GoPlusSecurity: The collateral program behind the crypto card has been attacked, affecting 1,685 users
2026-08-29 15:45:26
According to CoinMeta, as reported by GoPlusSecurity, on August 28th, the card balance collateralization program behind the crypto cards was attacked. Avici stated that 1,685 users were affected, with approximately $500,000 stolen, and they promised a full refund. The attackers exploited a vulnerability in the signature verification/authorization logic of the Solana card contract of Rain. They then executed the same three-step cycle in multiple users' collateralized accounts: (1) submitted forged signature packets – submitsignatures; (2) registered as administrators – addcollateraladmin; (3) withdrew the collateral – withdrawcollateralasset. The stolen funds were periodically exchanged for SOL and transferred. The root cause of the attack was not the stolen upgrade keys, nor a vulnerability in Solana L1, but a program error that incorrectly parsed/bound the ed25519 verification results, allowing the attackers' own signatures to pass through legitimate administrator authorization.
Bullish 0
Bearish 0
Source:X
This content is for market information only and does not constitute investment advice.