
Key Takeaways
Solana-based crypto neobank Avici has confirmed that 1,685 customers lost a combined $500,859.22 after an attacker exploited a vulnerability in the infrastructure supporting its payment cards.
The incident did not compromise users’ main Avici wallets.
According to the company, the vulnerability was found in an older version of a Solana card contract operated by card-issuing partner Rain.
When Avici users top up their payment cards, those funds leave their self-custodial wallets and move into a separate smart contract that holds the card balance.
It was this contract, rather than Avici’s wallet infrastructure, that was attacked.
Onchain analysis indicates that the attacker exploited an authorization flaw, allowing an unauthorized administrator to be added to affected collateral accounts.
The attacker then repeatedly used withdrawal functions to move balances from those accounts.
One reconstruction found thousands of withdrawal calls during the attack. The attacker-controlled address also accumulated substantial assets across affected programs, although estimates of the total amount moved have varied because the vulnerable Rain contract was reportedly used by multiple services.
Avici’s own reconciliation currently shows customer losses of $500,859.22 across 1,685 users.
Rain has since upgraded the vulnerable contract across affected programs, and Avici said it has seen no further unauthorized activity following the fix.
The incident shows an important difference between holding funds in a self-custodial wallet and moving them into a payment product.
Avici said users retain control of assets stored in their Solana and EVM wallets, and those balances were not exposed during the exploit.
The risk appeared only after customers transferred funds into the separate card contract used to support spending.
That separation limited the breach, but it also shows that a self-custodial crypto app can still introduce third-party smart-contract risk when users interact with cards, lending products or other external services.
Avici has said every affected card balance will be reimbursed in full.
The company is working with Rain and security partners while monitoring the upgraded infrastructure. It has also filed a report with the FBI’s Internet Crime Complaint Center.
Early social-media warnings claimed entire Avici wallets were drained, but the company later clarified that this was inaccurate: the exploit was confined to card balances held in a separate Rain-powered contract.
For users, that distinction is significant. The breach did not break Avici’s self-custody model, but it exposed how funds can take on a different security profile the moment they leave a wallet and enter third-party payment infrastructure.
Check your email to confirm
We sent a confirmation link to . Confirm it to activate your Kyroo cashback — you can do this anytime.
You're in! Taking you to {partner} in ...