Industry News

Crypto Bridge Exploits Highlight Risks of Overlooked Smart Contract Configurations

Cryptopolitan · 9 Sept 2026
Key Takeaway Businesses using blockchain or bridge-based financial tools should review how cross-chain messaging and contract permissions are configured, since attackers increasingly exploit trust relationships between systems rather than breaking encryption directly.

The Sandbox, a blockchain gaming platform, has begun processing refund claims for users who lost bridged SAND tokens in an August 22 exploit. Attackers found that SAND token contracts on Base and BNB Smart Chain were configured to act as the bridge's registered application, allowing messages from that source to be treated as legitimate instructions. By registering their own address as administrator, the attackers approved fraudulent bridge messages, minted tokens against deposits that never occurred, and withdrew nearly 14.75 million SAND from the Ethereum vault, causing roughly $1.49 million in damage.

The Sandbox has permanently shut down the affected bridge, stating that control over the compromised contracts can never be fully trusted again. Individual wallet holders must submit claims through the project's portal for a 1:1 refund in SAND on Ethereum, while exchange users will be compensated automatically.

A separate but related incident affected Cronos, a blockchain linked to Crypto.com, where attackers manipulated the thinly traded TONIC token to inflate its value roughly 100 times within 20 minutes, then borrowed real assets against the fake valuation. Cronos halted block production to contain the damage and appears further along in recovery than The Sandbox.

Summarised by CISO AI from Cryptopolitan. We link back to every original so you can read it yourself.