A vulnerability in an outdated Rain card contract drained roughly $1.1 million from several Solana-based programs, with the AVICI token of self-custodial neobank Avici falling as much as 49% from its 24-hour high of $0.43 to a record low of $0.217 before partially recovering to around $0.378. Rain, a Visa principal member that supplies the underlying stablecoin card infrastructure, said its monitoring identified the flaw in an older contract version used by Avici and a small number of other programs, and has since upgraded every program running that version with no further unauthorized activity observed.
Why it matters
The exploit exposes the custody handoff that underpins self-custodial crypto cards. Users controlled balances held in Avici's wallets, but funds loaded for spending moved into a third-party contract. That distinction is becoming more material: tracked crypto-card spending more than tripled to $1.04 billion in July, with stablecoins funding roughly 70% of more than 10 million transactions, a scale where a single contract vulnerability becomes a sector-wide risk vector.
Market impact
Avici confirmed $500,800 was taken from 1,685 of its users, while fellow crypto-card neobank Tria reported 636 affected users and losses above $430,000, with its token dropping more than 10% intraday. Both companies pledged full refunds, though Avici has not disclosed a refund timeline or funding source and has filed a report with the FBI's Internet Crime Complaint Center. Onchain data shows the attacker repeatedly added itself as an administrator to card-collateral accounts before withdrawing balances, then swapped the stolen stablecoins into SOL, bridged to Ethereum, and routed the proceeds through Tornado Cash. The gap between the roughly $1.1 million traced onchain and Avici's reported loss points to additional Rain-powered programs being hit, though neither company has named them or disclosed per-program totals.
Frequently asked questions
-
What vulnerability caused the Rain card exploit?
Rain identified a flaw in an older card contract version used by Avici and a small number of other programs, letting the attacker add itself as an administrator to card-collateral accounts and withdraw balances.
-
How much was stolen from Avici users?
Roughly $500,800 was taken from 1,685 Avici users, out of approximately $1.1 million drained across multiple Solana-based programs in total.
-
Were self-custodial wallets affected?
Avici said the breach was confined to card-funding contracts. The company's self-custodial wallets on Solana and Ethereum-compatible networks were not impacted.
-
How did the attacker move the stolen funds?
Onchain data shows the stolen stablecoins were swapped into SOL, bridged to Ethereum, and ultimately routed through crypto mixer Tornado Cash.
-
Will Avici refund affected users?
Avici has pledged full refunds for all affected balances but has not disclosed a timeline or funding source. The company has filed a report with the FBI's Internet Crime Complaint Center.
CoinDesk