The information provided in this article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry a high degree of risk. Always conduct your own research.

SAND Compensation After the Bridge Exploit: How to Get Your Frozen Tokens Back

The Sandbox intends to compensate every holder whose bridged SAND on Base and BNB Smart Chain was frozen, one for one in SAND on Ethereum. Anyone whose balance sits at an exchange need do nothing; anyone self-custodying does.

Steel vault wall with two compartments: the left one permanently welded shut, out of the right open compartment a coin with a diamond-shaped symbol rolls into the light
11 min read
Share:

If you held SAND through the bridge on Base or on BNB Smart Chain, the short answer is this: you are due to get your balance back, one for one, paid out as SAND on Ethereum. According to The Sandbox, the money comes from its own treasury, meaning the company's existing holdings, and no new tokens will be minted for it. Whether you have to do anything yourself hinges on a single question: on the evening of August 21, was your SAND sitting at a centralised exchange or in your own wallet?

For most of those affected the answer is "at an exchange", and that majority does not need to file a claim at all. For everyone else, a claim window opens whose start date the operator has given only approximately and whose end is not fixed at all so far. This article sorts out what is documented, what is merely asserted, and which circulating date you are better off ignoring.

What happened in the SAND bridge exploit and why is your balance frozen?

A bridge is a pair of contracts that makes tokens transferable from one blockchain to another: on the origin chain a holding is locked, on the destination chain an equal amount is issued. The token you then hold on the destination chain is a bridged token and therefore a claim on the locked original, not an asset in its own right.

That issuing function is exactly what was attacked on August 21, 2026. Through a configuration flaw in the SAND contracts on Base and BNB Smart Chain, the attacker was able to become the sole validator of incoming bridge messages, according to consistent accounts in the trade press. Whoever holds that role can self-confirm arbitrary transfers and then issue unbacked tokens. The chain notices nothing, because formally everything runs correctly.

The timing can be proven to the second

The first unauthorised mint falls on Base block 50,283,176 and on block 117,321,965 of BNB Smart Chain. We queried both blocks on September 4, 2026 through public nodes of the respective chain: the Base block carries the timestamp August 21, 2026, 23:41:39 UTC, the block on BNB Smart Chain 23:42:17 UTC the same evening. That leaves 38 seconds between the two chains.

The following morning The Sandbox closed the affected contracts. Since then, bridged SAND on Base and BNB Smart Chain can neither be moved nor redeemed. Anyone holding a balance there sees a number in their wallet with nothing actionable behind it for the time being. How that freeze came about, and why trading in this state was not a good idea, we wrote up on August 23 in our report on the SAND bridge exploit; this article picks up where that one ends.

How much SAND was actually stolen and where do the trillion figures come from?

This is where the biggest misunderstanding of the whole episode sits, and it shaped the German headlines of August 22. The number printed there was the minted amount. The actual damage is something else entirely.

  • Minted were unbacked tokens in astronomical quantities. crypto.news puts the amount at more than 339 trillion SAND across both chains; other analyses arrived at around 329 trillion. These tokens existed only on Base and BNB Smart Chain and were backed by nothing.
  • Drained, by contrast, is the amount the attacker was actually able to pull out of the deposited holding on Ethereum: around 14.74 million SAND, worth roughly $700,000.

The difference is not a detail. Measured against the maximum supply of three billion SAND, the real outflow amounts to just under 0.5 percent, and the unbacked minted volume never reached the holding on Ethereum. SAND sitting directly on Ethereum or on Polygon was at no point touched by the flaw, according to both trade outlets. If you hold your tokens there, none of this concerns you.

Torn-off steel bridge over dark water, a coin with a diamond-shaped symbol at the broken edge, behind it a lowered lock gate
According to the operator, the attacked bridge contracts are not to be reopened; future bridging would run through newly deployed contracts at different addresses.

Why the old bridge contracts on Base and BNB Chain will not reopen

The Sandbox says it has permanently shut down the affected contracts. The old contracts are not to be repaired or restarted. Two practical consequences follow for you, and the second is the more expensive one.

First: any later bridging of SAND would have to run through freshly deployed contracts at different contract addresses. Anything you send to the old address today lands, on the operator's account, in a contract that gives nothing back. Second: if you were entitled on the cut-off date and do not collect your claim on Ethereum, the amounts are said, on that same account, to become available later through the replacement contracts on Base and BNB Smart Chain. There is no date for that, and you should not plan around it.

Anyone self-custodying their SAND carries sole responsibility for the claim. That turns the question of how well your wallet access is secured into a money question here; our hardware wallet comparison shows where the devices differ in handling multiple chains.

Who is entitled to the SAND compensation and how was the cut-off date set?

A snapshot is a record of all balances at a particular block height. It decides who is owed what, and it is immutable, because a block height is not negotiable after the fact.

The cut-off for this compensation sits immediately before the first unauthorised mint, that is, at the two blocks named above. From that follows a property that is worth a great deal in practice: your claim is already fixed. Whatever you have tried to do with your frozen balance since August 22 changes nothing about the amount owed to you. Nor does the price SAND trades at today matter for the calculation, because the reimbursement is made in tokens and not in euros or dollars.

What the reimbursement explicitly is not

This is not price protection. You get back the same amount of SAND you held on August 21, on a different chain. Whether that amount is worth more or less today than before the attack remains your price risk. Compensation for trading opportunities missed during the weeks of the freeze is likewise not provided for.

Exchange or your own wallet: who has to file a SAND claim?

According to The Sandbox, more than 72 percent of eligible holdings sit at two centralised exchanges. Those two houses are to pay their affected customers directly, without the individual customers filing a claim. Which two exchanges are meant the operator has not stated publicly, and guesses are circulating for which there is no evidence. Go by what your own exchange writes to you, not by names from forums.

That produces a clear split in two:

  1. Your SAND was at an exchange. Then your job is to follow your provider's official notices and keep your account accessible. Check that the email address on file is current, because a credit is typically announced there. A credit as a rule arrives without any action by the customer and without a confirmation link.
  2. Your SAND was in your own wallet. Then you are responsible yourself. You still need access to exactly the address that held the balance on the cut-off date, and you need some ether for the transaction fee on Ethereum.

What self-custodians should prepare now

The claim attaches to the address, not to a person. Anyone who has changed wallets, reset a device or abandoned an address since the attack should restore access to the old address before the window opens. A second point is easily overlooked: the payout runs on Ethereum, and a transaction there costs fees in ether. Anyone holding balances exclusively on other chains would otherwise face a claim they cannot technically collect.

Almost empty brass hourglass on a blank, unprinted sheet of paper, next to it a coin with a diamond-shaped symbol
The operator has announced the start of the claim window only approximately and has so far given no date at all for its end.

When does the SAND claim window open and which date should you not trust?

The operator's statement of August 27 says the claim process is to open "within two weeks" and then stay open for "another two weeks". Straight arithmetic puts the opening somewhere around September 10, 2026 and the end somewhere around September 24. The second value is a calculation, not a commitment.

More important is a mix-up now doing the rounds: in at least one large data aggregator, September 10 appears as the closing day of the claim period. That contradicts the operator's statement, under which the period only begins around that date. Anyone relying on the aggregator value takes a date to be a deadline that, on the only primary statement available, is a start date. Rely on The Sandbox's own channels and treat any deadline you meet elsewhere as unconfirmed until it appears there.

On the quality of the evidence: the operator's post-mortem is a post on X dated August 27, 2026. We were unable to open it ourselves in this environment; its content is documented by two independently reporting trade outlets, Cointelegraph and crypto.news. It remains in any case a company's statement about itself, and we therefore report it attributed throughout.

How to tell a real SAND claim page from a scam site

Every announced compensation attracts imitations, and the attackers are fast: search results and the replies under official posts fill up with copies, experience shows, before the real portal is even online. Three rules carry further here than any case-by-case check.

  • A claim costs nothing beyond the network fee. Anyone asking you to send tokens first, to pay an "unlock fee" or to transfer a balance to an outside address is running a scam. With this reimbursement a prepayment would be pointless for the simple reason that your claim is already written on chain.
  • Never enter your seed phrase. No legitimate claim requires your twelve or twenty-four words. A page that asks for them has exactly one goal.
  • The address comes from the official channel, not from search. Open the claim page only through a link The Sandbox has published itself, and do not retype it from memory afterwards.

Anyone wanting to work with particular care sets up a fresh wallet application for the claim and connects only the one address that carries the entitlement. After the payout it is worth looking at the approvals granted: token approvals can be revoked individually in common wallets, and an approval nobody needs any more is an open door with no use.

What the case teaches about bridged tokens and wrapped coins

A bridged token is an IOU. As long as the pair of contracts works, you notice nothing, and the price moves in lockstep with the original. If one side falls away, you hold an entry on one chain whose backing sits elsewhere and for which you depend on the operator's cooperation.

This case is not a one-off. Only on September 1 we wrote up how many wrapped TON holdings were left stranded after the bridge shutdown on the cut-off date: there too what mattered was the end of redeemability rather than the price. Anyone working with bridges regularly should therefore keep two habits. First: larger holdings stay on the chain where the token is natively issued. Second: only as much sits on the destination chain as is genuinely needed for use there.

How to tell whether your token is native or bridged

A look at the block explorer of the chain in question is usually enough. If the token carries a contract address there that is marked as "bridged" or as a wrapper, you hold the derived version. In case of doubt the project's documentation decides which contract address on which chain is the native one.

Claiming SAND compensation: what to take away

  1. First establish where it was custodied on August 21. If your SAND was at a centralised exchange, you wait for its notice and keep your account reachable; a claim of your own is not even envisaged for the large majority. Which houses come into question for the European market at all is set out in the crypto exchange comparison.
  2. As a self-custodian, secure access to the cut-off address. The claim attaches to that address, and the payout runs over Ethereum, so you need some ether for the fee. If you use the occasion to rebuild your custody setup, the hardware wallet comparison helps with the choice.
  3. Take the deadline from the primary source, not from aggregators. September 10 is, on the operator's statement, the approximate start and not the end. Connect only the one address you need for the claim if you can, and revoke the approvals granted afterwards; which applications support that cleanly is shown in the software wallet comparison.

(As of September 4, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)

Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.

More from CryptoTicker