
Avici users received full refunds after a $500,859 exploit drained 1,685 card balances through an outdated Rain Solana contract.
Author: Akshat Thakur
29th August 2026- An attacker drained $500,859 from 1,685 Avici users on August 28. According to Avici, the theft exploited an authorization flaw in an outdated version of Rain’s Solana card contracts.
High Signal Summary For A Quick Glance
Reuben
@reubence
@avici i've seen support tickets take longer to resolve than it took y'all to make everyone whole. kudos team @avici!
UPDATE: Refunds are processed in full, with an extra 10% cashback. The Solana contract has been updated. We haven't seen any further related activity, and we're constantly monitoring it. If your Solana card balance was withdrawn a few hours ago, we've restored the full amount https://t.co/FJm8dES7K9 https://t.co/NTs0goOb4Q
05:52 PM·Aug 29, 2026
Steven (っ♡◡♡)っ
@stevensarmi
@avici @RamXBT 10% on top is wild. Nice.
UPDATE: Refunds are processed in full, with an extra 10% cashback. The Solana contract has been updated. We haven't seen any further related activity, and we're constantly monitoring it. If your Solana card balance was withdrawn a few hours ago, we've restored the full amount https://t.co/FJm8dES7K9 https://t.co/NTs0goOb4Q
05:12 PM·Aug 29, 2026
RoxaS
@skipfornow_R
@avici Thanks to this whole situation, I spent what was left in the app on the piano I was hesitant to buy. Now I got my money back + 10% cashback and the piano lol
UPDATE: Refunds are processed in full, with an extra 10% cashback. The Solana contract has been updated. We haven't seen any further related activity, and we're constantly monitoring it. If your Solana card balance was withdrawn a few hours ago, we've restored the full amount https://t.co/FJm8dES7K9 https://t.co/NTs0goOb4Q
05:06 PM·Aug 29, 2026
High attention and emotional sentiment detected.
The Avici exploit hit card balances that users had topped up, not their self-custody wallets. Since then, Rain, Avici’s card issuer, has covered every refund in full.
Avici runs a Solana-native neobank with a Visa-linked card. When users tap “Top Up,” their crypto moves out of their wallet and into a separate Rain card-balance contract.
That contract held the funds at risk. On August 28, an attacker used a flaw in an outdated version of it to add itself as an admin on user collateral accounts. Then it withdrew the topped-up balances.
According to Avici, the reconciled loss reached $500,859.22 across 1,685 users. The company reported the figure hours after the first drains appeared on August 28.
Rain confirmed the root cause the same day. In a statement on X, Rain said its monitoring systems found “a vulnerability impacting a small number of programs using an outdated version of our Solana contracts.” The issuer added that other programs stayed safe.
Tria, another card program built on Rain, reported the same attack. Tria later reconciled 636 users and $431,945 in withdrawn balances.
Together, the two official figures reach about $932,804. On-chain analysts put the full haul higher, near $1.1 million, once bridged proceeds are counted.
Not every Rain partner suffered. KAST, a separate card program, publicly said it was not affected. So far, Rain has not published the full list of programs that ran the old contract.
Neither Avici nor Rain has released a full technical post-mortem. The clearest account so far comes from on-chain researchers, including The Defiant and SolScanner.
According to those reconstructions, each drain followed a three-instruction chain. First, the attacker called SubmitSignatures on an authorization program alongside Solana’s Ed25519 signature check.
Next came AddCollateralAdmin, which installed the attacker as admin on a victim’s collateral account. Finally, WithdrawCollateralAsset swept the funds to attacker-controlled token accounts.
Analysts say the program bound a second signature check to the wrong instruction. Because of that, the runtime accepted the attacker’s own signature twice. In short, this was an authorization bug, not a Solana network failure.
Key milestones in the Rain/Avici Solana Card Contract Exploit
Rain’s older Solana card-balance contracts remain live at Avici and other programs. Neither firm has published the deploy date or why the contracts were not migrated sooner.
Wallet FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj is funded with ~1.79 SOL (~$190) via deBridge. Draining has not yet begun.
First malicious call hits the card contracts. Attacker exploits a signature-check flaw to add itself as admin and withdraw topped-up Solana card balances.
Card balance drains surface on X. Avici’s first public note at 18:42 UTC only states it is “aware of an issue affecting card balance withdrawals.”
Attacker wallet sends 10,000 SOL and is emptied; proceeds bridged off-chain. Avici’s recon later puts its slice at $500,859.22 across 1,685 users — not the full multi-program drain.
Rain upgrades the outdated Solana contracts across all affected programs. Avici posts recon figures, pledges full refunds, and files an FBI IC3 report. Rain confirms forensics experts and law enforcement are engaged.
Avici confirms every affected Solana card balance is restored in full with a 10% cashback on the withdrawn amount, funded by Rain. Self-custody wallets confirmed untouched.
Rain confirms all impacted cardholders repaid in full. Investigation remains open; no public recovery of the stolen funds has been announced.
The attack never reached funds sitting in Avici’s Solana or EVM smart wallets. Only balances already moved into the Rain card contract faced any risk.
As a result, Avici said its onramps, offramps, swaps, and EVM card path all stayed clean. The attacker also did not steal any upgrade-authority key, according to Avici and independent analysts.
Still, the incident dented a core promise. Avici’s own docs had stated that only a user’s wallet could withdraw escrow after card spends. On this Solana path, that guarantee failed.
Investigators quickly flagged the attacker’s Solana wallet, address FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj. Someone funded it with roughly 1.79 SOL, about $190, through the deBridge bridge.
From that small stake, the wallet grew fast. By 18:58 UTC, it held 10,005 SOL plus about $11,600 in stablecoins, worth around $1.07 million. Minutes later, at 19:02 UTC, it moved exactly 10,000 SOL.
The attacker then bridged the proceeds to Ethereum. Between 19:20 and 20:00 UTC, roughly 455.9 ETH flowed into Tornado Cash, the sanctioned mixing service. By 19:26 UTC, the Solana wallet sat empty.
In total, the attacker signed 14,672 transactions during the raid, and 2,344 of them failed. DefiLlama later logged the event as a $500,859 “Withdrawal Logic Flaw.”
The response moved almost as fast as the attack. On August 28, Rain pledged that “all affected users will be made whole.” Avici echoed that promise and filed a report with the FBI’s Internet Crime Complaint Center.
By the next afternoon, the refunds had landed. Avici said it restored every withdrawn balance and added a 10% cashback on top, credited in-app.
Crucially, Rain absorbed the cost. “Rain, our card issuing partner, covered all reimbursements in full,” Avici wrote on August 29. Rain confirmed that all impacted cardholders had “been repaid in full,” and Tria matched the refund-plus-10% terms.
Traders reacted before any refund posted. The AVICI token fell from about $0.4305 to a low near $0.2072 on August 28, a drop of roughly 37% from the open.
According to CoinGecko data cited by The Defiant, the token briefly printed $0.2175, an all-time low. Then the refund headlines flipped sentiment, and the price bounced back above $0.37 on August 29.
None of this is investment advice. Prices for tokens like AVICI can swing hard on incident news, so treat sharp moves with caution.
Several key questions remain open. Neither firm has named the attacker, published the patched program ID, or explained why the old contract stayed in production.
The trail into Tornado Cash also suggests the funds are not recovered. On top of that, no auditor or official root-cause report has surfaced for the vulnerable contract.
For now, users got their money back with a bonus, and Rain says it upgraded every program still on the old version. Whether a full post-mortem follows will show how seriously the industry treats outdated production code.
Our Crypto Talk is committed to unbiased, transparent, and true reporting to the best of our knowledge. This news article aims to provide accurate information in a timely manner. However, we advise the readers to verify facts independently and consult a professional before making any decisions based on the content since our sources could be wrong too. Check our Terms and conditions for more info.
Avici Users Get Full Refunds After Card Exploit
Charles Schwab Brings Solana, AVAX and LINK to Its Platform
Ripple Prime Takes Wall Street 24/7 With Delta One Launch
Sandbox Bridge Exploit Drains 14.7M SAND From Vault
Avici Users Get Full Refunds After Card Exploit
Charles Schwab Brings Solana, AVAX and LINK to Its Platform
Ripple Prime Takes Wall Street 24/7 With Delta One Launch
Sandbox Bridge Exploit Drains 14.7M SAND From Vault