The trust test of oracle shutdowns and pitfalls in smart contracts.

CN
1 hour ago

On August 30, 2026, the cross-chain oracle protocol Switchboard announced that it received a report of a suspected attack on its services the previous night. It immediately collaborated with relevant project parties and security agencies to intervene and selectively pulled the "switch" — suspending network services on the Aptos, Sui, IOTA, and Movement chains, while Solana, which has always held an important position in its business landscape, was not included in the suspension range. Almost on the same timeline, Avici revealed that its Solana card contract had vulnerabilities, with the affected scope clearly limited to the card contract balances injected through the Avici recharge process, while regular Solana and EVM wallets remained unaffected due to being self-custodial. After the incident was disclosed, Avici claimed to have completed refunds for all affected funds and additionally offered users a 10% cashback, with its partner Rain bearing the full refund cost. These two security incidents, deemed independent by officials, led to not just a one-time loss assessment but raised sharper questions: when the oracles are down and the card contracts hit landmines, how should multi-chain infrastructure providers and issuing institutions rebuild user trust in the entire system beyond just technical damage control?

Oracle Shutdown: Switchboard Suspends Multi-Chain Services

Just as the aftershocks from the Avici card contract incident were still unresolved, Switchboard, as a cross-chain oracle, sent another unsettling signal on August 30. The official stated that after receiving a report of a suspected attack on the oracle services the night before, it immediately coordinated with relevant project parties and third-party security agencies to enter an emergency response state, making a drastic but intuitive choice: to proactively "shut down." According to public information, this suspension affected Switchboard network services on Aptos, Sui, IOTA, and Movement, while Solana was not included in the suspended range, meaning the operation status of the same oracle infrastructure on different public chains was artificially divided.

For applications on these chains, the more immediate short-term risk is not the instant theft of funds, but the logical failure caused by interrupted price feeds: any DeFi protocols, derivative contracts, or liquidation mechanisms that rely on data such as prices provided by Switchboard could theoretically face business interruptions, risk management strategy failures, or even be forced to switch data sources. However, as of the time of the announcement, Switchboard had not disclosed the specific type of attack, the scale of possible losses, nor provided a clear recovery timetable, only vaguely stating that it was investigating and repairing. This makes it hard for outsiders to judge whether this collective shutdown of the multi-chain oracle was merely a cautious self-protection, or a precursor to a larger risk not yet fully revealed.

Multi-Chain DeFi Bears the Cost of Oracle Downtime

When Switchboard pressed the "pause button" on Aptos, Sui, IOTA, and Movement, while Solana remained online, the awkwardness of multi-chain DeFi was immediately exposed: locked within the contracts is an absolute trust in oracle price feeds. Key logical processes such as liquidation, order placement, and collateral management, once deprived of price input, either continue to "run blindly" — performing irreversible operations under potentially distorted prices — or are urgently shut off by the project parties, opting for business interruptions. The fact that these chains have controllable switches illustrates that the oracle itself can partially shut down, but whether the protocol parties have reserved a "single chain power-off" safety mode is only revealed at the moment of the incident.

For project parties, true risk control design has long since evolved from "which oracle to choose" to "how to survive when the oracle goes silent." Multi-source data, backup oracles, price deviation circuit breakers, and manual intervention whitelists — these seemingly mature solutions imply more complex contract statuses and governance processes, while Switchboard's currently available information remains at the level of suspension decisions and partner cooperation, lacking a technical review that allows integration parties to conduct thorough inspections of their dependency chains. What remains to be seen is how Switchboard will present its recovery strategy and incident review for each sub-chain, and during this interim period, whether the protocols on each chain connected to it will choose to continue entrusting a single oracle or take the opportunity to incorporate multi-source and circuit-break features into their production systems.

Avici Card Contract Misstep and 10% Refund

Compared to the on-chain logic of the oracle, another aspect that makes users more intuitively anxious is the "card contract misstep" at the fiat entry and exit points. Avici previously disclosed that there were issues with its Solana card contract, but the initial definition provided was quite restrained: the incident only affected the Solana card contract balances injected through the official Avici recharge process, while regular Solana wallets and EVM wallets were explicitly categorized as "self-custodial" and not within the affected range. In other words, the problem occurred in a specific funding pool associated with a designated recharge path, and not in the asset accessibility across the entire chain for users, which serves as a key delineation in an environment where panic might spread.

On the compensation front, Avici publicly stated that all affected funds had been fully refunded, and additionally offered related users a 10% cashback as compensation, with its partner Rain bearing all refund costs for this incident. Meanwhile, Avici emphasized that EVM card balances, fiat deposits/withdrawals, and token exchanges remained operational during the vulnerability period and were not included in the incident scope. For ordinary users, this means that even if they hit a landmine with the Solana card contract, the consequences are contained within a visible and verifiable small segment of their account, while the more regularly relied-on account systems and deposit/withdraw channels remain available. Currently, there is also no evidence in the public domain to suggest that this incident is directly related to the oracle turmoil involving Switchboard.

Responsibility and Compensation Game of Fiat Entry and Exit

In the Avici Solana card contract incident, Rain bore all the refund costs, which on the surface appears to be a "partner cover charge" business decision, but fundamentally lays out the internal responsibilities of the fiat entry and exit ecosystem: whoever leads the card products is responsible for user funds. Avici, in its announcement, precisely delineated the affected scope as "the card contract balances injected through the Avici recharge process," while repeatedly emphasizing that regular Solana and EVM self-custodial wallets, fiat deposits/withdrawals, and token exchange functionalities were unaffected, and additionally offered a 10% cashback on top of the full refund. This combination not only represents monetary compensation for users but also conveys a crucial message — when issues arise with card contracts, funds will be traced back along the path, and responsibilities will be split based on the collaborative relationships, indicating that fiat entry and exit is not a no-man's land.

In contrast, Switchboard chose to first suspend network services on the Aptos, Sui, IOTA, and Movement chains after receiving a report of a suspected attack, prioritizing downtime to mitigate potential risks; however, to date, it has not disclosed the type of attack, scale of losses, or compensation arrangements, and Solana has not been included in the suspension scope. Both incidents primarily communicated externally through announcements, yet they significantly differ in information density and compensation posture: one uses detailed impact delineation and clear cash refund amounts to restore trust, while the other keeps security measures within a black box. For users who are currently choosing card services and oracle services, this means that the emergency plans and responsibility commitments in the contracts can no longer be overlooked lengthy clauses, but must instead become a checklist to verify before decision-making — who will be responsible for the balance in case of contract incidents, whether they commit to timely disclosure of handling progress, and whether they are willing to provide additional compensation beyond minimum legal obligations; the clearer these stipulations are and the more decisively they are fulfilled, the more trust can be regained in fiat entry and exit and infrastructure during the next crisis.

Looking at the Next Crisis through These Two Incidents

When placed on a timeline, Switchboard chose to "suspend multi-chain services on Aptos, Sui, IOTA, and Movement" in August 2026 to combat a suspected attack whose details had not yet been confirmed, while shortly before, Avici’s Solana card contract completed refunds and additionally offered a 10% cashback, at a cost borne by its partner Rain. These two fundamentally different responses point to the same lesson: when fundamental infrastructure and fiat entry and exit encounter problems, the last to assume responsibility is often not the "black swan," but rather how defenses were laid out in advance and how responsibilities are borne afterward. Although there is currently no evidence showing a direct connection between the two incidents, they still reflect two sides of the same trust test — one oracle opts to shut down rather than operate sick amidst unclear risks, while the other card service fulfills promises of compensation after vulnerabilities are exposed. In the time ahead, variables worth observing include: how Switchboard discloses investigative conclusions, when and in what rhythm it restores services across chains, and whether other oracle and card service providers will follow suit in reinforcing contract and risk control processes. For project parties and users, a more pragmatic approach is not to emotionally "change service providers" only when incidents occur but to reserve redundant oracles at the architectural level, diversify entry and exit channels, and focus on whether official disclosures are transparent and whether repair and compensation plans are genuinely implemented, thus locking foreseeable risks within system design and contract terms before the next crisis arrives.

Join our community to discuss together and strengthen together!
Exclusive Hyperliquid benefits for AiCoin: https://app.hyperliquid.xyz/join/AICOIN88
Exclusive Aster benefits for AiCoin: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink