In Brief:
- The Sandbox (official site) reported a bridge exploit resulting in an estimated loss of $1.5 million, with the attacker capturing approximately $987,000.
- The exploit occurred on August 21, 2026, and involved a series of four critical steps to manipulate the bridge’s functionality.
- Compensation plans include a 1:1 replacement of SAND for wallets holding the token before the incident.
The exploit details
The Sandbox revealed a comprehensive post mortem detailing a breach of its bridge system, which allowed an attacker to manipulate token issuance down to the final token counts. This incident occurred on August 21, 2026, with the bridge’s closing implemented at the contract level across Base and BNB Smart Chain the following day.
The estimated economic impact reached around $1,496,784, with the attacker successfully extracting nearly $987,000.
Attack execution
The exploit leveraged a feature in the token contract on Base and BNB Smart Chain that allowed external calls. This feature was intended for user convenience but, in this case, was exploited to register an attacker-controlled address as an administrator.
In four steps, the attacker changed the verification process, allowing unauthorized transactions representing deposits that never occurred. They then sold the unbacked SAND for real ETH, manipulating the bridge to release assets from the Ethereum vault.
Precision in execution
The attacker demonstrated notable precision, minting 14,743,364.21 SAND—exactly 100 tokens less than the vault contained at the time. Despite this meticulous plan, unexpected activity from an arbitrage bot affected the total extraction, resulting in the attacker receiving 14,095,483.66 SAND instead of the intended amount.
The post mortem underscored that the attack did not involve any compromised keys or unauthorized access, but rather exploited design flaws in the operational contract structure.
Selling strategy
The selling strategy further showcased the attack’s intent, as 93,415,334.861816 SAND was moved across 26 sales, netting wrapped ether far exceeding the pool’s original depth. Each transaction was engineered to request roughly 90% of the ether available, perpetuating a cycle of arbitrage that allowed for repeated withdrawals.
Eventually, the attempt to extract more failed, indicating the exploit’s limits and the pool’s eventual saturation.
Shut down protocols
According to The Sandbox, the bridge cannot be safely reopened due to fixed contract configurations that the attacker exploited. Any attempts to reclaim control would be misleading and could not secure the system.
They stressed that the current state of unbacked tokens has created over 339 trillion SAND across both networks, diverging significantly from the actual supply of 3 billion.
Compensation for holders
In the wake of the exploit, The Sandbox announced a compensation plan for wallets holding SAND on the affected chains before the incident. Each legitimate holder will receive a 1:1 replacement in SAND on Ethereum.
This compensation will draw from The Sandbox treasury, and no new tokens will be minted. A process for claims will be set up, allowing holders to verify their balances without additional actions required.
The team warned against scams, stating they will not initiate contact regarding token recovery and that legitimate procedures will not require user funds.
Meanwhile, the attacker’s addresses have been flagged, with exchanges taking measures to suspend SAND transactions on the impacted chains.