Web3 Daily Exploits — 29 Aug 2026: Rain card stack drained; Ajna v2 hit for $775K
Rain’s legacy Solana card contract was abused across Avici and Tria prepaid balances, while Ajna v2 lost about $775K to liquidation accounting manipulation on Ethereum.

A legacy Rain Solana card contract was abused to pull prepaid balances from Avici and Tria users; disclosed losses exceed $930K and on-chain exits topped $1M before Tornado Cash. Hours later Ajna v2 told lenders to withdraw after a ~$775K Ethereum liquidation-accounting drain that Defimon says it flagged more than an hour early.
The last 24 hours were not quiet. Two confirmed, independently sourced incidents dominate: a shared-issuer card-balance drain on Solana that hit more than one neobank brand, and an oracleless lending exploit on Ethereum that emptied several Ajna pools. A separate GoPlus write-up also attributes an $8.2M Solana meme-token dump to a seized brand and insider-seeded wallets. Required alert accounts were checked; PeckShieldAlert, BlockSecTeam, Phalcon_xyz, Lookonchain, ZachXBT, CyversAlerts and rekt.news had no material new incident posts in-window.
1. Rain Solana card contract — Avici and Tria prepaid balances drained
Severity: High (confirmed). Chain: Solana, with Ethereum exit. Type: Authorization / signature-binding flaw in a legacy card-balance program. Status: Vulnerable programs upgraded; Rain, Avici and Tria say unauthorized activity has stopped and affected card balances will be refunded in full. Avici filed a report with the FBI IC3.
What happened
On 28 August 2026 an attacker funded a fresh Solana wallet with about 1.79 SOL (~$190) via deBridge, then spent several hours calling a Rain card-balance program used by Avici and at least Tria. Users’ self-custodial wallets were not the target. When a user tops up a card, funds leave that wallet and sit in a separate Solana contract that holds the spendable card balance. That contract — an outdated Rain program, per Rain and Avici — is what was drained.
Avici’s reconciliation, posted at 20:44 UTC on 28 August, put the Avici slice at $500,859.22 across 1,685 users. Tria, in a 29 August update, put its slice at $431,945 across 636 users. Combined disclosed partner losses are about $933K. That is not the full on-chain picture. CertiK tracked the same attacker swapping about 10,000 SOL for ~$1.02M USDC, bridging to Ethereum and converting to ~418 ETH. Independent tracing by SolScanner put bridged proceeds nearer 456 ETH, with ~455.9 ETH later deposited to Tornado Cash. Treat Avici/Tria figures as official partner disclosures and the ~$1.0–1.1M ETH exit as the likely aggregate across every program that still ran the old contract.
Technical outline (no reproduction steps)
GoPlus and on-chain reporters describe a repeating three-instruction loop against user collateral accounts: a crafted signature bundle submitted alongside Solana’s Ed25519 verify precompile, an instruction that registered the attacker as a collateral admin, then a withdrawal of the card asset. GoPlus attributes the root cause to the program mis-binding the Ed25519 verify result, so the attacker’s own signature could pass as a legitimate admin authorization. Rain framed it as a vulnerability in an outdated version of its Solana contracts used by a small number of programs; other Rain programs, it said, were not impacted. This is not an L1 bug and, per current public analysis, not a stolen upgrade key.
First malicious calls against the card stack are placed at about 16:49 UTC on 28 August. Avici acknowledged a card-withdrawal issue at 18:42 UTC. Tria reported unauthorized Solana USDC/USDT card-balance withdrawals at 20:20 UTC. Rain published its incident note at 20:26 UTC and said every program on the outdated version had been upgraded.
Key addresses and transactions
- Solana attacker: FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj
- SOL staging wallet cited by CertiK: MsaXH6cGDahPQDwJjFYod7RW8QLVDZGByywWvwQ9TFu
- Hit program cited by GoPlus: 26DkA98jjctzPkBEteUsN935CR4dsKx3XvjrtE7MeL4a
- Drainer program cited by SolScanner: CWgkFB7ngUc9cGD1LryyhP7h6xYWtwrAjhSKKCoR1gkz
- Ethereum landing / swap wallet: 0x2cE21E4921d3Eb116526c3651Dac0257657338D5
- Ethereum gas wallet cited by SolScanner: 0xa1a15f1b0d4878873f2933573e4385ab1e4df25c
Rain, Avici and Tria all state that self-custodial wallets were untouched and that refunds of affected card balances are in process. Timetable for those refunds has not been published. Other Rain-powered brands circulated on social lists; only Avici and Tria have issued confirmed user-loss figures in this window. Treat additional brand names as unverified unless the issuer posts.
2. Ajna v2 — ~$775K liquidation accounting manipulation (Ethereum)
Severity: High (confirmed by the protocol; loss estimate from Defimon). Chain: Ethereum. Type: Liquidation / auction accounting manipulation on an oracleless peer-to-pool lender. Status: Team investigating. Official guidance: withdraw, repay loans, do not interact.
What happened
At 04:58 UTC on 29 August, @ajnafi wrote that Ajna v2 was aware of an exploit and unusual movements, and told users to withdraw all funds, repay loans, and stop interacting with the protocol. Defimon Alerts later put realized pool losses at about $775K, split across syrupUSDC (~$173.7K), wstETH (~$159.8K), rETH (~$127.4K + $15.6K), cbETH (~$124.8K + $12.1K), WBTC (~$101.8K), WETH/USDC (~$42.0K) and sDAI (~$18.0K).
Defimon says its monitors saw a prepared attack more than an hour before the first exploit transaction and notified the team in Discord, and that the team did not stop the drain in time. That early-warning claim is Defimon’s; Ajna has not publicly addressed the Discord alert in-window.
Technical outline
Ajna is an oracleless, governance-minimized lender. Prices and liquidation eligibility are derived from pool accounting (bucket deposits, LUP, auctions), not from an external feed. Independent analysis circulating this morning — notably from @ShiroCipher, correlating with Defimon’s cbETH line — describes a harvest against a sitting auction rather than a same-transaction mint bug. In a sample cbETH-pool transaction at block 25854888 (28 August ~16:19 UTC), a Balancer flash loan of 4 WETH funded a bucketTake / removeCollateral / take / settle sequence. Phalcon-style balance changes on that tx show the pool losing ~48.13 cbETH against ~3.47 WETH in, with the attack contract keeping most of the collateral. The analyst flags the target as a July 2023 v1-clone pool rather than the January 2024 factory. Root description in public threads: auction settlement can hand leftover collateral to the party that finishes the auction while quote repaid is zero, and LUP can sit at a minimum price on an oracleless book. Treat the precise selector-level theory as likely until Ajna or a named firm publishes a post-mortem. Do not interact with remaining pools while that review is open.
Key addresses and transactions
- Sample harvest tx (cbETH line): 0x12dfde527ef62882bfabb64362c9ae0e6bfb628363bd298d0d0956c9a114e4f5
- EOA on that tx: 0x6f2f5236b10fe7162da077a2779f8b5f04b7827e
- Attack contract on that tx: 0x80ad419c4783a09252ad6a576ce059f51cc53d47
Defimon listed additional attacker addresses in its alert thread; those should be taken from the primary post rather than reconstructed. No official recovery address and no confirmation that funds have been frozen. Users with open Ajna v2 lend or borrow positions should use the frontend they already trust, repay and withdraw, and ignore fresh “support” links.
3. $GOLD / $PLATINUM — seized brand, insider-seeded dump (Solana)
Severity: High for holders of those specific tokens; not a protocol hack. Chain: Solana. Type: Account/domain seizure plus coordinated launch, pump and dump; second token alleged to allow arbitrary balance sweeps. Status: GoPlus alert timed 29 August ~10:51 UTC. Profit figure is GoPlus’s on-chain attribution (~$8.2M+), not an independent audit.
GoPlus says a fraud ring seized realtrumpcoins[.]com and the @realtrumpcoins1 account, then launched $GOLD, pumped reported market cap toward $60M, and dumped. Dev seed is traced by GoPlus to a KuCoin-linked hot wallet; 15 operator wallets were seeded from a Binance-linked hot wallet and routed through a shared contract labeled FLASHX…. The same crew, GoPlus says, deployed $PLATINUM with a contract that can sweep a holder’s full balance. Do not buy either token. This is a brand-and-liquidity rug, not a blue-chip protocol exploit, but the dollar figure is the largest single number in today’s window if GoPlus’s profit estimate holds.
- $GOLD mint: EMWtbpHaNqMbjUMZguuazhuZUVLWG3z4C5oZnGJPSqxS
- Dev wallet: 3pQA1ZCaAuFgVJPmkxUGhBaDQjRpt88CXaXmoVy3fRsr
- Operator wallet: 3odTMNgv5ViWXYoiZCwXuMbk8FTdJkpwvEHJfosuATos
- Dev funder (KuCoin-linked, per GoPlus): BmFdpraQhkiDQE6SnfG5omcA1VwzqfXrwtNYBwWTymy6
- Funder of 15 insider wallets (Binance-linked, per GoPlus): 5tzFkiKscXHK5ZXCGbXZxdw7gTjjD1mBwuoFbhUvuAi9
- Routing contract: FLASHX8DrLbgeR8FcfNV1F5krxYcYMUdBkrP1EPBtxB9
- $PLATINUM mint: AuzcYsvKsYs1DFkQVzpm6tLzWb2fFSfZGxLHyubWY4jM
Also noted
- StealC via fake Qwen weights (confirmed campaign, not a protocol hack). SlowMist on 28 August documented a GitHub repo impersonating local Qwen 3.8 27B quantized weights. A real Q4_K_M 27B package is >16 GB; the delivered ZIP was 487 KB and held a batch file, a renamed LuaJIT interpreter and an obfuscated Lua script. Official Qwen was not compromised. SlowMist attributes the inner payload to StealC (browsers, wallets, extensions) and found 29 similar ZIPs across 23 repos. Fallback C2 is read from a Polygon contract via
eth_call, so operators can rotate infrastructure on-chain. Primary: SlowMist thread and SlowMist Medium write-up. - CashCowCoin (CCC) on BNB Chain (~$117K). Defimon and SlowMist published technical notes early on 28 August for an 27 August oracle/reserve-manipulation drain of the CCC/WBNB pair. First reporting sits at or just outside this briefing’s 24-hour cut. Not re-litigated here; no material new loss figure in-window.
- Unverified “Fogo Foundation / 400M fogo:native” claims. Aggregator posts this morning alleged a ~$3M token theft and an 18% price drop. No corroboration from required security accounts or an official Fogo incident post was found in-window. Leave it unconfirmed.
Sources & references
Official / issuer
- Ajna v2 withdraw notice — https://x.com/ajnafi/status/2093563829116383734
- Avici initial notice — https://x.com/avici/status/2093408878663000074
- Avici refund and $500,859.22 / 1,685-user reconciliation — https://x.com/avici/status/2093439613201482068
- Rain incident statement — https://x.com/raincards/status/2093435073081053518
- Tria unauthorized-withdrawal notice — https://x.com/useTria/status/2093433665258963450
- Tria $431,945 / 636-user update — https://x.com/useTria/status/2093651836079116392
Security firms and on-chain desks
- Defimon Alerts, Ajna ~$775K — https://x.com/DefimonAlerts/status/2093632180656263283
- CertiK Alert, Avici ~$1.02M / 418 ETH / Tornado — https://x.com/CertiKAlert/status/2093428949334266091
- GoPlus, Avici/Rain breakdown — https://x.com/GoPlusSecurity/status/2093606636694667717
- GoPlus, $GOLD / $PLATINUM — https://x.com/GoPlusSecurity/status/2093652785095233933
- SlowMist, StealC / fake Qwen repo — https://x.com/SlowMist_Team/status/2093294554623754278
- ShiroCipher, Ajna cbETH harvest tx — https://x.com/ShiroCipher/status/2093648134744199353
- SolScanner anatomy (Avici/Rain exit path) — https://www.solscanner.app/blog/inside-the-avici-exploit
- The Defiant (Avici / Rain) — https://thedefiant.io/news/hacks/attacker-drains-more-than-usd1-million-from-avici-users-in-live-solana-neobank-attack
Checked in-window with no material new incident post
@Phalcon_xyz, @PeckShieldAlert, @BlockSecTeam, @Lookonchain, @zachxbt, @CyversAlerts, Immunefi (industry commentary only), rekt.news.
Editor’s note
Two different custody stories ran in parallel. Ajna is immutable, oracleless pool math: once a sitting auction can be closed on favorable accounting, there is no admin pause to debate. Rain is upgradeable issuer infrastructure sitting under several consumer brands: the wallets were fine, the prepaid card vault was not, and the blast radius was defined by who still ran the old program. Neither incident is an excuse to click a freshly DMed “recovery” portal. If you held an Ajna v2 position, use the frontend you already used. If you held a Rain-powered card balance, wait for the issuer refund path you already have in-app — do not sign a new allowance because a stranger posted an airdrop.
This briefing covers incidents first reported, confirmed or materially updated in the roughly 24 hours to 29 August 2026, 06:30 American Eastern. Loss figures are labeled by source.
Read more

Web3 Daily Exploits — 07 Sep 2026: Liquid $320M Whitehat Peg-Out + Cozy $170K
Liquid Network sees ~4,000 BTC (~$320M) unauthorized peg-out claimed as whitehat; Cozy Finance loses ~$170k on Optimism via UMA oracle abuse; Secured Finance ~$104k price-manipulation drain on Ethereum; Rocket $287k update.

Web3 Daily Exploits — 06 Sep 2026: Reddio ~9.25 ETH Vault Double-Count + Autonolas Gov Attempt
A quiet window produced one confirmed low-value vault exploit and one blocked governance attempt. Reddio’s RedSonic Vault lost approximately 9.25 ETH to a cross-vault double-counting flaw; a malicious Autonolas proposal targeting ~40 ETH remains unexecuted.

Web3 Daily Exploits — 05 Sep 2026: Notional $1.7M Overflow + Dream Health $72k Logic Drain
Notional Finance lost ~$1.73M on Ethereum via an unsafe uint128 downcast in free-collateral checks. A separate ~$72k logic flaw drained Dream Health Chain awards on BSC.

Web3 Daily Exploits — 04 Sep 2026: Notional $1.7M integer overflow drain
Notional Finance lost ~$1.7M on Ethereum via an unsafe uint128 downcast in free-collateral checks. Attacker minted extreme fCash pairs and drained escrow before mixing via Tornado Cash.

