RugHunters is a community-powered investigation network where anyone can report a rug, open a case, submit evidence, trace wallets and help connect the people behind them.
Hunters can take on bounties, uncover missing pieces of a case and earn rewards funded through RugHunters trading fees.
Every investigation strengthens the archive.
Every connection makes the next rug harder to hide.
The First Hunt begins.
Find. Trace. Hunt. Expose.
Report on the @raincards smart contract vulnerability.
FVNF…nCEj submitted a crafted signature bundle, called AddCollateralAdmin to add itself, then immediately calling WithdrawCollateralAsset.
The apparent bug is in Ed25519 signature validation. The second “approval” claimed to come from real admin 9J97**, but its index fields pointed to instruction 0. Solana therefore verified the first signature again, while AVICI credited the embedded admin key.
That fake approval authorized the attacker’s AddCollateralAdmin call. Once added, subsequent withdrawals passed as legitimate admin actions. At my last RPC snapshot, the attacker’s key appeared as the second admin on 1,144 AVICI collateral accounts.
https://t.co/JJtpufLHLc
Hacker washing funds:
https://t.co/oUAXEyo6AU
All losses will be refunded:
https://t.co/lLdKAigWIp
In then end, we are reminded why security is needed and so important.
At least this was handled quickly and everyone will be refunded.
UPDATE: All affected card balances will be refunded in full
Earlier today, our card-issuing partner, Rain, identified a vulnerability in an version of a Solana card contract used by Avici and a small number of other programs. The contract has now been upgraded across all programs, and no further unauthorised activity has been observed.
Avici wallets and card balances are separate. Avici wallets are self-custodial and remain under users’ control.
When users top up their cards, funds move into a separate Solana contract that holds their card balance. Only this contract was affected.
Note: Funds held in Avici’s Solana and EVM wallets are safe and were not affected.
Our current reconciliation shows that 1,685 users were affected, representing $500,859.22 in card balances.
Every affected user will have their card balance refunded in full. We remain in close contact with our card-issuing and security partners and are monitoring the remediation closely.
Avici has also filed a report with the FBI’s Internet Crime Complaint Center. We are deeply sorry for the concern and inconvenience this has caused.
AVICI is being actively drained (cc @avici). On-chain, FVNF…nCEj submitted a crafted signature bundle, called AddCollateralAdmin to add itself, then immediately began calling WithdrawCollateralAsset.
Next to @avici, @useTria is also exploited.
Problem at @raincards it seems.
Secure your funds.
Join the hunt:
Avici:
https://t.co/YYcENZuITk
UseTria:
https://t.co/I9zbFI4eUb
No news regarding @avici ? Interesting.
What’s going on? Seems they got hacked or something.
Users accounts getting drained. Token dumping.
Check on your peeps.
Upon investigating the drain / hack @avici.. We came across another one that might have been hacked
Is @useTria also hacked?
We just opened a new case.
If you see this, check your balances and protect your funds!!
Join the hunt @
https://t.co/I9zbFI4eUb
Ongoing situation at @avici..
First hunters started to collect evidence, notes and clues.
Exit scam? Or protocol hack..
Join the hunt:
https://t.co/YYcENZuITk
We just opened a case for the @avici ongoing hack.
Community investigation!
Join the hunt, collect evidence and find the responsible drainer!
Follow and track the progress on:
https://t.co/YYcENZuITk