Crypto Bridge Exploits Highlight Risks of Overlooked Smart Contract Configurations
The Sandbox, a blockchain gaming platform, has begun processing refund claims for users who lost bridged SAND tokens in an August 22 exploit. Attackers found that SAND token contracts on Base and BNB Smart Chain were configured to act as the bridge's registered application, allowing messages from that source to be treated as legitimate instructions. By registering their own address as administrator, the attackers approved fraudulent bridge messages, minted tokens against deposits that never occurred, and withdrew nearly 14.75 million SAND from the Ethereum vault, causing roughly $1.49 million in damage.
The Sandbox has permanently shut down the affected bridge, stating that control over the compromised contracts can never be fully trusted again. Individual wallet holders must submit claims through the project's portal for a 1:1 refund in SAND on Ethereum, while exchange users will be compensated automatically.
A separate but related incident affected Cronos, a blockchain linked to Crypto.com, where attackers manipulated the thinly traded TONIC token to inflate its value roughly 100 times within 20 minutes, then borrowed real assets against the fake valuation. Cronos halted block production to contain the damage and appears further along in recovery than The Sandbox.