Preview surface — demo data. Where real data exists today (e.g. RealT, BlackRock BUIDL, Lift Dollar) we render it; everywhere else we render synthetic enrichment generated deterministically from public signal and clearly marked Demo or Inferred. The Phase 3 roadmap replaces every synthetic source with live ingestion — see Methodology → Exposure Graph & Similarity Engine.

The Sandbox

Identity, NFTs, Gaming & Consumer Appslow·risk 0.2800·TVL $0·blast $0·active
Static profile (Identity / Contract / Dependency / Governance / Reputation)

Identity

Sector
Identity, NFTs, Gaming & Consumer Apps
Subsector tags
consumer_app, general_defi, infra_toolingDemo
Chain deployments
Ethereum, Polygon
Website
https://www.the-sandbox.xyzDemo
Launch date
Dec 21, 2021
Immutable
noDemo
Permissionless
yesDemo

Contract

Primary address
0x3845badAde8e6dFF049820680d1F14bD3903a5d0
Proxy pattern
none
Upgrade authority
UNKNOWN
Multisig threshold
Compiler
0.7.6
Uses assembly
noDemo
Bug bounty
noneDemo
Contract addresses
0x3845badAde8e6dFF049820680d1F14bD3903a5d0Demo
Audits tier
0

Dependency

Oracle providers
Bridge dependencies
Stablecoin dependencies
LST / LRT deps
Demo
DEX liquidity venues
camelot, curveDemo
CEX listings
Demo
Custodian
Demo
KMS provider
unknownDemo
RPC provider
alchemyDemo
Frontend host
fleekDemo
npm lockfile sha
sha256:b87e2406f417568c7f769188fc1fa9502bc9b44d2739ee81e289f1f9fe1bd2ebDemo

Governance

Governance type
token_votingDemo
Governance token
0xc96010aea196c695ae602971e2cae571235b05a9Demo
Treasury size
$0Demo
Team size
6Demo
Jurisdiction
ILDemo
Incorporated entity
The Sandbox DAO LLCDemo
Anonymous team
noDemo
Security disclosure
yesDemo
IR SLA (hours)
72Demo

Reputation

GitHub
https://github.com/the-sandbox/the-sandboxDemo
Commit velocity (30d)
39Demo
Contributors
7Demo
Twitter
@the-sandboxDemo
Discord
https://discord.gg/n5n9qvDemo
Last incident
Feb 28, 2025Demo
KYT screening
cleanDemo

Threat History

3 recorded incidents
oracle manipulationprotocolwhitehatDemo
$51.9M

On 2025-02-28, The Sandbox suffered a oracle manipulation incident resulting in approximately $51,903,519 in losses. The exploit targeted the protocol layer. Attribution: whitehat. This is a demonstration entry — not a real incident.

DEMO:AADAPT.TA0040DEMO:AADAPT.TA0007
signature malleabilityprotocolunknownDemo
$3.9M

On 2023-11-23, The Sandbox suffered a signature malleability incident resulting in approximately $3,941,318 in losses. The exploit targeted the protocol layer. Attribution: unknown. This is a demonstration entry — not a real incident.

DEMO:AADAPT.TA0004
ice phishing approvalhuman opunknownDemo
$121.6K

On 2023-07-12, The Sandbox suffered a ice phishing approval incident resulting in approximately $121,624 in losses. The exploit targeted the human_op layer. Attribution: unknown. This is a demonstration entry — not a real incident.

DEMO:AADAPT.TA0001DEMO:AADAPT.TA0040

Peer Incidents · Method B

7 root-cause predicate matches

Vulnerable to: phishing drainer

Matches the phishing drainer predicate

18 historical peer events
  • GoldfinchDemo
    $1M
  • BitgetDemo
    $739.9K
  • OrcaDemo
    $180.8K
  • Ether.fiDemo
    $443.4K
  • Alchemy PayDemo
    $334.2K
  • + 13 more

Vulnerable to: flash loan governance

Matches the flash loan governance predicate

18 historical peer events
  • ThirdwebDemo
    $33.2M
  • LayerZero Labs (physical verification context only)Demo
    $40.2M
  • First Digital USDDemo
    $12.1M
  • Protocol-Native Treasury Agents (DAO-embedded)Demo
    $13.8M
  • F2PoolDemo
    $3.5M
  • + 13 more

Vulnerable to: ice phishing approval

Matches the ice phishing approval predicate

15 historical peer events
  • deBridgeDemo
    $7.5M
  • EulerDemo
    $87.9K
  • Bend DAODemo
    $968.9K
  • Maple FinanceDemo
    $1.4M
  • BlurDemo
    $6.5M
  • + 10 more

Vulnerable to: supply chain npm

Matches the supply chain npm predicate

10 historical peer events
  • Beefy FinanceDemo
    $176.2K
  • PowerledgerDemo
    $7.4M
  • UnichainDemo
    $8.8M
  • MEXCDemo
    $1M
  • Mango MarketsDemo
    $915.6K
  • + 5 more

Vulnerable to: dvn collapse

Matches the dvn collapse predicate

8 historical peer events
  • Blast, Blockdaemon Wallet +2Demo
    $93.6M
  • Fordefi, XSGDDemo
    $17M
  • Element Finance, QuantozDemo
    $1.1M
  • Mercado Bitcoin, SwellDemo
    $15.3M
  • Internet Computer (DFINITY), Mantle +1Demo
    $10.3M
  • + 3 more

Vulnerable to: signature malleability

Matches the signature malleability predicate

7 historical peer events
  • Ether.fiDemo
    $17.2M
  • Swell NetworkDemo
    $1.2M
  • Immutable protocolDemo
    $4M
  • PancakeSwapDemo
    $656.7K
  • EulerDemo
    $4.9M
  • + 2 more

Vulnerable to: governance proposal malicious

Matches the governance proposal malicious predicate

5 historical peer events
  • Stripe CryptoDemo
    $1.5M
  • Notional V3Demo
    $507.1K
  • Hong Kong Monetary Authority — Ethereum pilotsDemo
    $18.9M
  • FalconXDemo
    $4.8M
  • AvailDemo
    $30.8M

Dependency Twins · Method A + B + C ensemble

Top 10 of 25 precomputed
#1

Immutable protocol

Stablecoin Issuers & Synthetic Dollars · medium
Ensemble
0.425
A · Jaccard0.14
B · Overlap2
C · Cosine0.74
Matches on
  • kms_provider = unknown
  • subsector_tags = consumer_app, general_defi, infra_tooling
  • chain_deployments = Ethereum
  • method_b_root_causes = signature_malleability
#2

Euler

Lending, Money Markets & CDPs · low
Ensemble
0.390
A · Jaccard0.07
B · Overlap2
C · Cosine0.70
Matches on
  • subsector_tags = general_defi, infra_tooling
  • chain_deployments = Ethereum
  • method_b_root_causes = signature_malleability, ice_phishing_approval
#3

Goldfinch

Lending, Money Markets & CDPs · medium
Ensemble
0.382
A · Jaccard0.14
B · Overlap1
C · Cosine0.87
Matches on
  • kms_provider = unknown
  • subsector_tags = consumer_app, general_defi, infra_tooling
  • chain_deployments = Ethereum
  • method_b_root_causes = phishing_drainer
#4

Safe{Core}

Institutional Custody & Prime Services · low
Ensemble
0.378
A · Jaccard0.14
B · Overlap1
C · Cosine0.85
Matches on
  • kms_provider = unknown
  • subsector_tags = general_defi, consumer_app, infra_tooling
  • chain_deployments = Ethereum
  • method_b_root_causes = flash_loan_governance
#5

Blur

Identity, NFTs, Gaming & Consumer Apps · high
Ensemble
0.374
A · Jaccard0.13
B · Overlap1
C · Cosine0.85
Matches on
  • kms_provider = unknown
  • subsector_tags = infra_tooling, general_defi, consumer_app
  • chain_deployments = Ethereum
  • method_b_root_causes = ice_phishing_approval
#6

MEXC

Centralized Exchanges & Brokerages · critical
Ensemble
0.373
A · Jaccard0.05
B · Overlap2
C · Cosine0.66
Matches on
  • subsector_tags = general_defi, consumer_app, infra_tooling
  • chain_deployments = Ethereum, Polygon
  • method_b_root_causes = supply_chain_npm, ice_phishing_approval
#7

Credora

Compliance, Forensics & Audit Tooling · medium
Ensemble
0.372
A · Jaccard0.10
B · Overlap1
C · Cosine0.87
Matches on
  • kms_provider = unknown
  • subsector_tags = infra_tooling, general_defi, consumer_app
  • method_b_root_causes = flash_loan_governance
#8

CCIP (Chainlink)

Cross-Chain Bridges & Messaging · low
Ensemble
0.369
A · Jaccard0.10
B · Overlap1
C · Cosine0.86
Matches on
  • kms_provider = unknown
  • subsector_tags = infra_tooling, general_defi, consumer_app
  • method_b_root_causes = flash_loan_governance
#9

Swell Network

Liquid Staking & Restaking · high
Ensemble
0.367
A · Jaccard0.14
B · Overlap1
C · Cosine0.82
Matches on
  • kms_provider = unknown
  • subsector_tags = consumer_app, infra_tooling, general_defi
  • chain_deployments = Ethereum
  • method_b_root_causes = signature_malleability
#10

Opyn

Stablecoin Issuers & Synthetic Dollars · medium
Ensemble
0.366
A · Jaccard0.14
B · Overlap1
C · Cosine0.81
Matches on
  • kms_provider = unknown
  • subsector_tags = infra_tooling, consumer_app
  • chain_deployments = Ethereum, Polygon
  • method_b_root_causes = flash_loan_governance