In Brief:
- According to the project’s post-mortem, a bridge misconfiguration on Base and BNB Smart Chain allowed an attacker to pull 14,742,341.84 SAND — roughly $697,000, or about 0.5% of max supply — out of The Sandbox (official site)’s Ethereum vault.
- Not a single private key was stolen. Instead, a legacy
approveAndCallfunction handed the attacker LayerZero delegate rights, opening the door to minting unbacked SAND without any corresponding deposit on Ethereum. - The official claim process for affected holders will go live next week, The Sandbox said, with eligibility rules, a timeline and step-by-step instructions to follow on X and the project blog.
The Sandbox’s post-mortem on the Aug. 22 exploit is out, and it points to a configuration failure at the root of the incident — not a compromised key.
In total, 14,742,341.84 SAND left the Ethereum vault, worth roughly $697,000 and equal to about 0.5% of the 3 billion maximum supply. Holders on Ethereum and Polygon were never touched, and total supply on Ethereum still stands at 3,000,000,000 tokens.
SAND exploit compensation update
– the official claim process for holders affected by the August 22 exploit will be live next week.
– full details (eligibility, timeline, and how to claim) will be published in an article on X and on The Sandbox blog.The SandboxView on X ↗
How the mint worked
Aug. 21 at 23:41 UTC is when the first unbacked mint hit the chain. What made it possible was a convenience feature sitting inside the SAND token contract — approveAndCall, an older ERC-20 extension that packs an approval and a subsequent contract call into a single transaction.
Pushing a crafted payload through the token contract, the attacker got at the delegate mechanism of the omnichain fungible token deployment and installed itself as the bridge’s administrator. From that point the attacker was the only party verifying inbound bridge messages, and the contract stopped requiring a genuine burn on Ethereum before authorizing a mint on Base or BSC.
Blockaid, which followed the delegate hijack back through approveAndCall on the Base contract, characterized the fault as an application-level configuration issue rather than anything wrong with LayerZero itself.
On this point the post-mortem does not hedge: nothing was stolen in the conventional sense. It was the token contract itself that altered the bridge configuration, acting on instructions the attacker had generated.
The attacker knew the vault balance
Thirty-nine blocks on from the first unbacked mint came a second one of 14,743,364.21 SAND. At that moment the vault held 14,743,464.21 SAND — leaving the mint exactly 100 tokens shy of the target.
The tokens were then bridged over to Ethereum, and six withdrawals emptied the vault, the final one likewise sized to leave 100 SAND untouched. The haul, however, came up short. Roughly 48 minutes earlier an unrelated arbitrage bot had picked up some of the unbacked SAND and redeemed 642,471.52 SAND, leaving the attacker with 14,095,483.66 SAND — a shortfall of 647,880.55.
Not one SAND has moved out of the vault since Aug. 22 at 02:21 UTC. That same day at 05:26 UTC, The Sandbox shut the bridge at contract level across all three chains, used governance to strip the LayerZero peer settings for Base and BSC, and retired the compromised contracts.
“An attacker was able to mint unbacked SAND on Base and BSC. We have disabled bridging to and from both networks, so SAND on Base and BSC is currently isolated and cannot be moved or redeemed,” the project said in its first statement on the incident.
What the headline numbers missed
While the attack was under way, PeckShield flagged some 14.9 billion SAND as abnormally minted. That number tracks tokens created, not value extracted from the system — and that distinction accounts for most of the gap between the early estimates and what the forensics ultimately showed.
By the project’s own accounting, the total economic impact reached about $1,496,784. The biggest slice of it, roughly $760,000, landed on traders in a Base decentralized exchange pool rather than on anyone using the bridge.
The attacker’s wallet was reported to TRM Labs by The Sandbox, and the addresses carry flags with Chainalysis and SEAL as well.
Who gets paid
Any wallet that held legitimately bridged SAND on Base or BSC in the moments before the incident is due 1:1 compensation in SAND on Ethereum. Entitlements are derived from balances at Base block 50,283,176 and BSC block 117,321,965 — both locked in ahead of the first unauthorized mint, meaning no action taken by a holder afterward alters what they are owed.
The treasury covers the compensation. There will be no new SAND minted for it.
Because two exchanges account for over 72% of the affected balance and will be reimbursed directly, their users have nothing to file. Everybody else claims using the wallet that held the SAND when the snapshot was taken, and per the project a claim needs nothing more than a transaction from that wallet — no token approvals, no off-chain message signing, and nothing sent anywhere. Claims stay open for 14 days. Anyone who misses the window does not lose the entitlement; it will be made available on Base and BSC after replacement contracts go live.
Neither The Sandbox nor Animoca Brands will contact holders about recovering, swapping or unlocking SAND, the project said, and any purported recovery process that asks for a wallet connection or a transfer of funds should be treated as a scam.
Holders will be able to verify their own balance in advance, as the full entitlement list ships alongside the claim instructions. At the time of the post-mortem, the Ethereum vault still contains 100 SAND — the remainder the attacker deliberately left behind.
















STAY ALWAYS UP TO DATE