treated as a scam.
The full entitlement list will go out alongside the claim instructions so holders can check their own balance first. As of the post-mortem, 100 SAND still sits in the Ethereum vault, the remainder the attacker left on purpose.