An authorization flaw in a legacy Solana smart contract operated by card-issuing infrastructure provider Rain allowed an attacker to drain $500,859.22 in card balances from 1,685 Avici users on Friday, August 29, according to on-chain data and statements from both companies.
Avici, a self-custodial neobank offering Visa-linked spending cards on Solana, has confirmed that every affected user will receive a full refund and disclosed that it has filed a report with the FBI’s Internet Crime Complaint Center (IC3).
How the Attack Unfolded
On-chain records reviewed by multiple analysts show a tightly sequenced exploit that began and ended within hours on August 28, 2026.
The attacker’s wallet FVNFzq…CEj, was created at 13:40 UTC on August 28 and seeded with about 1.79 SOL (roughly $190) bridged from Ethereum to Solana via deBridge, according to on-chain researcher Nikita (@0xVishnya) and SolScanner’s exploit timeline. The wallet remained dormant for roughly three hours before initiating its first interaction with Avici’s smart contracts at 16:49 UTC.
From that point, on-chain records show the attacker executed a repeating three-step sequence across affected accounts:
- A SubmitSignatures call through Avici’s authorization program alongside Solana’s Ed25519 signature verification program.
- An AddCollateralAdmin call that registered a new administrator on the target user’s collateral account.
- A WithdrawCollateralAsset call that swept the card balance to an attacker-controlled address.
Analysts say the root cause was an authorization flaw: the second signature verification was incorrectly routed to the first instruction, causing Solana’s runtime to accept the attacker’s own signature as valid a second time. This allowed the program to add an administrator key that it should not have accepted under normal conditions.
By an 18:58 UTC checkpoint, the wallet held 10,005.03 SOL (approximately $1.07 million at prevailing prices) alongside roughly $11,600 in combined USDC and USDT. The address had signed 14,672 transactions, of which 2,344 failed. One reviewed withdrawal moved 2,346.77 USDT from a single user’s account.
An anonymous on-chain analyst known as STACC built a live tracker that identified 125 distinct sending accounts, with individual transfers ranging from approximately $9 USDC to more than $26,000 USDT.
The attacker gained administrative privileges over more than 1,100 collateral accounts. The median amount stolen per account was approximately $24, while the largest single loss in the sample was $5,268.
Community members on X flagged reports of the exploit being live. On-chain analyst @inno_sol noted that the attacker bridged approximately $1 million in USDC from Solana to Ethereum through deBridge and subsequently laundered proceeds using Tornado Cash. The same analyst listed multiple Rain-powered neobanks whose users were reporting fund drains, including Tria, Solayer Pay, and others.
Avici and Rain Respond
Avici acknowledged the situation approximately 1 hour and 53 minutes after the first reported transaction, posting on X: “We are aware of the issue affecting card balance withdrawals and are closely monitoring the situation.” Users had already begun reporting stolen balances on social media before the official acknowledgment.
In a subsequent update posted on X, Avici attributed the exploit to a vulnerability identified by Rain in an outdated version of a Solana card contract. The statement confirmed that the vulnerable contract was used by Avici and a small number of other programs, and that Rain has since upgraded the contract across all affected programs with no further unauthorized activity observed.
Avici emphasized the distinction between its self-custodial wallets and card balances. User wallets, which are self-custodial and secured via passkeys, were not affected. When users top up their cards, funds move into a separate Solana contract that holds their card balance. Only this contract was compromised. Funds held in Avici’s Solana and EVM wallets remain safe, the company stated.
Rain, which operates as a Visa Principal Member and provides stablecoin-powered card infrastructure to dozens of neobanks and fintech platforms globally, acknowledged the vulnerability in its own statement on X. Rain confirmed that it identified the flaw, upgraded the affected contracts, and is working with impacted partners to remediate.
Avici’s reconciliation identified 1,685 affected users with a combined loss of $500,859.22 in card balances. The company pledged full refunds for all affected users and disclosed that it has filed a report with the FBI’s IC3.
Broader Impact Across Rain-Powered Platforms
The exploit’s impact may extend beyond Avici. On-chain analyst @inno_sol listed a series of neobanks built on Rain’s infrastructure that were reportedly affected or at risk: etherfi Cash, Avalanche Card, Plasma One, Tangem Pay, KAST, Offramp, Currency, Dakota, Solayer Pay, Nuvei, Cadana, Wallbit, Takenos, Western Union Stablecard, Wyoming FRNT, Uniswap, Tria, XPlace, Oobit, Exa Card, Lava Card, and Tuyo Card. Independent verification of losses across all listed platforms has not been completed. Users from Tria and Solayer Pay were specifically cited as reporting drained funds.
Rain is a major card-issuing infrastructure provider in the crypto neobank market. In a January 9, 2026 Series C announcement covered by The Block, Reuters, and Rain’s own PR Newswire release, the company said it raised $250 million at a $1.95 billion valuation and that its platform supported more than 200 partners with more than $3 billion in annualized transactions. It announced native Solana support in May 2025.
Neither Avici nor Rain has disclosed whether an independent security audit of the vulnerable contract was conducted prior to the exploit, nor have they stated whether the contract in question had been audited by any third-party firm.
On-Chain Data and Infrastructure Concerns
On-chain analysts noted that both of Avici’s smart contract programs (authorization and collateral) are upgradable and share the same standard Solana account for upgrade permissions rather than using a multisig arrangement. This single-key upgrade authority has drawn criticism from security researchers, who argue that a multisig setup would have added a layer of protection against unauthorized contract modifications.
The attack pattern observed in the Avici exploit fits a broader trend identified in 2026 security data. Hacken’s Q2 2026 report found that compromised keys, signers, and infrastructure accounted for 88.3% of roughly $764 million stolen in Q2 2026. Separately, Blockaid reported that total crypto security losses surpassed $1.1 billion across 212 incidents in the first half of 2026, marking the most exploited half-year on record.
Avici Inc. is registered as a Delaware corporation with a San Francisco address listed on its website. The project raised $3.5 million through a capped MetaDAO token sale in October 2025, where 7,352 contributors pledged approximately $34.23 million, with roughly 89.8% returned after the cap was applied.
AVICI Token Tanks Nearly 50%
The native AVICI token bore the brunt of market reaction. According to data from MEXC and CoinGecko cited on August 28, AVICI fell as much as 49.4% within 24 hours to $0.2175, setting a new all-time low. The token was trading roughly 97% below its record high of $7.56, which was reached on November 26, 2025.
Market capitalization compressed to approximately $2.84 million on about $656,543 in 24-hour trading volume, most of it routed through MetaDAO’s futarchy automated market maker, with LBank, KCEX, and MEXC carrying the remainder.
Phishing Campaigns Compound the Damage
In addition to the smart contract exploit, a parallel phishing campaign has compounded losses for Avici users. Fraudulent websites impersonating the neobank, including domains such as getavici.today, lured users into connecting their wallets under the pretense of claiming airdrops. Once connected, drainer malware swept funds from those wallets.
These phishing-related losses reportedly total more than $600,000. Phishing activity targeting Avici users was first observed in late 2025, with individual incidents draining smaller amounts of roughly 0.2 SOL each.
What It Means for Solana Neobanks
The exploit underscores a recurring challenge in the rapidly expanding Solana neobank sector: the gap between marketing claims of self-custody and the on-chain reality of administrative permissions in smart contracts that hold user funds. Avici’s Apple App Store listing states that users always retain control and that the company never holds their funds. The ability for an attacker to register as an administrator and withdraw card collateral puts that claim under scrutiny.
For the broader ecosystem, the incident highlights the systemic risk that comes with shared infrastructure. Rain’s card contracts underpin a significant portion of the Solana neobank market. A vulnerability in one shared contract layer can cascade across dozens of consumer-facing products simultaneously.
No independent security firm has yet published a full post-mortem. The community awaits a detailed technical report to determine the precise origin of the authorization flaw and to confirm whether the vulnerable contract version had received any formal security audit.
Also Read: Moonwell Loses Nearly $8.7M in Base Exploit After MAMO Price Manipulation
