PublicAML

The Sandbox SAND Bridge Exploited for $675,000

The Sandbox's SAND cross-chain bridge was exploited, resulting in a loss of approximately $675,000. The attacker gained sole verifier rights and minted unbacked SAND, draining funds from the Ethereum vault.

The Sandbox's SAND cross-chain bridge was exploited, leading to a significant financial loss. The attacker utilized a configuration function to obtain sole verifier rights, which allowed them to mint large amounts of unbacked SAND. This action resulted in the draining of approximately 14.74 million real SAND, valued at around $675,000, from the Ethereum vault.

In response to the incident, The Sandbox quickly halted the affected bridging operations. It is important to note that assets on Ethereum and Polygon remained unaffected by this exploit. The incident highlights vulnerabilities in the bridge's configuration that were exploited to facilitate the unauthorized minting of tokens.

The specific chain involved in this incident was Ethereum, as the drained funds were sourced from its vault. The use of a cross-chain bridge indicates that the exploit could potentially have implications across multiple chains, although the immediate impact was confined to Ethereum. The on-chain record would reflect the unauthorized minting and draining of SAND, although specific addresses involved were not disclosed.

Sources

Share:XTelegramLinkedIn
The Sandbox SAND Bridge Exploited for $675,000 | PublicAML