The Sandbox has begun accepting compensation claims from users who lost bridged SAND in an August exploit.Β
The move to make users whole is coming around the same time that hardware wallet makers Ledger and Trezor are warning that the next wave of bugs is arriving at a pace that is faster than what defenders can patch.
The Sandbox reopens the claim window
Sandbox shared the information on X on September 8, stating that anyone who held bridged SAND on Base or BNB Smart Chain before the August 22 exploit can now file for a full 1:1 refund paid in SAND on Ethereum.Β
It said that individual wallet holders need to submit a claim through the projectβs portal, while users who held the token on an exchange do not have to do anything.
The Sandbox post-mortem shows the pool of funds that was lost was around $697,000, as Cryptopolitan reported. The balances on Ethereum and Polygon were never touched, and the Ethereum supply still has 3 billion tokens.
SAND currently trades around $0.041, having risen by over 2.7% in the past 24 hours. However, it is worth noting that it is currently well off its November 2021 record of $8.44.
How did the Sandbox bridge attack occur?
The post-mortem pointed fingers to the SAND token contracts on Base and BNB Smart Chain, which had been configured to double as the bridgeβs registered application so users could skip extra transactions. The messaging layer read anything from that source as an order from The Sandbox.
Attackers registered their own address as administrator, loosened the settings so a single self-approval cleared a bridge message, minted SAND against deposits that never happened, and then reverse-bridged real tokens out of the Ethereum vault.Β
Forensics pinned the vault withdrawal at 14,742,341.84 SAND and total economic damage near $1.49 million. The Sandbox shut the bridge across all three chains on August 22.Β
The Sandbox team has ruled out reopening the bridge, as it says that control over the compromised contracts is βcontestable forever.β
Cronos recovers after the Tectonic drain
Another project, Cronos, that suffered an exploit towards the end of August, seems to be further along in its recovery. The Crypto.com-linked chain halted block production on August 30 to contain an attack on Tectonic, its largest lending market, as Cryptopolitan reported.Β
An attacker reportedly inflated the thinly traded TONIC token around 100 times in 20 minutes. They then borrowed real assets against the fake value.
The freeze worked, as only about $6 million out of the roughly $75 million exposed reached Ethereum before the chain stopped, security firm PeckShield confirmed.Β
Crypto.com CEO Kris Marszalek said the exchange and app were never compromised. Cronos has since come back online, and Tectonicβs total value locked, which had cratered from about $122 million to under $3 million, has climbed back above $121 million.
Ledger and Trezor press for private reporting
While the platforms are working on trying to make affected users whole, two of the industryβs best-known cold wallet makers, Ledger and Trezor, have highlighted some of the security challenges that platforms have to grapple with, especially when it comes to disclosures of vulnerabilities.
Charles Guillemet, chief technology officer at Ledger, said that AI has made vulnerabilities cheap to find. In an X post, Guillemet stated that AI being introduced into the mix has also stripped defenders of the head start they once had.Β
He called out the fact that some researchers now publish findings before a fix exists, which he called βattention farming with someone elseβs risk.β
On the process of disclosures, he urged researchers to report the issues privately and settle on a fixed timeline first, citing 90 days as a common default that flexes with severity. Trezor supported Guillemetβs comments on X, stating that they are firmly behind responsible disclosure.Β
Jan Komarek, Trezorβs head of security, shared his thoughts on the matter, stating, βNinety days is a commitment on the vendor, not just on the researcher.β He added that researchers can go ahead and publish their findings if the vendor misses the window.
The push follows Coldcard thefts topping $100 million and a breach at Trezorβs shipping provider that exposed tens of thousands of customers.
The smartest crypto minds already read our newsletter. Want in? Join them.



















English (US)