Avici says every one of the 1,685 users hit by a card balance exploit this week will get their money back in full. The Solana based neobank confirmed the refund late on August 28, after its card issuing partner Rain traced the breach to an outdated version of a Solana smart contract. Rain, in its own statement posted hours after the attack began, said its monitoring systems found a vulnerability affecting “a small number of programs using an outdated version of our Solana contracts.” That detail matters more than it first looks. It means the flaw sat in shared infrastructure that other Rain powered card programs also relied on, not in code unique to Avici.
UPDATE: All affected card balances will be refunded in full
Earlier today, our card-issuing partner, Rain, identified a vulnerability in an version of a Solana card contract used by Avici and a small number of other programs. The contract has now been upgraded across all…
— Avici (@avici) August 28, 2026
On chain activity backs that framing up. A wallet address, FVNFzq…QnCEj, funded with less than $200 through the cross chain bridge deBridge, ended up holding more than $1 million in SOL and stablecoins, according to on chain trackers, well above Avici’s own confirmed loss of $500,859.22. That gap is the real open question in this story. Rain has not said, and no on chain evidence independently confirms, exactly how much of that broader total came from programs other than Avici. One outlet has named Tria and Solayer Pay among roughly 22 Rain powered card programs that used the same outdated contract, but that reporting is not yet backed by a confirmed loss figure the way Avici’s number is.
The mechanism itself was not a stolen password or a leaked private key. Reporting on the exploit describes a signature verification bug: a check meant to confirm a second, separate authorization was instead pointed back at the first one, letting Solana’s runtime accept the attacker’s own signature as valid twice. That let the attacker register themselves as an administrator on user collateral accounts, then withdraw the funds directly, without ever needing a user’s private key.
Avici’s wallets themselves were not touched. The company says user wallets are self custodial and separate from card balances, and only the Solana contract that holds top up funds for card spending was exposed.
The token market reacted before either company finished its statement. AVICI fell 49.4% over 24 hours to $0.2175, a new all time low, cutting its market capitalization to roughly $2.84 million.
Avici says it has filed a report with the FBI’s Internet Crime Complaint Center and is continuing to work with Rain and its security partners on remediation. Whether any other Rain powered card program discloses a loss of its own is the detail worth watching next.
Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.
To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.


















