Crypto Fraud Watch: A $600,000 Solana Card Breach, The Sandbox's 1:1 Repayment Pledge, and a $201.8 Million ETF Reversal
Two security failures and a sharp reversal in fund flows shaped the last two days in crypto. A vulnerability in a third-party card contract on Solana cost users roughly $600,000, The Sandbox committed to making holders whole after a bridge exploit, and Bitcoin gave back a chunk of its August gains as ETF money ran the other way. Below is what happened in each case, and what it means legally.
A Vendor's Outdated Contract Costs Avici Users $600,000
On August 28, Solana-based neobank Avici told users it was investigating a problem with card balance withdrawals. Hours later, Rain, the card-issuing partner behind the product, disclosed that its monitoring systems had found a vulnerability in an outdated version of its Solana card contracts, affecting a small number of programs. More than $600,000 was drained. Avici said 1,685 of its users were owed roughly $500,000 in card balances and committed to refunding every affected balance in full. Jupiter's card program briefly paused balance withdrawals as a precaution and confirmed its own users were never affected.
The legally interesting part is that the failure did not happen at the company holding the customer relationship. It happened one layer down, at the vendor. Who ultimately eats that $500,000 will be decided by the program agreement between Avici and Rain, not by anything on-chain. For consumers, the harder question is whether the error-resolution protections of Regulation E attach to a crypto-funded card balance at all. That turns on how the product is structured and who holds the underlying funds, and many crypto card programs are built in ways that leave the answer contested. Avici refunding quickly makes the question academic here. The next program may not.
The Sandbox Pledges 1:1 Repayment, and the Claims Window Is Short
Also on August 28, The Sandbox published its post-mortem and compensation plan for the bridge exploit that hit it on August 21 and 22. The attacker abused the approveAndCall function on the SAND omnichain token contract on Base to hijack LayerZero delegate permissions, then minted 329.24 trillion unbacked SAND across 703 separate events over about five hours. The realized theft was far smaller than that headline number: roughly 14.74 million SAND, about 0.5% of maximum supply, was pulled from the Ethereum adapter in under a minute and converted to around 80 ETH, worth approximately $675,000. Holders who legitimately held bridged SAND on Base or BNB Smart Chain before the attack are to receive an equal amount of Ethereum-based SAND from the treasury, with no new tokens minted. Claims are expected to open within about two weeks and stay open for roughly two more.
A voluntary make-whole program is not a legal remedy, and the difference matters. Claim processes of this kind frequently ask participants to sign a release, which trades an uncertain future claim for a certain present payment. That can be a perfectly sensible trade, but it should be a decision rather than a reflex. The compressed timeline is the other risk: a four-week total window is easy to miss if you are not monitoring the project's announcement channels, and missing it can leave you arguing about a deadline instead of a loss.
A $201.8 Million ETF Outflow Ends a Nine-Day Streak
Bitcoin traded near $77,800 on August 29, down about 3.8% over 24 hours, with total crypto market capitalization around $2.72 trillion. Roughly $381 million in leveraged positions were liquidated across more than 81,000 accounts in a single day. US spot Bitcoin ETFs recorded $201.8 million in net outflows on August 28, ending a nine-day run that had added more than $3 billion. August remains net positive at about $3.3 billion.
Fast drawdowns are when disputes get made. Liquidation cascades produce complaints about oracle pricing, auto-deleveraging, order routing, and platform outages, and those complaints are far easier to pursue when the evidence was captured in the moment rather than reconstructed weeks later. Most exchange agreements also impose short notice periods and mandatory arbitration, so the practical window to raise an issue is often measured in days.
Visa Signs Upbit's Parent for Korean Stablecoin Payments
On August 28, Dunamu, the operator of South Korean exchange Upbit, announced a strategic partnership with Visa covering stablecoin payments, cross-border remittances, and AI-driven financial services. Open USD is among the stablecoins under consideration, though Dunamu has said it is one of several. No product, chain, or launch date has been set.
Announcements like this get ahead of the law by design. South Korea's own stablecoin framework is still being written, which means the commercial terms are being negotiated against licensing and issuance rules that do not yet exist in final form. For businesses considering similar arrangements, the useful discipline is building termination and repricing rights that survive a regulatory framework arriving in a shape nobody planned for.
How to Protect Yourself
Vendor risk is invisible from inside an app. The Avici users who lost card balances had no way to know which contract version their issuer was running, which is a good argument for treating any crypto-linked card balance as spending money rather than storage, and for moving the rest to self-custody. Treat bridged and wrapped tokens as carrying contract risk on top of price risk, since the bridge, not the asset, is where the failure usually lives. Turn on withdrawal and transaction alerts wherever they are offered. If you hold a position that was affected by an exploit, follow the project's official channels directly for claim windows rather than waiting for news coverage, and preserve wallet addresses, transaction hashes, and screenshots immediately.
On recourse: if a platform, issuer, or program manager caused or failed to prevent your loss, contract and negligence theories may be available, and prompt written notice often preserves rights that silence forfeits. Reimbursement offers deserve a careful read before acceptance, particularly the release language and the deadline. Where a loss involves theft, a report to law enforcement and to the FBI's Internet Crime Complaint Center creates a record that can matter later, and blockchain tracing is often more productive in the first days after an incident than at any point afterward. An attorney can help you evaluate whether to accept a compensation offer or preserve a claim.
At Coin Counsel, we work with individuals and businesses navigating the legal fallout of crypto fraud - whether you're a victim seeking recovery, a company facing regulatory scrutiny, or a project working to stay compliant in an increasingly complex legal landscape. The rules are evolving fast, and the cost of getting it wrong has never been higher. Contact us at coin-counsel.com to speak with a crypto-focused attorney today.
Disclaimer
This blog post is for informational purposes only and does not constitute legal advice. Reading this content does not create an attorney-client relationship between you and Coin Counsel or Franco Law PLLC. The legal landscape surrounding cryptocurrency is rapidly evolving and varies by jurisdiction. Do not act or refrain from acting based on information in this post without first consulting a qualified attorney. If you believe you have been the victim of crypto fraud, contact us at coin-counsel.com for a consultation.