The Sandbox LANDs are migrating to a new smart contract
TL;DR
- A new version of the LAND smart-contract has been deployed; its address is 0x5CC5B05a8A13E3fBDB0BB9FcCd98D38e50F90c38
- The migration interface can be found here: https://sandbox.game/en/me/migration/
- The previous smart contract contained a vulnerability that was first reported on December 25th, 2021.
- The vulnerability has been fixed and the fix audited. It has not been exploited by any malicious user and has now been secured.
- The issue did not allow transfers nor minting of new LAND and no tokens have been compromised. Additionally, we have run thorough investigations on our other smart contracts and none of them are at risk.
- We deployed a migration smart contract to let everyone migrate their LAND to the new LAND contract; its address is 0x371f4c6fd305c6772Bc6224b795b0B46b6B6f8dB
- There is no cost involved on the user’s side. All migration gas costs are entirely covered by The Sandbox.
The Sandbox smart contracts were extensively audited by two top security firms, Certik and Solidified, and received high-security scores. These audits can be accessed publicly on our Github repository. The LAND smart contract was originally audited by Certik on December 10th, 2019, and involved three auditors through a two-week process.
However, a vulnerability was first discovered on December 25th, 2021.
Upon learning of the vulnerability, we took immediate action to fix the issue, as the following timeline demonstrates:
- On Dec 25th, a security researcher called Danel Hazlewood (@Alphasoups) notified us of the vulnerability.
- On Dec 25th, we carried out internal tests and confirmed the reproducibility of the issue.
- Between December 25th and 30th, we worked on a fix and submitted it for audit again by Certik security auditors to confirm the fix didn’t introduce new vulnerabilities.
- After consulting with fellow developers, we all agreed the best course of action was to deploy the fix and enable users to migrate all LAND tokens to the new smart contract without any costs (gasless support).
- The root cause has been investigated and a new smart contract migration and interface has been developed.
- On January 28th, we deployed the new fixed smart contract; the address is 0x371f4c6fd305c6772Bc6224b795b0B46b6B6f8dB
- We also deployed additional security measures to ensure the safety of all LAND while the migration is in progress
- On January 28th, we released our migration interface to let every LAND owner migrate their LAND tokens to the new contract. All the gas costs associated are entirely covered by The Sandbox. No fees are incurred by our users
After peer-reviewing several solutions, we all agreed that the best course of action was to schedule a migration from the old LAND contract to the new one.
This migration is not forced upon users. They can do it at their own pace when they are ready.
We are covering the gas costs through the deployment of a gasless feature for this migration.
So, don’t worry — this process:
- Is free to all users
- Has no time limit
We released the migration interface on January 28th:
If you need support to migrate your LAND tokens, please contact us through
We plan to keep the community updated on the overall progress of the migration. We are aware this is a very unique situation and are doing everything we can to keep the process as seamless and transparent as possible.
Thank you for your support and understanding.