TL;DR:
- Direct compensation: Users with verified SAND holdings on Base and BNB Smart Chain will receive tokens on Ethereum at a 1:1 ratio.
- Financial impact: The attacker stole 14,742,341.84 SAND tokens from the Ethereum vault, equivalent to $697,000 according to the official report.
- Permanent closure: The development team permanently shut down the bridge contracts after confirming structural flaws in delegation permissions.
The Sandbox team will reimburse victims of the exploit on its cross-chain bridge following the theft of $697,000 in SAND tokens on August 22. The restitution will take place on the Ethereum mainnet to cover all legitimate affected balances.
This contingency measure aims to mitigate losses suffered by liquidity providers and asset holders on the Base and BNB Smart Chain (BSC) networks. According to the announcement published by The Sandbox, the compromised contracts will not be reopened due to technical limitations that prevent guaranteeing their long-term security.
Attack Mechanics and Delegation Contract Vulnerability
The attack vector exploited a vulnerability in the approveAndCall function of the SAND token contract on the destination networks. According to the technical forensic report released by the company, the token contract operated simultaneously as the bridge’s registered application, causing the messaging layer to interpret the attacker’s instructions as direct commands from the core system.
With this administrative access, the attacker modified verification parameters to authorize transfers using only their own signature. Official records indicate that fake deposits were issued to mint unbacked SAND on Base and BSC, subsequently triggering the reverse withdrawal function to drain 14,742,341.84 SAND from the Ethereum vault.
On-chain security firms such as PeckShield and Blockaid noted that billions of nominal, unbacked tokens were generated within minutes during the incident. Blockaid analysts explained in their report that these figures reflected the face value of the illicitly minted assets, not the actual liquid capital the attacker managed to siphon from the ecosystem.
The stolen volume accounted for less than 0.01% of the total 3 billion SAND supply capped on the Ethereum network. According to CoinMarketCap market data from August 27, 2026, the price of SAND hovered around $0.042 following the incident.

Scope of Damage and Compensation Timeline
SAND balances held natively on Ethereum and the Polygon network remained unaffected throughout the incident. The team’s technical breakdown confirmed that Polygon utilizes an independent bridge architecture with zero exposure to the vulnerable contracts, meaning users on these chains do not need to take any corrective action.
The incident prompted immediate precautionary measures across centralized exchanges. South Korean platforms Upbit and Bithumb suspended SAND deposits and withdrawals on August 22, 2026, under South Korea’s Virtual Asset User Protection Act, citing potential spot market volatility.
The Sandbox confirmed that wallet addresses associated with the attacker were shared with blockchain analytics firms Chainalysis and TRM Labs to coordinate fund tracing and potential blacklisting across centralized exchanges.
The formal claims process will launch within two weeks of August 27, 2026, and will remain open for an additional 14-day window. Eligible victims, identified via a pre-exploit snapshot, will receive their funds directly on the Ethereum network once the technical verification phase concludes.




