The Sandbox (SAND) sustainability report
| Name | BlockNodes SAS |
| Relevant legal entity identifier | 969500PZJWT3TD1SUI59 |
| Name of the crypto-asset | The Sandbox |
| Beginning of the period to which the disclosure relates | 2025-09-27 |
| End of the period to which the disclosure relates | 2026-09-27 |
| Energy consumption | 933.78370 kWh/a |
Consensus Mechanism
The Sandbox is present on the following networks: Base, Ethereum, Polygon.
Base is a Layer 2 network that executes transactions away from the Ethereum chain and settles them on it. It runs no consensus protocol of its own and has no validator set of its own. Agreement about which Base transactions occurred, and in what order, is ultimately established by the data and the state commitments the network publishes to Ethereum, which are secured by Ethereum's proof-of-stake consensus.
Ordering and execution on the Layer 2 are carried out by a single sequencer, operated by the company that launched the network. It receives transactions, places them into blocks at a fixed cadence and returns a result to the user straight away; those blocks are then compressed and posted to Ethereum in batches, alongside commitments to the state they produce. Once a batch sits inside a finalized Ethereum block, the ordering it encodes is as hard to reverse as Ethereum itself. Users are not wholly dependent on the sequencer for access: a transaction can instead be submitted through a contract on Ethereum, and the rules by which the Layer 2 chain is derived oblige it to be included, which bounds how far the sequencer can censor.
Base is an optimistic rollup, built on the shared OP Stack codebase and part of the Superchain group of networks that use it. State commitments are accepted as correct unless disputed. Anyone may propose one and anyone may challenge one within a dispute window, by playing an interactive game on Ethereum that narrows the disagreement down to a single step of execution, which an Ethereum contract then settles by running that step itself. Both sides post bonds, so an untrue claim and a frivolous challenge are each expensive. Permissionless fault proofs have run on the main network since late 2024, and a multi-party security council with a supermajority threshold governs changes to the contracts; together these place the network at the intermediate tier of the rollup maturity scale commonly used to compare such systems. A withdrawal to Ethereum cannot complete until the dispute window for the relevant commitment has elapsed. Decentralizing the sequencer itself remains outstanding work.
Ethereum reaches agreement through proof of stake, adopted in September 2022 when the original mining-based chain was retired in favor of a validator-driven consensus layer. The protocol family is usually referred to as Gasper. A fork-choice rule named LMD-GHOST selects the head of the chain by following the branch carrying the greatest accumulated weight of validator votes, while a separate finality gadget, Casper FFG, periodically justifies and then finalizes checkpoints, so that reversing them would require destroying an enormous quantity of bonded value.
Time is divided into slots of twelve seconds, and thirty-two slots form an epoch. For each slot the protocol pseudo-randomly designates one active validator to assemble and publish a block, and assigns the rest to committees that vote on what they believe is the correct head and the correct checkpoints. Under healthy conditions a checkpoint becomes final two epochs after it is proposed, a little under thirteen minutes, after which everything beneath it is treated as settled.
Joining the validator set requires a deposit of no fewer than 32 units of the native asset. Since the protocol upgrade of May 2025 a single validator may hold a far larger balance, up to 2,048 units, and earn on the whole of it, which lets an operator running many minimum-sized validators consolidate them into fewer; the activation floor itself did not change. Entry and exit are rate-limited by a queue measured in staked weight rather than in validator headcount, which bounds how fast the composition of the set can turn over.
Security rests on voting power being bonded. A validator that signs contradictory messages can be proved to have done so and is penalized, and the size of that penalty scales with how much other stake was penalized at the same time, so a coordinated attack is punished far more severely than an isolated fault. Should the chain stop finalizing altogether, a separate mechanism gradually erodes the balances of validators that are not participating until the remainder again represents a large enough majority to finalize. Upgrades during 2024 and 2025 changed how large data payloads are distributed and sampled between nodes, without altering this underlying agreement process.
Polygon PoS is an EVM-compatible proof-of-stake network that runs its own validator set and anchors itself to Ethereum by posting periodic checkpoints there. It should not be confused with the other chains that have carried the Polygon name: the zero-knowledge rollup operated under that brand was shut down in 2026, and chains built with Polygon's development kit are independent networks with their own validators. Polygon PoS executes transactions and holds its own transaction data, so it is a sidechain or commit-chain rather than a rollup inheriting Ethereum's execution and data-availability guarantees.
The architecture splits into two node layers that every validator runs together. The execution layer, derived from Go Ethereum, assembles transactions into blocks. The consensus layer coordinates the validator set, tracks staking and finalizes checkpoints; it was rebuilt in 2025 on the Cosmos SDK and CometBFT, which brought checkpoint-based finality down from a wait of one to two minutes to a matter of seconds and capped how deeply the chain may reorganize. At intervals the consensus layer gathers the blocks produced since the last checkpoint into a Merkle tree and submits the root to contracts on Ethereum, where it becomes the reference point for bridge withdrawals.
Staking itself lives on Ethereum. Validators bond the network's native asset, POL, which replaced MATIC in the migration that began in 2024 and now serves as both the staking asset and the gas asset, into contracts on Ethereum mainnet; holders delegate through share-based pools in the same contracts. The active set is capped, so entry requires displacing an incumbent by stake.
Block production changed materially with the Rio upgrade in late 2025. Rather than rotating producers by stake-weighted draw over short intervals, validators now vote, with voting power weighted by stake, to elect the producer or producers for a span. Because a single elected producer builds the span, competing chain tips largely disappear and reorganizations are eliminated. The same upgrade introduced witness-based verification, letting a validator check a block against a supplied witness instead of holding full state, which lowers the storage burden of participating.
Incentive Mechanisms and Applicable Fees
The Sandbox is present on the following networks: Base, Ethereum, Polygon.
Base has no native protocol asset, no staking and no issuance. Nothing is minted to reward participation and there is no validator or delegation system on the Layer 2. Fees are denominated and paid in ether, the same asset used on the settlement layer.
What a user pays has two parts, and they behave quite differently. The first is the cost of executing the transaction on the Layer 2, metered in gas exactly as on Ethereum and priced by an equivalent algorithmic base fee that moves with how full recent Layer 2 blocks have been, plus an optional tip. Because Layer 2 block space is plentiful, this component is usually very small and fairly stable. The second is a charge for the cost of publishing that transaction's data to Ethereum. It is assessed per transaction from the compressed byte size of the transaction and the prevailing price of settlement-layer data space, and it is collected when the transaction is processed even though the actual posting happens later, in a batch shared with many others. This second component typically dominates the total and is why Layer 2 costs track conditions on Ethereum.
Since Ethereum opened a dedicated market for rollup data in 2024, the network posts its batches into that market rather than as ordinary transaction data. Those data fees are priced independently of execution and are destroyed rather than paid to anyone, which cut this component sharply. A December 2025 change on the settlement layer raised the available data capacity while introducing a floor that ties the minimum data price to ordinary execution costs, so the charge no longer falls to almost nothing whenever demand for data space is light.
Fees collected on the Layer 2 accrue to the entity operating the sequencer, funding the cost of running it and of settling to Ethereum, with a portion shared with the collective that stewards the shared codebase. The other economic mechanism at work is the dispute system: participants who propose or challenge a state commitment post bonds that are forfeited if they are shown to be wrong, which funds honest challenges and makes dishonest claims costly.
Payment inside the protocol flows to validators, the only participants the consensus layer compensates directly. A validator earns newly issued units of the network's native asset for voting promptly and correctly on the head of the chain and on the checkpoints being justified, for serving its turn in the committee that signs headers for light clients, and, when selected to propose, for the block itself. The proposer additionally keeps the priority portion of the fees in that block, together with whatever it receives from the separate market through which many proposers outsource block assembly. There is no delegation inside the consensus rules: stake is either operated directly or entrusted to an operator through arrangements that sit outside the protocol.
Users pay for execution in gas, metered per operation, with writes to persistent state priced far above arithmetic. Every transaction carries a base fee per unit of gas that the protocol sets algorithmically from how full recent blocks have been, and that amount is destroyed rather than paid to anyone, so sustained demand withdraws native asset from circulation. On top of it a user adds a voluntary tip, which goes to the proposer and governs how quickly the transaction is picked up. Data posted on behalf of Layer 2 networks is priced in a second, independent market whose fee is likewise destroyed; a December 2025 upgrade tied the floor of that market to ordinary execution costs so it cannot collapse to a negligible level, and capped the gas any one transaction may consume.
Penalties mirror the rewards. Failing to vote, or voting late or incorrectly, costs a validator roughly what correct behavior would have earned it. Provable equivocation is treated far more harshly: the offender is scheduled for ejection, forfeits part of its balance immediately, and later incurs an additional correlated penalty computed from how much other stake was penalized nearby in time. Prolonged absence while the chain is failing to finalize drains balances until finality can resume. Stakers may take out accumulated rewards without leaving the set, and since 2025 may also trigger a full exit from the execution layer rather than only from the consensus client.
Validators on Polygon PoS are paid for two distinct jobs: producing and executing blocks on the chain itself, and signing the checkpoints submitted to Ethereum. Rewards are distributed per checkpoint, funded by protocol issuance of the native asset together with an allocation of transaction fees, and they are apportioned by stake and by how reliably each validator signed. Because the staking contracts sit on Ethereum, a validator's operating costs include Ethereum gas for checkpoint submission and for staking transactions, a meaningful expense that chain-local fee models do not capture.
Delegation works through validator-specific share pools. A holder exchanges the native asset for shares in a chosen validator, and as rewards accrue the redemption value of each share rises, so returns appear as appreciation of the share rather than as separate payments. Validators take a commission before the remainder flows to their delegators. Stake withdrawn from a validator remains locked for a defined number of checkpoints before it can be moved out, while switching between validators carries no such delay.
The penalty structure is weighted toward lost income. The staking contracts define consequences for double-signing and for sustained unavailability, but in normal operation the dominant economic pressure on a validator is forfeited reward: missed checkpoint signatures and poor block-production uptime reduce what a validator and its delegators earn. The producer election introduced by the Rio upgrade also redistributes fee income, including value captured from transaction ordering, toward validators that are not currently producing, so that supporting the chain stays worthwhile for the rest of the set.
Users pay fees in the native asset under a base-fee-plus-tip model. The base fee moves with how full recent blocks have been and is routed to a burn path, while the optional tip goes to the producer. A 2026 protocol change made that base-fee destination configurable in order to fund a time-limited program that recycles fees for one narrow category of activity, with ordinary transactions continuing to follow the burn path. There is no storage rent, and contract deployment and execution are charged purely as metered gas on the resources they consume.
Energy consumption sources and methodologies
The Sandbox is present on the following networks: Base, Ethereum, Polygon.
The estimate for this network has two components, and they are constructed differently.
The first is the network's own infrastructure. This is a small and largely identifiable set of machines rather than a large permissionless population: the sequencer that orders and executes transactions, the batching service that compresses and submits data to the settlement layer, the service that publishes state commitments, and the replica and archive nodes that third parties operate to serve applications and to independently check what the sequencer produced. The number of independent replicas is estimated from crawlers of the Layer 2 peer-to-peer network and from public information about node operators and infrastructure providers. Hardware profiles are inferred from the published requirements of the node software, which for a high-throughput rollup are materially heavier than for an ordinary chain, and per-device power draw comes from measurement on representative equipment under controlled laboratory conditions, counting idle draw as well as load. The fault-proof machinery adds little in normal operation, since the interactive dispute game runs only when a commitment is actually challenged rather than continuously.
The second component is the share of the settlement layer's consumption that this network causes. That layer is Ethereum, whose own consumption is estimated from its validator population using the node-level method described for that network. A portion is attributed here in proportion to what this network occupies there, principally the data space its batches consume, alongside the gas used by its commitment and dispute contracts. Because the settlement layer's consumption is driven by a continuously running validator set rather than by throughput, this attributed share is modest next to the Layer 2's own footprint, but it is included so that settlement is not treated as free.
Both components are estimates built on public observation and stated software requirements, not metered readings. The replica population is the least observable part and the largest source of uncertainty. Where evidence is thin, the assumptions used are those more likely to overstate impact than understate it, and figures are revised as observation improves. The settlement layer publishes its own account of its energy profile at Ethereum energy consumption.
The figure reported for this network is assembled machine by machine, treating the computers that run the protocol as the thing that draws electricity. The starting point is an estimate of how many independent nodes are operating, built from crawlers that walk the peer-to-peer layer and record every peer they can reach, supplemented by public listings of infrastructure and staking providers and by the protocol's own visible record of how much stake is active and how it is spread across operators.
A representative hardware profile is then inferred for those machines. The client software publishes what it requires in processor, memory and disk terms, and operators have little reason to provision far beyond that, so the profile is derived from those stated requirements rather than from a survey of individual operators. Power draw for the resulting device classes comes from measurement on representative equipment under controlled laboratory conditions, capturing both the load validating places on a machine and the draw of a machine that is powered on but momentarily idle, which for a network of this kind accounts for a large share of the total. Multiplying measured per-device draw across the estimated population over the reporting period yields the network figure. Where a disclosure concerns one of the many assets issued on this network rather than the network itself, a portion of the network total is assigned to it in proportion to observed on-chain transfer volumes.
The limits deserve stating plainly. The node count records what is reachable, not a census, and machines behind restrictive network configurations are missed. The hardware profile is a reasoned inference from published software requirements, not a record of what any particular operator bought. Nothing here is metered at the wall. Where the evidence runs out, the assumptions chosen are those that push the estimate upward rather than downward, so the result is more likely to overstate consumption than to understate it, and it is revised as observation improves. The network's own account of its energy profile is published at Ethereum energy consumption.
Polygon PoS is a staked network, so its consumption is modeled from the machines that run it rather than from mining economics. Two components are added together. The first is the chain's own infrastructure: every validator operates a paired execution and consensus process, which in practice means a heavier machine than a single-process chain of comparable throughput would need, plus the wider population of full and archive nodes serving applications and data consumers. The second is a share of Ethereum's consumption, because the checkpoint and staking transactions that give Polygon PoS its anchor are executed by Ethereum's validators; that share is apportioned by the gas those transactions consume as a fraction of total Ethereum gas.
For the chain's own component, the node count is estimated from peer-discovery crawls, public node listings and the validator set recorded on chain, with the understanding that crawls see only nodes willing to accept connections. A representative hardware profile is inferred from the published requirements for running both node processes, and the electrical draw of such a configuration is taken from measurement of comparable machines, at load and at idle, since a validator's hardware draws power continuously regardless of whether it is currently producing. Aggregating across the estimated population, with an allowance for the overhead of the facilities housing it, gives the chain-local total.
The usual qualifications apply and matter here. The node population and the hardware behind it are inferred from public observation and stated software requirements, not metered. Where evidence is incomplete, the assumptions used err toward a higher figure rather than a lower one. The estimate is revised as observation improves. The gas-based apportionment of Ethereum's consumption is a convention rather than a physical measurement, since Ethereum's validators would run whether or not the checkpoints were posted. And where a share of the network total is attributed to an individual asset issued on the chain, that attribution is made from observed on-chain transfer volumes, which reflects how heavily an asset is used rather than the energy it uniquely causes.
Key energy sources and methodologies
The Sandbox is present on the following networks: Base, Ethereum, Polygon.
The renewable share reported for this network is a weighted average of the electricity mixes of the grids its infrastructure draws on, assembled in two steps: establish where the machines are, then attach regional generation statistics to those places.
Locating them is easier for some parts of the network than others. The sequencing, batching and commitment services run in identifiable data center regions, and the hosting regions an operator uses are publicly observable. The wider population of replica and archive nodes is inferred as it would be for any peer-to-peer network, from the addresses peers advertise so that others can reach them, collected by crawlers and supplemented by public directories of infrastructure providers. Resolving a single address to a country is unreliable, but in aggregate these resolutions describe a distribution well enough to weight against. Where the observable sample is too thin, the geographic spread of a structurally comparable network is used in its place, chosen because its operators face similar hosting economics rather than because it runs similar software. The same exercise is carried out for the settlement layer, because part of the figure reported here is an attributed share of Ethereum's consumption, and Ethereum's validator population is spread quite differently from a rollup's concentrated operator infrastructure. The two distributions are weighted by their respective contributions to consumption and combined.
Each location is then matched to published statistics on how electricity is generated in that country or region, and the renewable proportion is the consumption-weighted share falling in regions supplied by renewable generation. Grid averages are used throughout, because the actual supply arrangements of individual hosting facilities are not observable; a facility on a dedicated renewable supply and one drawing ordinary grid power in the same country are treated alike.
Energy intensity is a marginal figure rather than an average: the additional electricity attributable to one further transaction on the network as it currently runs. Because most of the infrastructure runs continuously whether or not it is busy, that marginal quantity is much smaller than dividing total consumption by the transaction count would suggest. The generation statistics come from Share of electricity generated by renewables, compiled by Our World in Data from Ember's electricity datasets and the Energy Institute's Statistical Review of World Energy.
The renewable share reported here is a weighted average of grid mixes rather than a record of what any operator actually buys. It is produced in two steps: establish where the infrastructure sits, then attach regional electricity statistics to those places.
Location is inferred from what the network exposes publicly. Nodes advertise network addresses in order to be reachable by peers, and those addresses resolve to a country accurately enough to describe an aggregate distribution, even though any single resolution may be wrong. Crawlers of the peer-to-peer layer and public directories of hosting and staking infrastructure supply the input. Where the observable sample is too thin or too skewed to stand for the whole population, the geographic spread of a structurally similar network is substituted, chosen because its participants face comparable hardware costs and comparable pressures over where to site machines, on the reasoning that operators respond to the same commercial forces even where the software differs.
Each location is then matched to published statistics on how electricity in that country or region is generated. The renewable proportion for the network is the consumption-weighted share falling in regions where generation is renewable. Grid averages are used because the alternative, knowing each operator's actual supply contract, is not observable; an operator on a dedicated renewable supply and one drawing ordinary grid power in the same country are treated alike.
Energy intensity is reported on a different basis from total consumption. It is a marginal quantity: the additional electricity attributable to processing one further transaction on the network as it currently runs. For a network whose consumption is driven by a validator set that operates continuously regardless of how busy the chain is, that marginal figure is small, and it is not the total divided by the transaction count. The generation statistics are drawn from Share of electricity generated by renewables, compiled by Our World in Data from Ember's electricity datasets and the Energy Institute's Statistical Review of World Energy.
The renewable share attributed to Polygon PoS depends on where its infrastructure physically sits, so the method begins with geolocation. Nodes visible through peer discovery and public network observation are resolved to hosting providers, autonomous systems and countries, giving an approximate map of where validator and full-node capacity is concentrated. Coverage is never complete; where it is too thin to be relied on, the geographic distribution of a network with a similar staking design and operator economics is used as a proxy. The same exercise applies to the portion of Ethereum's footprint brought in through checkpointing, using Ethereum's own observed node distribution.
Those locations are then matched to national electricity statistics. Each country's share of generation from renewable sources comes from Share of electricity generated by renewables, compiled and processed by Our World in Data from Ember's yearly electricity datasets and the Energy Institute's Statistical Review of World Energy. Weighting the country-level shares by the estimated node capacity in each produces a single renewable figure for the network.
Energy intensity is reported as a marginal quantity: the extra electricity associated with processing one more transaction, not the annual total divided by the number of transactions. On a chain whose validators run continuously and produce blocks on a schedule, that marginal figure is much smaller than a simple average would suggest, and the two are not interchangeable.
The limitations are inherent to the approach. An observed hosting location identifies a grid, not a power purchase agreement, so an operator sourcing renewable electricity on a carbon-heavy grid is invisible to the method. Cloud hosting and proxying can misplace a node relative to the hardware actually running it. Annual national averages cannot capture the hourly and seasonal swings in generation mix that continuously running machines draw from. And the borrowed share of Ethereum's footprint carries whatever geographic error is present in Ethereum's own distribution.
Key GHG sources and methodologies
The Sandbox is present on the following networks: Base, Ethereum, Polygon.
Emissions are not measured directly. They are derived by attaching a carbon intensity to each unit of electricity the network is estimated to consume, across both parts of its footprint: the machines the network operates itself, and the share of the settlement layer's consumption attributed to the data and commitments it posts there.
The geographic step repeats the one used for the renewable share. The hosting regions of the sequencing and batching infrastructure are publicly observable; the wider set of replica and archive nodes is located from the addresses peers advertise, collected by crawlers and public directories. Where observation is too sparse to characterize the population, the spread of a structurally comparable network is used in its place. The settlement layer's validator population is located separately, because it is distributed quite differently, and the two are weighted by how much consumption each accounts for. Each region is then assigned a carbon intensity, the average greenhouse gas released per unit of electricity generated on that grid, expressed in carbon dioxide equivalent so that methane and the other gases are counted on a common basis. Estimated consumption in a region multiplied by that region's intensity, summed across regions, gives the total.
Two scopes are distinguished. Scope 1 covers emissions from sources the operators of the infrastructure control directly, such as fuel burned on site in a generator. For infrastructure that consists of ordinary servers in commercial data centers drawing from public grids, there is generally nothing in that category, and it is reported as such rather than left out. Scope 2 covers the indirect emissions embodied in the purchased electricity, and is where essentially the whole footprint sits. Emissions from manufacturing and transporting the hardware fall outside this boundary.
Greenhouse gas intensity follows the marginal logic used for energy intensity: the additional emissions attributable to one further transaction, not an average spread across all of them. It inherits the uncertainty of both the consumption estimate and the grid averages. Carbon intensities are taken from Carbon intensity of electricity generation, compiled by Our World in Data from Ember's electricity datasets and the Energy Institute's Statistical Review of World Energy, and made available under the CC BY 4.0 license.
Emissions are derived from the consumption estimate rather than measured, by attaching a carbon intensity to each unit of electricity the network is estimated to draw and summing across the network.
The geographic step repeats the one used for the renewable share. Node locations are inferred from publicly observable network data, principally the addresses peers advertise so that others can connect to them, gathered by crawlers and supplemented by public information about where staking and hosting infrastructure is operated. Where that observation is too sparse to characterize the whole population, the distribution of a comparable network stands in for it, selected because its participants face similar operating economics rather than because its software resembles this one. Each region is assigned a carbon intensity, meaning the average greenhouse gas released per unit of electricity generated on that grid, expressed in carbon dioxide equivalent so that methane and the other gases are counted on a common basis. Estimated consumption in a region multiplied by that region's intensity, summed across regions, gives the network total.
The reporting separates two scopes. Scope 1 covers emissions from sources the operators of the infrastructure control directly, such as fuel burned on site in a generator. For a network of this kind, whose participants overwhelmingly run ordinary servers connected to a public grid, there is generally nothing in that category, and it is reported as such rather than left out. Scope 2 covers the indirect emissions embodied in the electricity purchased to run that infrastructure, and that is where essentially the whole footprint sits. Emissions further up the supply chain, such as those from manufacturing and shipping the hardware, fall outside this boundary.
Greenhouse gas intensity follows the same marginal logic as energy intensity: it expresses the additional emissions attributable to one further transaction rather than an average spread across all of them. Because it inherits both the consumption estimate and the grid averages, its uncertainty combines theirs. Carbon intensities are taken from Carbon intensity of electricity generation, compiled by Our World in Data from Ember's electricity datasets and the Energy Institute's Statistical Review of World Energy, and made available under the CC BY 4.0 license.
Emissions attributed to Polygon PoS rest on the same geographic work as the renewable share, with regional carbon factors applied in place of renewable percentages. Validator and full-node locations are approximated from peer discovery, public network observation and hosting attribution, and a comparable network's distribution stands in wherever direct observation is too sparse. The share of Ethereum's footprint brought in through checkpointing is located the same way, against Ethereum's own node distribution. Each location is paired with the carbon intensity of its national grid, taken from Carbon intensity of electricity generation, processed by Our World in Data from Ember's yearly electricity data and the Energy Institute's Statistical Review of World Energy, and made available under a CC BY 4.0 license. Multiplying regional electricity by regional grams of carbon dioxide equivalent per kilowatt-hour, then summing, yields the annual total.
Scope matters to how the result should be read. Scope 1 captures emissions from sources under the direct control of the network's operators, such as fuel burned on site, which for servers in rented facility space is generally negligible and reported as such. Scope 2 captures the indirect emissions embodied in purchased electricity, and that is where essentially the entire footprint falls. Manufacture and disposal of the hardware sit outside the boundary of this accounting.
Greenhouse-gas intensity is defined marginally, as the incremental emissions associated with one additional transaction rather than the annual total spread across throughput.
The error bars on the emissions figure inherit those on the electricity estimate and add to them. Grid carbon intensity differs by more than an order of magnitude between countries, so a misallocated share of node capacity shifts the result considerably, and annual national averages hide the hourly swings in intensity that machines running around the clock experience in full.