The Sandbox will repay eligible holders of bridged SAND on Base and BNB Chain 1:1 in Ethereum-based SAND after an Aug. 22 exploit drained 14,742,341.84 SAND from its Ethereum vault, the project said in an Aug. 27 post-mortem.
The plan covers legitimately bridged balances recorded in a pre-incident snapshot, rather than tokens created through the unauthorized mint. The Sandbox will fund the replacements from its treasury and said no new SAND will be minted, leaving the token’s fixed 3 billion maximum supply unchanged.
Two centralized exchanges hold more than 72% of eligible balances and are expected to distribute replacement tokens directly to affected customers. Other qualifying holders will use a claims portal that The Sandbox expects to open within two weeks of the post-mortem and keep open for a further two weeks.
On Base and BNB Chain, the SAND token contract also acted as the LayerZero bridge integration, according to The Sandbox. A configuration function allowed the attacker to register as the sole verifier of incoming bridge messages, enabling fraudulent messages to mint unbacked SAND on both networks.
The 14.74 million SAND taken from the Ethereum vault represented about 0.5% of the token’s maximum supply. The final figure was materially higher than The Sandbox’s initial estimate of less than 0.01%, which the project said reflected only what it could observe during the first hours of containment.






