generated: '2026-08-30' method: probed source: >- https://docs.sandbox.game/en/accounts/security-topics/officialtsblinks.md (the provider's own "Official The Sandbox Links" page) + https://docs.sandbox.game/en/general/helpcontact + live probes of Immunefi and every sandbox.game /.well-known/security.txt on 2026-08-30 summary: >- ABSENCE RECORD, NOT A HIT. The Sandbox does not currently serve a reachable vulnerability disclosure surface. It publishes no security.txt on any host, and the bug bounty program it links from its own official-links page - https://immunefi.com/bounty/thesandbox/ - now returns HTTP 404, as do both modern Immunefi URL forms for that program. NO `Security` pointer and NO `VulnerabilityDisclosure` pointer are emitted; there is nothing live to point at. pointer_basis: >- A dead bounty link in the provider's own documentation is a finding about the provider, not a disclosure program. Recording it as one would be exactly the false-presence failure the well-known/ probe guards against. security_txt: found: false probed: - url: https://developers.sandbox.game/.well-known/security.txt status: 404 - url: https://docs.sandbox.game/.well-known/security.txt status: 404 - url: https://api.sandbox.game/.well-known/security.txt status: 404 - url: https://www.sandbox.game/.well-known/security.txt status: 403 note: Cloudflare bot interstitial; unreachable rather than confirmed absent. - url: https://sandbox.game/.well-known/security.txt status: 403 note: Cloudflare bot interstitial; unreachable rather than confirmed absent. bug_bounty: platform: Immunefi advertised_by_provider: true advertised_at: https://docs.sandbox.game/en/accounts/security-topics/officialtsblinks.md advertised_url: https://immunefi.com/bounty/thesandbox/ live: false probed: - url: https://immunefi.com/bounty/thesandbox/ status: 404 checked: '2026-08-30' - url: https://immunefi.com/bug-bounty/thesandbox/ status: 404 checked: '2026-08-30' - url: https://immunefi.com/bug-bounty/thesandbox/scope/ status: 404 checked: '2026-08-30' - url: https://immunefi.com/bug-bounty/thesandbox/information/ status: 404 checked: '2026-08-30' note: >- The program is real history - The Sandbox announced it on its own Medium in 2022 and Immunefi still surfaces the program URLs in search - but every one of the four URL forms 404s today. It is either retired or delisted. The consequence for a security researcher is concrete: the only vulnerability-reporting route The Sandbox names on its official-links page is a dead end. related_contacts: - purpose: Security and anti-fraud reporting (bad actors, ToU violations, fraud) email: report@sandbox.game source: https://docs.sandbox.game/en/general/helpcontact note: >- This is a trust-and-safety channel for reporting scammers and platform abuse, NOT a technical vulnerability disclosure address. Recorded so a future round does not promote it into one. - purpose: Privacy and GDPR queries email: privacy@sandbox.game source: https://docs.sandbox.game/en/general/helpcontact trust_center: found: false note: >- No trust.sandbox.game or security.sandbox.game, and no page anywhere naming an audited certification (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP). The nearest published assurance practice is the smart-contract audit policy in the contracts monorepo (https://github.com/thesandboxgame/sandbox-smart-contracts/blob/master/audit-best-practices.md), which governs on-chain code, not the platform or the API. NO `TrustCenter` and NO `Compliance` pointer emitted. what_would_close_it: - Serve an RFC 9116 /.well-known/security.txt on www.sandbox.game with a Contact and a Policy field. - Repoint or remove the dead Immunefi link on the Official The Sandbox Links page. checked: '2026-08-30'