In Brief:
- The Sandbox (official site) disclosed a bridge exploit that it estimates cost roughly $1.5 million, with about $987,000 of that ending up in the attacker’s hands.
- Dated August 21, 2026, the attack unfolded through four decisive steps that bent the bridge’s logic to the attacker’s will.
- Wallets that held the token prior to the breach are set to be made whole through a 1:1 SAND replacement.
The exploit details
In a detailed post mortem, The Sandbox walked through how its bridge system was breached, giving an attacker control over token issuance right down to the last decimal. The breach is dated August 21, 2026, and the bridge was shut at the contract level on both Base and BNB Smart Chain a day later.
Total economic damage is pegged at approximately $1,496,784, of which just under $987,000 was pulled out by the attacker.
Attack execution
What made the attack possible was a token contract capability on Base and BNB Smart Chain that permitted external calls. Built as a convenience for users, it instead became the route through which an address controlled by the attacker was registered with administrator rights.
Across four steps, the verification process was rewritten so that transactions standing in for deposits which had never taken place could pass as valid. The resulting unbacked SAND was then sold for genuine ETH, with the bridge coaxed into releasing holdings from the Ethereum vault.
Precision in execution
The precision on display was striking: the mint came to 14,743,364.21 SAND, landing exactly 100 tokens below what the vault held at that moment. The plan did not survive contact with the market, however, as an arbitrage bot’s unforeseen activity skewed the final tally and left the attacker with 14,095,483.66 SAND rather than the figure originally targeted.
No keys were compromised and no unauthorized access took place, the post mortem stressed; what failed were design decisions baked into the operational contract structure.
Selling strategy
The disposal of the tokens made the intent plain. A total of 93,415,334.861816 SAND was pushed out over 26 separate sales, pulling in wrapped ether well beyond what the pool originally held. By sizing each trade to take out close to 90% of the available ether, the attacker kept an arbitrage loop turning and withdrew again and again.
The run ended when a further extraction attempt came up short, marking both the ceiling of the exploit and the point at which the pool was drained dry.
Shut down protocols
Reopening the bridge safely is off the table, The Sandbox says, because the contract configurations the attacker took advantage of are fixed in place. Presenting any effort to retake control as a fix would be misleading, since the system cannot be secured that way.
The team also highlighted the scale of the distortion: unbacked tokens now amount to more than 339 trillion SAND spread across the two networks, a figure wildly out of step with the real supply of 3 billion.
Compensation for holders
Following the breach, The Sandbox laid out a compensation plan covering wallets that held SAND on the affected chains before the exploit took place. Every legitimate holder is to be issued a 1:1 replacement in SAND on Ethereum.
Funding comes out of The Sandbox treasury rather than from any fresh minting. A claims process is being put in place so holders can confirm their balances, with nothing further required on their part.
The team also flagged the risk of scams, noting that it will never reach out first about recovering tokens and that no genuine process will ever ask users to hand over funds.
In the meantime, the addresses tied to the attacker have been flagged, and exchanges have moved to halt SAND transactions on the chains involved.


















STAY ALWAYS UP TO DATE