If you held SAND through the bridge on Base or on BNB Smart Chain, the short answer is this: you are due to get your balance back, one for one, paid out as SAND on Ethereum. According to The Sandbox, the money comes from its own treasury, meaning the company's existing holdings, and no new tokens will be minted for it. Whether you have to do anything yourself hinges on a single question: on the evening of August 21, was your SAND sitting at a centralised exchange or in your own wallet?
For most of those affected the answer is "at an exchange", and that majority does not need to file a claim at all. For everyone else, a claim window opens whose start date the operator has given only approximately and whose end is not fixed at all so far. This article sorts out what is documented, what is merely asserted, and which circulating date you are better off ignoring.
A bridge is a pair of contracts that makes tokens transferable from one blockchain to another: on the origin chain a holding is locked, on the destination chain an equal amount is issued. The token you then hold on the destination chain is a bridged token and therefore a claim on the locked original, not an asset in its own right.
That issuing function is exactly what was attacked on August 21, 2026. Through a configuration flaw in the SAND contracts on Base and BNB Smart Chain, the attacker was able to become the sole validator of incoming bridge messages, according to consistent accounts in the trade press. Whoever holds that role can self-confirm arbitrary transfers and then issue unbacked tokens. The chain notices nothing, because formally everything runs correctly.
The first unauthorised mint falls on Base block 50,283,176 and on block 117,321,965 of BNB Smart Chain. We queried both blocks on September 4, 2026 through public nodes of the respective chain: the Base block carries the timestamp August 21, 2026, 23:41:39 UTC, the block on BNB Smart Chain 23:42:17 UTC the same evening. That leaves 38 seconds between the two chains.
The following morning The Sandbox closed the affected contracts. Since then, bridged SAND on Base and BNB Smart Chain can neither be moved nor redeemed. Anyone holding a balance there sees a number in their wallet with nothing actionable behind it for the time being. How that freeze came about, and why trading in this state was not a good idea, we wrote up on August 23 in our report on the SAND bridge exploit; this article picks up where that one ends.
This is where the biggest misunderstanding of the whole episode sits, and it shaped the German headlines of August 22. The number printed there was the minted amount. The actual damage is something else entirely.
The difference is not a detail. Measured against the maximum supply of three billion SAND, the real outflow amounts to just under 0.5 percent, and the unbacked minted volume never reached the holding on Ethereum. SAND sitting directly on Ethereum or on Polygon was at no point touched by the flaw, according to both trade outlets. If you hold your tokens there, none of this concerns you.

The Sandbox says it has permanently shut down the affected contracts. The old contracts are not to be repaired or restarted. Two practical consequences follow for you, and the second is the more expensive one.
First: any later bridging of SAND would have to run through freshly deployed contracts at different contract addresses. Anything you send to the old address today lands, on the operator's account, in a contract that gives nothing back. Second: if you were entitled on the cut-off date and do not collect your claim on Ethereum, the amounts are said, on that same account, to become available later through the replacement contracts on Base and BNB Smart Chain. There is no date for that, and you should not plan around it.
Anyone self-custodying their SAND carries sole responsibility for the claim. That turns the question of how well your wallet access is secured into a money question here; our hardware wallet comparison shows where the devices differ in handling multiple chains.
A snapshot is a record of all balances at a particular block height. It decides who is owed what, and it is immutable, because a block height is not negotiable after the fact.
The cut-off for this compensation sits immediately before the first unauthorised mint, that is, at the two blocks named above. From that follows a property that is worth a great deal in practice: your claim is already fixed. Whatever you have tried to do with your frozen balance since August 22 changes nothing about the amount owed to you. Nor does the price SAND trades at today matter for the calculation, because the reimbursement is made in tokens and not in euros or dollars.
This is not price protection. You get back the same amount of SAND you held on August 21, on a different chain. Whether that amount is worth more or less today than before the attack remains your price risk. Compensation for trading opportunities missed during the weeks of the freeze is likewise not provided for.
According to The Sandbox, more than 72 percent of eligible holdings sit at two centralised exchanges. Those two houses are to pay their affected customers directly, without the individual customers filing a claim. Which two exchanges are meant the operator has not stated publicly, and guesses are circulating for which there is no evidence. Go by what your own exchange writes to you, not by names from forums.
That produces a clear split in two:
The claim attaches to the address, not to a person. Anyone who has changed wallets, reset a device or abandoned an address since the attack should restore access to the old address before the window opens. A second point is easily overlooked: the payout runs on Ethereum, and a transaction there costs fees in ether. Anyone holding balances exclusively on other chains would otherwise face a claim they cannot technically collect.

The operator's statement of August 27 says the claim process is to open "within two weeks" and then stay open for "another two weeks". Straight arithmetic puts the opening somewhere around September 10, 2026 and the end somewhere around September 24. The second value is a calculation, not a commitment.
More important is a mix-up now doing the rounds: in at least one large data aggregator, September 10 appears as the closing day of the claim period. That contradicts the operator's statement, under which the period only begins around that date. Anyone relying on the aggregator value takes a date to be a deadline that, on the only primary statement available, is a start date. Rely on The Sandbox's own channels and treat any deadline you meet elsewhere as unconfirmed until it appears there.
On the quality of the evidence: the operator's post-mortem is a post on X dated August 27, 2026. We were unable to open it ourselves in this environment; its content is documented by two independently reporting trade outlets, Cointelegraph and crypto.news. It remains in any case a company's statement about itself, and we therefore report it attributed throughout.
Every announced compensation attracts imitations, and the attackers are fast: search results and the replies under official posts fill up with copies, experience shows, before the real portal is even online. Three rules carry further here than any case-by-case check.
Anyone wanting to work with particular care sets up a fresh wallet application for the claim and connects only the one address that carries the entitlement. After the payout it is worth looking at the approvals granted: token approvals can be revoked individually in common wallets, and an approval nobody needs any more is an open door with no use.
A bridged token is an IOU. As long as the pair of contracts works, you notice nothing, and the price moves in lockstep with the original. If one side falls away, you hold an entry on one chain whose backing sits elsewhere and for which you depend on the operator's cooperation.
This case is not a one-off. Only on September 1 we wrote up how many wrapped TON holdings were left stranded after the bridge shutdown on the cut-off date: there too what mattered was the end of redeemability rather than the price. Anyone working with bridges regularly should therefore keep two habits. First: larger holdings stay on the chain where the token is natively issued. Second: only as much sits on the destination chain as is genuinely needed for use there.
A look at the block explorer of the chain in question is usually enough. If the token carries a contract address there that is marked as "bridged" or as a wrapper, you hold the derived version. In case of doubt the project's documentation decides which contract address on which chain is the native one.
(As of September 4, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)