Solana Crypto Card Exploit Drains $1.1M; AVICI Plummets

Article

Solana Crypto Card Exploit Drains $1.1M; AVICI Plummets

A Rain contract vulnerability led to a $1.1M theft from several Solana apps, heavily impacting Avici (AVICI token fell 49%). Tria users also lost funds. Both firms promise reimbursements; attacker used Tornado Cash.

Reading time: 2 Minutes

A vulnerability in an older Rain smart contract used by crypto card services resulted in the theft of approximately $1.1 million from multiple Solana-based apps. The incident hit neobank Avici hardest, pushing its AVICI token down as much as 49% in a short period. On-chain analysis shows a sophisticated chain of conversions and mixers used to launder the stolen assets.

Impact on Avici and Tria

Avici losses and token crash

Roughly $500,800 belonging to 1,685 Avici users was taken in the attack. AVICI’s price fell from an intraday high of $0.43 to an all-time low near $0.217 before partially recovering. The sudden drawdown spooked traders and highlighted the liquidity and market-risk implications of protocol-level exploits for centralized token projects.

Tria users affected

Neo-bank Tria reported that 636 of its users lost more than $430,000 combined. Both Avici and Tria have pledged to fully reimburse affected customers, a move intended to preserve trust but which raises questions about long-term operational and insurance practices for crypto card programs.

How the Exploit Unfolded

According to Rain, the attacker exploited permissions tied to an outdated contract version that handled funds after card top-ups. By abusing signed authorizations, the attacker added themselves as a collateral manager and drained on-contract balances. The stolen stablecoins were converted to SOL, bridged to Ethereum, and ultimately routed through Tornado Cash, complicating recovery efforts.

Security Takeaways

Rain says the vulnerability existed in an old contract and that all apps using that version have been updated. Importantly, self-custody wallets on Solana and Ethereum-compatible chains belonging to users were not compromised—the breach targeted the intermediary card contract where funds were temporarily held.

This case highlights broader DeFi security risks: even self-custodial services can face new attack surfaces when bridging user funds to card infrastructures and third-party smart contracts. Teams integrating crypto cards, stablecoins, and off-chain services should enforce rigorous contract audits, upgrade paths, and least-privilege permissioning to reduce exploit risk.

What to Watch

Monitor official disclosures from Rain, Avici, and Tria for reimbursement timelines and forensic updates. Watch on-chain movement of the laundered funds and any law enforcement or protocol-level responses. For crypto users, the incident is a reminder to understand where funds are held during off-chain interactions and to practice careful risk management in DeFi and crypto payments.

Leave a Comment

Comments

No comments yet. Be the first.