en
Back to the list

The Sandbox, Cronos move on from hacks as researchers urged to report bug responsibly

source-logo  cryptopolitan.com 28 m
image

The Sandbox has begun accepting compensation claims from users who lost bridged $SAND in an August exploit.

The move to make users whole is coming around the same time that hardware wallet makers Ledger and Trezor are warning that the next wave of bugs is arriving at a pace that is faster than what defenders can patch.

The Sandbox reopens the claim window

Sandbox shared the information on X on September 8, stating that anyone who held bridged $SAND on Base or $BNB Smart Chain before the August 22 exploit can now file for a full 1:1 refund paid in $SAND on Ethereum.

It said that individual wallet holders need to submit a claim through the project’s portal, while users who held the token on an exchange do not have to do anything.

The Sandbox post-mortem shows the pool of funds that was lost was around $697,000, as Cryptopolitan reported. The balances on Ethereum and Polygon were never touched, and the Ethereum supply still has 3 billion tokens.

$SAND currently trades around $0.041, having risen by over 2.7% in the past 24 hours. However, it is worth noting that it is currently well off its November 2021 record of $8.44.

How did the Sandbox bridge attack occur?

The post-mortem pointed fingers to the $SAND token contracts on Base and $BNB Smart Chain, which had been configured to double as the bridge’s registered application so users could skip extra transactions. The messaging layer read anything from that source as an order from The Sandbox.

Attackers registered their own address as administrator, loosened the settings so a single self-approval cleared a bridge message, minted $SAND against deposits that never happened, and then reverse-bridged real tokens out of the Ethereum vault.

Forensics pinned the vault withdrawal at 14,742,341.84 $SAND and total economic damage near $1.49 million. The Sandbox shut the bridge across all three chains on August 22.

The Sandbox team has ruled out reopening the bridge, as it says that control over the compromised contracts is “contestable forever.”

Cronos recovers after the Tectonic drain

Another project, Cronos, that suffered an exploit towards the end of August, seems to be further along in its recovery. The Crypto.com-linked chain halted block production on August 30 to contain an attack on Tectonic, its largest lending market, as Cryptopolitan reported.

An attacker reportedly inflated the thinly traded TONIC token around 100 times in 20 minutes. They then borrowed real assets against the fake value.

The freeze worked, as only about $6 million out of the roughly $75 million exposed reached Ethereum before the chain stopped, security firm PeckShield confirmed.

Crypto.com CEO Kris Marszalek said the exchange and app were never compromised. Cronos has since come back online, and Tectonic’s total value locked, which had cratered from about $122 million to under $3 million, has climbed back above $121 million.

Ledger and Trezor press for private reporting

While the platforms are working on trying to make affected users whole, two of the industry’s best-known cold wallet makers, Ledger and Trezor, have highlighted some of the security challenges that platforms have to grapple with, especially when it comes to disclosures of vulnerabilities.

Charles Guillemet, chief technology officer at Ledger, said that AI has made vulnerabilities cheap to find. In an X post, Guillemet stated that AI being introduced into the mix has also stripped defenders of the head start they once had.

He called out the fact that some researchers now publish findings before a fix exists, which he called “attention farming with someone else’s risk.”

On the process of disclosures, he urged researchers to report the issues privately and settle on a fixed timeline first, citing 90 days as a common default that flexes with severity. Trezor supported Guillemet’s comments on X, stating that they are firmly behind responsible disclosure.

Jan Komarek, Trezor’s head of security, shared his thoughts on the matter, stating, “Ninety days is a commitment on the vendor, not just on the researcher.” He added that researchers can go ahead and publish their findings if the vendor misses the window.

The push follows Coldcard thefts topping $100 million and a breach at Trezor’s shipping provider that exposed tens of thousands of customers.

cryptopolitan.com