The Sandbox · Vulnerability Disclosure

The Sand Box Vulnerability Disclosure

Vulnerability disclosure

The Sandbox publishes a vulnerability disclosure policy for reporting security issues.

CompanyMetaverseGamingBlockchainNFTWeb3Virtual WorldsUser Generated ContentEthereumIdentity
Program:

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

the-sand-box-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-30'
method: probed
source: >-
  https://docs.sandbox.game/en/accounts/security-topics/officialtsblinks.md (the provider's own
  "Official The Sandbox Links" page) + https://docs.sandbox.game/en/general/helpcontact + live
  probes of Immunefi and every sandbox.game /.well-known/security.txt on 2026-08-30
summary: >-
  ABSENCE RECORD, NOT A HIT. The Sandbox does not currently serve a reachable vulnerability
  disclosure surface. It publishes no security.txt on any host, and the bug bounty program it links
  from its own official-links page - https://immunefi.com/bounty/thesandbox/ - now returns HTTP 404,
  as do both modern Immunefi URL forms for that program. NO `Security` pointer and NO
  `VulnerabilityDisclosure` pointer are emitted; there is nothing live to point at.
pointer_basis: >-
  A dead bounty link in the provider's own documentation is a finding about the provider, not a
  disclosure program. Recording it as one would be exactly the false-presence failure the
  well-known/ probe guards against.
security_txt:
  found: false
  probed:
  - url: https://developers.sandbox.game/.well-known/security.txt
    status: 404
  - url: https://docs.sandbox.game/.well-known/security.txt
    status: 404
  - url: https://api.sandbox.game/.well-known/security.txt
    status: 404
  - url: https://www.sandbox.game/.well-known/security.txt
    status: 403
    note: Cloudflare bot interstitial; unreachable rather than confirmed absent.
  - url: https://sandbox.game/.well-known/security.txt
    status: 403
    note: Cloudflare bot interstitial; unreachable rather than confirmed absent.
bug_bounty:
  platform: Immunefi
  advertised_by_provider: true
  advertised_at: https://docs.sandbox.game/en/accounts/security-topics/officialtsblinks.md
  advertised_url: https://immunefi.com/bounty/thesandbox/
  live: false
  probed:
  - url: https://immunefi.com/bounty/thesandbox/
    status: 404
    checked: '2026-08-30'
  - url: https://immunefi.com/bug-bounty/thesandbox/
    status: 404
    checked: '2026-08-30'
  - url: https://immunefi.com/bug-bounty/thesandbox/scope/
    status: 404
    checked: '2026-08-30'
  - url: https://immunefi.com/bug-bounty/thesandbox/information/
    status: 404
    checked: '2026-08-30'
  note: >-
    The program is real history - The Sandbox announced it on its own Medium in 2022 and Immunefi
    still surfaces the program URLs in search - but every one of the four URL forms 404s today. It is
    either retired or delisted. The consequence for a security researcher is concrete: the only
    vulnerability-reporting route The Sandbox names on its official-links page is a dead end.
related_contacts:
- purpose: Security and anti-fraud reporting (bad actors, ToU violations, fraud)
  email: report@sandbox.game
  source: https://docs.sandbox.game/en/general/helpcontact
  note: >-
    This is a trust-and-safety channel for reporting scammers and platform abuse, NOT a technical
    vulnerability disclosure address. Recorded so a future round does not promote it into one.
- purpose: Privacy and GDPR queries
  email: privacy@sandbox.game
  source: https://docs.sandbox.game/en/general/helpcontact
trust_center:
  found: false
  note: >-
    No trust.sandbox.game or security.sandbox.game, and no page anywhere naming an audited
    certification (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP). The nearest published assurance
    practice is the smart-contract audit policy in the contracts monorepo
    (https://github.com/thesandboxgame/sandbox-smart-contracts/blob/master/audit-best-practices.md),
    which governs on-chain code, not the platform or the API. NO `TrustCenter` and NO `Compliance`
    pointer emitted.
what_would_close_it:
- Serve an RFC 9116 /.well-known/security.txt on www.sandbox.game with a Contact and a Policy field.
- Repoint or remove the dead Immunefi link on the Official The Sandbox Links page.
checked: '2026-08-30'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/the-sand-box-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.