Web3 Daily Exploits — 30 Aug 2026: Fogo halts mainnet after 400M-token foundation compromise
Fogo paused its SVM Layer-1 after a foundation compromise moved 400 million FOGO, worth about $3 million. On Ethereum, Ajna confirmed a ~$775,000 liquidation-accounting exploit, while Rain said Avici and Tria cardholders have been repaid after Friday’s Solana card-contract drain.

Fogo paused its SVM Layer-1 after a foundation compromise moved 400 million FOGO, worth about $3 million. On Ethereum, Ajna confirmed a ~$775,000 liquidation-accounting exploit, while Rain said Avici and Tria cardholders have been repaid after Friday’s Solana card-contract drain.
The last 24 hours were dominated by follow-through, not a brand-new nine-figure drain. Fogo reversed its first public assessment and halted mainnet to restrict addresses tied to a 400 million FOGO foundation transfer. Ajna confirmed that a bad actor hit multiple v2 pools and told users to exit an immutable, ungoverning protocol. Rain, Avici, and Tria closed the loop on Friday’s Solana card-contract incident by stating that affected card balances have been repaid.
Required alert accounts were checked for this window. @CertiKAlert, @Phalcon_xyz, @PeckShieldAlert, @BlockSecTeam, @Lookonchain, @zachxbt, @CyversAlerts, and @immunefi did not publish a new protocol-exploit alert after 11:35 UTC on 29 August 2026. @SlowMist_Team was quiet on fresh hacks in the same window. Claims below are marked confirmed, likely, or unverified.
UPDATE: Fogo Foundation compromise, then a mainnet halt
Status: Confirmed compromise of foundation-controlled tokens; root cause undisclosed. Mainnet halt confirmed by the project. User-fund loss on the chain itself is not claimed.
Protocol / chain / asset: Fogo Foundation / Fogo (SVM Layer-1) / FOGO
Estimated loss: 400 million FOGO. Independent coverage clustered around about $3 million at post-incident prices near $0.0075. That is about 4% of the 10 billion genesis supply and, per The Block, more than 10% of circulating supply. Token-price moves after the disclosure are not treated as additional stolen value.
Attack type: Organizational / wallet or key compromise (not a disclosed consensus or runtime bug).
What happened. Late Friday, Fogo said an unknown actor compromised the Foundation and sent 400 million FOGO to “a bad actor.” The same post said exchanges, law enforcement, and forensic specialists had been notified, and that “there is no impact to the Fogo blockchain, which continues to operate as normal.” About 15 hours later, on Saturday 29 August at 16:29 UTC, the official account reversed the operational posture: mainnet was “temporarily halted as a precautionary measure following the detection of unauthorized activity,” to stop further movement of affected assets while validators upgraded the network to restrict incident-linked addresses.
That halt is the material development in this briefing window. The initial disclosure landed at 01:13 UTC on 29 August, just outside the strict 24-hour cut. The halt, exchange deposit/withdrawal freezes reported at Bitget, MEXC, and later KuCoin, and the continued absence of a root-cause write-up all fall inside the window.
Technical details. Fogo has not published the compromised wallet, the destination address, a transaction signature, or whether the actor obtained a hot-wallet key, a multisig signer, an operational workstation, or something else. Until those artifacts are public, treat on-chain reconstructions circulating on social media as unverified. The project’s own framing is infrastructure-level compromise of Foundation holdings, not a break in SVM execution or consensus. The upgrade path described on Saturday is address restriction during a coordinated halt — a chain-governance response, not a smart-contract patch.
Key addresses and transactions: none published by Fogo as of this briefing. Do not trust unofficial “attacker wallet” screenshots until the Foundation or a named forensics firm posts an explorer link.
Sources: Fogo initial disclosure; Fogo halt; The Block.
UPDATE: Ajna v2 — ~$775,000 via liquidation accounting on Ethereum
Status: Confirmed by the protocol. Loss figure is Defimon’s pool table (~$775,000 / ~$775,400). Full postmortem still pending. No user reimbursement announced.
Protocol / chain / asset: Ajna v2 / Ethereum / syrupUSDC, wstETH, rETH, cbETH, WBTC, WETH/USDC, sDAI pools
Estimated loss: about $775,000 (Defimon, 29 August 09:29 UTC). Individual pool marks: syrupUSDC $173.7K; wstETH $159.8K; rETH $127.4K + $15.6K; cbETH $124.8K + $12.1K; WBTC $101.8K; WETH/USDC $42.0K; sDAI $18.0K.
Attack type: Liquidation / auction accounting manipulation on an oracle-free lending market. Not an external price-oracle feed hack.
What happened. Attack contracts were deployed around 15:16 UTC on 28 August. The first reconstructed extraction against a cbETH pool landed at 16:19 UTC the same day in block 25854888. Ajna first told users there were “unusual movements” at 04:58 UTC on 29 August and asked them to withdraw quote tokens, repay loans, and stop using v2. Defimon later said it had flagged a prepared attack more than an hour before the first exploit transaction and notified the team in Discord without a preventive response. In this window, Ajna posted a confirmation at 15:58 UTC on 29 August: a bad actor executed a series of malicious transactions against multiple pools; a postmortem is in progress; users should still not interact with v2.
Ajna v2 has no governance and no upgrade key. The only containment lever is user exit. That is why the Saturday reminder matters even though the first drain was Friday afternoon UTC.
Technical details. Public reconstructions, including a reply under Defimon’s thread, describe same-transaction pool accounting used to derive auction prices. In that model, an attacker can combine draw/repay, quote-token accounting, and a kick inside one atomic transaction so a liquidation opens at a price that undervalues collateral. The sample cbETH transaction is consistent with a Balancer flash loan of 4 WETH, interaction with Ajna auction primitives (bucketTake / collateral removal), and a net bleed of pool cbETH against a much smaller WETH quote inflow. Explorer decoders that label the same hash as “two swaps” are incomplete; the balance-change view is the useful one.
Ajna has not published a line-by-line root-cause note. Treat mechanism write-ups that go beyond the confirmed pool list and the sample transaction as likely until the official postmortem lands.
Key addresses and transactions:
- Sample extraction (cbETH pool, 28 Aug 16:19 UTC): 0x12dfde527ef62882bfabb64362c9ae0e6bfb628363bd298d0d0956c9a114e4f5
- From (EOA): 0x6F2f5236b10FE7162Da077A2779f8b5f04b7827e
- To / attack contract: 0x80AD419C4783A09252Ad6a576ce059f51Cc53D47
- cbETH pool touched in that tx: 0xad24FC773e125Edb223C38a39657cB64bc7C178e
- Borrower position referenced in logs: 0x02D329Ebb1DA079A89988366b777aF300DB96F5f
- Balancer Vault (flash-loan source in the sample tx): 0xBA12222222228d8Ba445958a75a0704d566BF2C8
Defimon listed additional attacker links in its original alert; those still resolve through t.co wrappers. Only the addresses above are reproduced from the sample transaction itself.
Separately, at 22:28 UTC on 29 August Defimon broadcast an on-chain note asking an Ethereum address to discuss a bounty for return of funds: 0xef7ce81cdabc1ba9f60b2bfac419e42b07f3b1318c7ae5caff02bb82c307da71 (from 0xdDbf679d6332d9E5b409865b9671d1927255B52A to 0xD71dD9B6e634412713c47fe7aE02c628e338C384). Defimon did not label that message as Ajna-specific. Treat the linkage as unverified.
Sources: Ajna first public note; Ajna Saturday confirmation; Defimon pool table; Crypto Times reconstruction.
UPDATE: Rain Solana card contract — Avici and Tria say users are repaid
Status: Confirmed exploit on 28 August. Confirmed repayment statements on 29 August from Rain and Tria. Avici had already pledged full refunds on Friday and reported the matter to the FBI IC3. On-chain theft is not reversed; issuers say they recapitalized card balances.
Protocol / chain / asset: Rain card-collateral program on Solana, used by Avici, Tria, and at least one unnamed program / USDC, USDT, then SOL and ETH
Estimated loss: Avici reconciled $500,859.22 across 1,685 users. Tria reconciled $431,945 across 636 users. Combined disclosed user balances: about $932,800 across 2,321 users. CertiK and on-chain flow notes put the attacker’s converted stack near $1.02 million after a 10,000 SOL transfer, which is consistent with additional Rain programs beyond the two named neobanks. CoinDesk’s ~$1.1 million cluster figure is likely as an upper bound on the shared contract, not a third official reconciliation.
Attack type: Authorization / signature-binding flaw in a legacy Solana card program, then unauthorized admin on per-user collateral accounts and withdrawal of card floats. Not a Solana L1 bug and not a drain of self-custodial wallets.
What happened in this window. The live drain was 28 August, beginning around 16:49 UTC. What is new inside 24 hours is closure language from the issuer stack. Tria said at 10:47 UTC on 29 August that 636 users and $431,945 in card balances were in scope, then at 18:58 UTC that every affected user had received a full refund plus an extra 10%. Rain said at 19:24 UTC that all impacted cardholders from the previous day had been repaid in full, that funds sit in upgraded user smart contracts, and that forensics plus law enforcement remain engaged. CoinDesk and later roundups on 29–30 August packaged Avici + Tria as a shared Rain outage and noted AVICI’s drawdown to a record low near $0.217 (price context only).
Technical details. Independent notes from GoPlus, SlowMist, CertiK, and The Defiant converge on the same three-instruction loop against Rain’s legacy program: submit a crafted signature bundle (SubmitSignatures), register the attacker as admin on the victim collateral account (AddCollateralAdmin), withdraw (WithdrawCollateralAsset). GoPlus attributes the root cause to mis-parsing or mis-binding of the Ed25519 verify result, so the attacker’s own signature could pass as admin authorization. SlowMist logged the event as a smart-contract vulnerability for $500,859.22 at Avici. Self-custodial Avici and Tria wallets on Solana and EVM were repeatedly described as untouched; only the separate card-float contract was in scope.
CertiK tracked the cash-out: attacker FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj sent 10,000 SOL to MsaXH6cGDahPQDwJjFYod7RW8QLVDZGByywWvwQ9TFu, swapped toward ~$1.02 million USDC, then bridged and swapped through 0x2cE21E4921d3Eb116526c3651Dac0257657338D5 into about 418 ETH that later entered Tornado Cash. Hit program cited by GoPlus: 26DkA98jjctzPkBEteUsN935CR4dsKx3XvjrtE7MeL4a.
Key addresses:
- Solana attacker: FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj
- SOL receiver / swap hop: MsaXH6cGDahPQDwJjFYod7RW8QLVDZGByywWvwQ9TFu
- Affected Rain program: 26DkA98jjctzPkBEteUsN935CR4dsKx3XvjrtE7MeL4a
- Ethereum cash-out / mixer hop: 0x2cE21E4921d3Eb116526c3651Dac0257657338D5
Individual Solana drain transaction signatures were circulated as t.co wrappers by alert accounts; this brief does not invent hashes that were not expanded to full 88-character signatures in primary posts.
Sources: Avici refund pledge; Rain Friday incident note; Rain Saturday repayment; Tria scope; Tria repaid + 10%; GoPlus breakdown; CertiK thread; SlowMist incident row; CoinDesk.
Also noted
- GoPlus — seized domain and $GOLD token (likely / partly unverified on profit). At 10:51 UTC on 29 August, just outside the strict 24-hour start, GoPlus said a fraud ring seized realtrumpcoins.com and the @realtrumpcoins1 account, launched $GOLD (EMWtbpHaNqMbjUMZguuazhuZUVLWG3z4C5oZnGJPSqxS), pumped market cap, and rugged with claimed profit above $8.2 million. Dev wallet: 3pQA1ZCaAuFgVJPmkxUGhBaDQjRpt88CXaXmoVy3fRsr. Operator: 3odTMNgv5ViWXYoiZCwXuMbk8FTdJkpwvEHJfosuATos. Routing contract: FLASHX8DrLbgeR8FcfNV1F5krxYcYMUdBkrP1EPBtxB9. Related malicious mint $PLATINUM: AuzcYsvKsYs1DFkQVzpm6tLzWb2fFSfZGxLHyubWY4jM. Seed-money attributions to KuCoin and Binance hot wallets are GoPlus labels, not exchange confirmations. This is an account-takeover plus malicious-token event, not a DeFi protocol exploit.
- No new CertiK, Phalcon, PeckShield, BlockSec, Lookonchain, ZachXBT, Cyvers, or Immunefi protocol-drain alerts after 11:35 UTC on 29 August.
- Older items kept out of the lead: Moonwell (~$8.7 million, 27 August), CCC / CashCowCoin (~$117k, 28 August SlowMist note), Cosmos EVM downstream chain exploits from the prior week, BounceBit, Term Finance, Enjin Crypto Items. Those did not have a confirmed material on-chain or official development in this window.
Sources and references
- https://x.com/fogo/status/2093507386300637306
- https://x.com/fogo/status/2093737730920325153
- https://www.theblock.co/news/defi/2026-08-29-layer-1-blockchain-fogo-halts-mainnet-after-attacker-receives-400-million-fogo-tokens-10-of-circulating-supply-413064
- https://x.com/ajnafi/status/2093563829116383734
- https://x.com/ajnafi/status/2093730105713377452
- https://x.com/DefimonAlerts/status/2093632180656263283
- https://x.com/DefimonAlerts/status/2093828258986856774
- https://etherscan.io/tx/0x12dfde527ef62882bfabb64362c9ae0e6bfb628363bd298d0d0956c9a114e4f5
- https://www.cryptotimes.io/2026/08/29/ajna-v2-loses-775k-on-ethereum-after-attacker-exploits-liquidation-math/
- https://x.com/avici/status/2093439613201482068
- https://x.com/raincards/status/2093435073081053518
- https://x.com/raincards/status/2093781877295653267
- https://x.com/useTria/status/2093651836079116392
- https://x.com/useTria/status/2093775283799327079
- https://x.com/GoPlusSecurity/status/2093606636694667717
- https://x.com/GoPlusSecurity/status/2093652785095233933
- https://x.com/CertiKAlert/status/2093428949334266091
- https://hacked.slowmist.io/
- https://www.coindesk.com/web3/2026/08/29/a-usd1-1-million-crypto-card-hack-crashed-a-neobank-s-token-49
- https://solscan.io/account/FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj
- https://etherscan.io/address/0x2cE21E4921d3Eb116526c3651Dac0257657338D5
Editor’s note
This brief covers first reports, confirmations, and material updates from roughly 11:35 UTC on 29 August 2026 through 11:35 UTC on 30 August 2026 (24 hours before 06:35 America/Panama). Friday’s Avici/Rain drain and Friday night’s Fogo foundation disclosure are carried only because Saturday produced official follow-through — a chain halt, a protocol confirmation plus exit order, and issuer repayment statements. Loss figures are issuer or monitor marks, not token-price drawdowns. No exploit playbooks are included. If Fogo names a wallet or Ajna ships a postmortem after this edition is scheduled, treat those as a later update rather than as facts already in this file.
Read more

Web3 Daily Exploits — 07 Sep 2026: Liquid $320M Whitehat Peg-Out + Cozy $170K
Liquid Network sees ~4,000 BTC (~$320M) unauthorized peg-out claimed as whitehat; Cozy Finance loses ~$170k on Optimism via UMA oracle abuse; Secured Finance ~$104k price-manipulation drain on Ethereum; Rocket $287k update.

Web3 Daily Exploits — 06 Sep 2026: Reddio ~9.25 ETH Vault Double-Count + Autonolas Gov Attempt
A quiet window produced one confirmed low-value vault exploit and one blocked governance attempt. Reddio’s RedSonic Vault lost approximately 9.25 ETH to a cross-vault double-counting flaw; a malicious Autonolas proposal targeting ~40 ETH remains unexecuted.

Web3 Daily Exploits — 05 Sep 2026: Notional $1.7M Overflow + Dream Health $72k Logic Drain
Notional Finance lost ~$1.73M on Ethereum via an unsafe uint128 downcast in free-collateral checks. A separate ~$72k logic flaw drained Dream Health Chain awards on BSC.

Web3 Daily Exploits — 04 Sep 2026: Notional $1.7M integer overflow drain
Notional Finance lost ~$1.7M on Ethereum via an unsafe uint128 downcast in free-collateral checks. Attacker minted extreme fCash pairs and drained escrow before mixing via Tornado Cash.

