The Sandbox · Vulnerability Disclosure
The Sand Box Vulnerability Disclosure
Vulnerability disclosure
The Sandbox publishes a vulnerability disclosure policy for reporting security issues.
CompanyMetaverseGamingBlockchainNFTWeb3Virtual WorldsUser Generated ContentEthereumIdentity
Program:
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-08-30'
method: probed
source: >-
https://docs.sandbox.game/en/accounts/security-topics/officialtsblinks.md (the provider's own
"Official The Sandbox Links" page) + https://docs.sandbox.game/en/general/helpcontact + live
probes of Immunefi and every sandbox.game /.well-known/security.txt on 2026-08-30
summary: >-
ABSENCE RECORD, NOT A HIT. The Sandbox does not currently serve a reachable vulnerability
disclosure surface. It publishes no security.txt on any host, and the bug bounty program it links
from its own official-links page - https://immunefi.com/bounty/thesandbox/ - now returns HTTP 404,
as do both modern Immunefi URL forms for that program. NO `Security` pointer and NO
`VulnerabilityDisclosure` pointer are emitted; there is nothing live to point at.
pointer_basis: >-
A dead bounty link in the provider's own documentation is a finding about the provider, not a
disclosure program. Recording it as one would be exactly the false-presence failure the
well-known/ probe guards against.
security_txt:
found: false
probed:
- url: https://developers.sandbox.game/.well-known/security.txt
status: 404
- url: https://docs.sandbox.game/.well-known/security.txt
status: 404
- url: https://api.sandbox.game/.well-known/security.txt
status: 404
- url: https://www.sandbox.game/.well-known/security.txt
status: 403
note: Cloudflare bot interstitial; unreachable rather than confirmed absent.
- url: https://sandbox.game/.well-known/security.txt
status: 403
note: Cloudflare bot interstitial; unreachable rather than confirmed absent.
bug_bounty:
platform: Immunefi
advertised_by_provider: true
advertised_at: https://docs.sandbox.game/en/accounts/security-topics/officialtsblinks.md
advertised_url: https://immunefi.com/bounty/thesandbox/
live: false
probed:
- url: https://immunefi.com/bounty/thesandbox/
status: 404
checked: '2026-08-30'
- url: https://immunefi.com/bug-bounty/thesandbox/
status: 404
checked: '2026-08-30'
- url: https://immunefi.com/bug-bounty/thesandbox/scope/
status: 404
checked: '2026-08-30'
- url: https://immunefi.com/bug-bounty/thesandbox/information/
status: 404
checked: '2026-08-30'
note: >-
The program is real history - The Sandbox announced it on its own Medium in 2022 and Immunefi
still surfaces the program URLs in search - but every one of the four URL forms 404s today. It is
either retired or delisted. The consequence for a security researcher is concrete: the only
vulnerability-reporting route The Sandbox names on its official-links page is a dead end.
related_contacts:
- purpose: Security and anti-fraud reporting (bad actors, ToU violations, fraud)
email: report@sandbox.game
source: https://docs.sandbox.game/en/general/helpcontact
note: >-
This is a trust-and-safety channel for reporting scammers and platform abuse, NOT a technical
vulnerability disclosure address. Recorded so a future round does not promote it into one.
- purpose: Privacy and GDPR queries
email: privacy@sandbox.game
source: https://docs.sandbox.game/en/general/helpcontact
trust_center:
found: false
note: >-
No trust.sandbox.game or security.sandbox.game, and no page anywhere naming an audited
certification (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP). The nearest published assurance
practice is the smart-contract audit policy in the contracts monorepo
(https://github.com/thesandboxgame/sandbox-smart-contracts/blob/master/audit-best-practices.md),
which governs on-chain code, not the platform or the API. NO `TrustCenter` and NO `Compliance`
pointer emitted.
what_would_close_it:
- Serve an RFC 9116 /.well-known/security.txt on www.sandbox.game with a Contact and a Policy field.
- Repoint or remove the dead Immunefi link on the Official The Sandbox Links page.
checked: '2026-08-30'
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/the-sand-box-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.