Invest1 distinct publisher3 min readPublished
The same failure mode showed up twice in two days: Rain's Solana card contract, then Ajna's liquidation accounting. Avici's fix costs about $297 a user, and that number is now the floor its competitors get measured against.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
The attacker's route through Avici reportedly ran SubmitSignatures on the authorization program, then AddCollateralAdmin on the collateral program, then WithdrawCollateralAsset [6], a sequence that asks a program to believe its own collateral ledger rather than to defeat a signature, and DefiLlama filed it as a withdrawal logic flaw in a Rust-based protocol rather than as anything more glamorous [4]. A day later, Defimon described Ajna's loss as liquidation accounting manipulation [9]. The chain was different and the dollar amount was different, but the trust that failed was the same kind in both cases.
Which is why the CoinGecko security figures are the load-bearing arithmetic here, or rather the ratio inside them: 147 of the 245-plus incidents logged between January 2025 and July 2026 hit audited protocols, and those 147 carried 88.44% of the $3.63 billion stolen [13][14], about $3.21 billion [9] from 60% of the events [8], with the report noting that most attacks went at infrastructure, third parties, governance or human error rather than at code inside the audit's scope [14]. The pool meant to absorb that has thinned: active on-chain cover fell from $163.2 million to $130.2 million, a decline of 20.2% [15][6], with five of nine on-chain insurers inactive or pivoted by August 2026 [15]. Against $3.63 billion of losses, $130.2 million is 3.6% [7].
So the refund is a balance-sheet decision, not an insurance recovery. Divide $500,859.22 by 1,685 affected users and the promise costs about $297.25 each [1], which is cheap enough that the interesting question is what it prices for everyone else, because a firm that loses a hundred times as much cannot buy the same sentence. The attacker's wallet, holding roughly 10,005 SOL worth about $1.07 million plus $11,600 in stablecoins [7], comes to about 2.16 times the logged loss [2], consistent either with earlier balances in that wallet or with the initial estimates of $600,000 to more than $1 million that Avici has not confirmed [5].
Ajna is the more brutal comparison. Its roughly $775,000 loss is 3.14 times the $246,880 still locked in the protocol [9][12][4], total value locked was already down 71.3% over the prior 30 days [12], and Defimon says it flagged a prepared attack more than an hour before the first exploit transaction and warned the team in Discord without response [10]. The depositors best served were the ones who left before any of that.
This is probably wrong, but I read Avici's pledge as the cheapest reputational asset on the market at these dollar amounts, and the token tape supports the cheapness: AVICI still sits more than 96% below its November 2025 peak of $7.61 [8], so the equity holders paid for the incident and the cardholders are being made whole out of what is left. How this reads later depends on what happens next. If the 1,685 refunds settle on-chain at the stated figure, the floor is real and the next issuer answers for it. If they settle quietly, partially, or only at the lower of the competing loss estimates [5], the pledge was a press cycle. And if another program running Rain's flawed contract version turns up with its own hole [3], the $500,859 stops being the incident and starts being the first invoice.
Ranked by verification strength, evidence, and original report placement.
Avici said its card-issuing partner Rain traced the problem to a flawed version of a Solana card contract.
Avici wrote that the flawed contract was used by the neobank and "a small number of other programs" before being upgraded across the board.
Avici, a Solana-based neobank, said in an August 28 post on X that all affected card balances will be refunded in full, covering 1,685 users and $500,859.22 in card balances drained in an August 28 breach.
The attacking wallet ended up holding about 10,005 SOL, worth around $1.07 million at the time, along with around $11,600 in stablecoins.
AVICI fell about 39% in 24 hours, touching a new all-time low near $0.2189, and was trading around $0.3093 at the time of writing, still down more than 96% from its November 2025 peak of $7.61.
On August 29, on-chain monitoring firm Defimon Alerts reported that Ethereum lending protocol Ajna lost about $775,000 to liquidation accounting manipulation, with the syrupUSDC pool alone accounting for $173,700.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 29, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
invest
Avici's token shed 2.7 times what the hackers took from its depositors1 distinct publisher
invest
A Solana DEX halted trading and says the loss stopped at its treasury. Nobody can check1 distinct publisher
invest
Tokenized funds reach $611.5M, and distribution is now the only scarce input1 distinct publisher
invest
The card networks just picked the referee for agent checkout, and it looks like EMVCo2 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One outlet, four interested sources
Cryptopolitan is the whole record here, and it is passing along other people's numbers: Avici's X post for the refund, DefiLlama for the loss and Ajna's deposits, Defimon Alerts for the Ethereum exploit, a CoinGecko report for the annual totals. The specifics that can be checked on-chain — balances, TVL, the contract upgrade — are firm. The specifics that matter most to the story's framing are not: the $500,859 anchoring the per-user refund math is contradicted inside the same piece, and the three-call exploit path arrives with a "reportedly" and no author.
Damage measurable, remedy not yet
Everything verifiable points down. Ajna's deposits are at $246,880 after a 71.3% month, AVICI made a new all-time low, five of nine on-chain insurers have stopped writing coverage. Set against that, the one constructive act in the story — full refunds to 1,685 people — exists as a promise posted hours after the breach, with no timetable, no funding source, and not a single restored balance shown. The contract upgrade Rain is credited with is likewise asserted rather than demonstrated, and the other programs that ran the same code are still unnamed.
Tidier than the numbers allow
Two things get smoothed over. First, the pairing: a missing authority check in a shared card contract and manipulated liquidation accounting in a lending pool are not one failure mode, however neatly they fall two days apart. Second, the money: $500,859 is treated as settled while the attacker's wallet holds roughly 2.16 times that, and the piece's own FAQ admits nobody official has confirmed a figure. The insurance line even mangles its own arithmetic, calling a 20.2% decline a 20.2% market share. The restraint in the writing is real — no rescue narrative, no victim-blaming — but the confidence in the headline numbers outruns what is behind them.
Each number supplied by whoever it flatters
Avici sets both halves of its own scorecard: the promise to make users whole and the loss figure that promise is measured against. Rain, whose contract broke, appears only through the client it broke for, and never in its own voice. Defimon's version of Ajna establishes that Defimon's alerts fired an hour early and were ignored — the best possible advertisement for a monitoring service. CoinGecko's audit-failure statistics come from a report published to be cited, as it duly is. The outlet's own hand shows too: the wider loss range is sourced to Cryptopolitan itself, and the piece breaks for a newsletter pitch.
Solid outline, soft interior
That both exploits happened, and roughly what they cost, is safe to rely on — on-chain data and public statements agree on the shape. Beyond that, hold loosely. One outlet, no independent verification, a loss figure the outlet itself will not settle, an exploit path with no named source, and a refund whose execution is entirely prospective. A second newsroom, or Rain speaking for itself, would move this materially in either direction.