The Sandbox’s official post-mortem on last week’s bridge exploit puts a final number on how much unbacked SAND an attacker minted: more than 339 trillion tokens across Base and BNB Smart Chain.
That figure settles five days of conflicting reports. Early estimates ranged from 500 million tokens to 14.9 billion, according to blockchain security firm PeckShield, while other coverage put the nominal value near $49 billion.This outlet reported at the time that the true scale hadn’t been reconciled against the contract’s own mint log. None of those numbers, including the reconciled one, was ever real money.
August 22 exploit Post-Mortem is now live.
TL;DR: attacker drained 14,742,341.84 SAND (~0.5% of max supply) from the Ethereum vault via a bridge configuration flaw on Base/BSC. Ethereum and Polygon were never affected.
We've reported the attacker's wallet to TRM Labs and… https://t.co/FPKmrJznfE
— The Sandbox (@TheSandboxGame) August 27, 2026
The phantom mint that still can’t move
A check of the Base liquidity pool the attacker used to cash out shows why. As of this week, that contract still holds an estimated 26.3 trillion of the unbacked SAND, worth roughly $1.046 trillion at SAND’s current price. It cannot be traded, bridged, or redeemed. Sandbox disabled the bridge at the contract level within hours of the exploit, and no withdrawal has gone through since Aug. 22.
What actually left the vault
The real damage was far smaller. An attacker withdrew 14,742,341.84 SAND, about $697,000, from the vault contract that backs SAND on Ethereum. The opening came from a convenience feature in the token contract that let the attacker register itself as the bridge’s administrator, then set itself as the sole verifier for incoming bridge messages.
Part of the unbacked SAND was sold directly on Base, where the attacker extracted more than 20 times a single trading pool’s available liquidity through repeated trades. The rest was used to redeem real SAND through the bridge’s reverse route, though an unrelated bot beat the attacker to some of that redemption by buying unbacked SAND on the open market first.
Sandbox estimates the total economic impact, combining the vault drain and the ether taken from Base, at about $1.5 million. It says the attacker itself captured roughly $987,000 of that.
The 1:1 repayment
Sandbox says every wallet that held legitimately bridged SAND on Base or BNB Smart Chain immediately before the exploit will be repaid 1:1 in SAND on Ethereum, funded from its treasury rather than new token issuance. Eligibility is fixed to on-chain balances recorded at Base block 50,283,176 and BSC block 117,321,965, the moment before the first unauthorized mint.
Two exchanges hold more than 72% of the affected balance and will be repaid directly, Sandbox says. Everyone else will need to file a claim once the process opens, expected within two weeks of the Aug. 27 announcement and staying open for two weeks after that.
What holders should watch
Sandbox says holders who miss the Ethereum claim window will not lose their entitlement. The same amount becomes claimable again on Base and BNB Smart Chain once replacement bridge contracts, built with the token and bridge functions split apart this time, are deployed at new addresses. The retired contracts will not reopen. Sandbox says the flaw that let the attacker reassign bridge administration is fixed in the contracts’ bytecode and cannot be patched.
Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.
To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.
















