Particle.news

The Sandbox to Reimburse SAND Holders After Bridge Exploit

A configuration error let an attacker act as the sole verifier for bridge messages and the project says it will retire the compromised Base and BNB Smart Chain bridge contracts.

Overview

  • The exploit occurred on Aug. 21 and drained about 14.7 million SAND from Ethereum‑backed reserves while the attacker minted more than 339 trillion unbacked SAND on destination chains.
  • The Sandbox’s Aug. 27 post‑mortem traced the breach to a configuration flaw in SAND bridge contracts that gave a single address verifier powers to approve fraudulent incoming messages.
  • The project says the fraudulent supply has been isolated so it cannot be bridged back or redeemed and the affected Base and BNB Smart Chain bridge contracts will be permanently retired.
  • The Sandbox will reimburse eligible bridged SAND holders 1:1 from its treasury without minting new tokens, with a claims portal expected to open in roughly two weeks and two large exchanges handling distribution for their customers.
  • The incident highlights repeated cross‑chain verification and key‑management failures this year and underscores risks in lock‑and‑mint bridge designs that issue destination tokens only after correct verification of lock messages.