The Sandbox to Fully Refund Bridge Exploit Victims After $697K SAND Theft

TL;DR:
- Direct compensation: Users with verified SAND holdings on Base and BNB Smart Chain will receive tokens on Ethereum at a 1:1 ratio.
- Financial impact: The attacker stole 14,742,341.84 SAND tokens from the Ethereum vault, equivalent to $697,000 according to the official report.
- Permanent closure: The development team permanently shut down the bridge contracts after confirming structural flaws in delegation permissions.
The Sandbox team will reimburse victims of the exploit on its cross-chain bridge following the theft of $697,000 in SAND tokens on August 22. The restitution will take place on the Ethereum mainnet to cover all legitimate affected balances.
This contingency measure aims to mitigate losses suffered by liquidity providers and asset holders on the Base and BNB Smart Chain (BSC) networks. According to the announcement published by The Sandbox, the compromised contracts will not be reopened due to technical limitations that prevent guaranteeing their long-term security.
Attack Mechanics and Delegation Contract Vulnerability
The attack vector exploited a vulnerability in the approveAndCall function of the SAND token contract on the destination networks. According to the technical forensic report released by the company, the token contract operated simultaneously as the bridge’s registered application, causing the messaging layer to interpret the attacker’s instructions as direct commands from the core system.
… Continue reading the full article at the original source below.



