A Solana-based exploit tied to an outdated Rain contract drained about $1.1 million across several programs, with Avici users accounting for $500,800 of the total loss. The incident triggered a sharp sell-off in Avici’s token, which fell 49% from its 24-hour high to a record low of $0.217 before recovering to $0.305.

Avici said the breach was limited to contracts used to hold funds after customers loaded money onto their payment cards. The company said its self-custodial wallets on Solana and Ethereum-compatible networks were not affected and that all impacted card balances will be fully refunded.

Attack centered on card-funding contracts

According to Avici, the attacker did not compromise its core self-custodial wallet infrastructure. Instead, the exploit hit a Solana contract used in the card-funding flow, where customer funds were held after a card top-up and before spending.

Rain, the card infrastructure provider involved, said its monitoring systems identified a vulnerability in an outdated version of a contract used by Avici and a small number of other programs. The company said it upgraded every program still running that version and reported no additional unauthorized activity afterward.

On-chain trail points to broader impact

Blockchain transaction data indicate the attacker repeatedly reused a signed authorization, inserted itself as an administrator on individual card-collateral accounts, and then withdrew the balances. The stolen stablecoins were later exchanged into SOL, bridged to Ethereum, and ultimately sent through the crypto mixer Tornado Cash.

While Avici disclosed losses of $500,800 affecting 1,685 users, on-chain tracing suggests the total exploited amount was closer to $1.1 million. That gap indicates other Rain-powered programs were also affected, although neither Rain nor Avici identified those programs or detailed how much each one lost.

Token price fell as users assessed the breach

The market reaction was immediate. AVICI slid 49% from its 24-hour peak as news of the exploit spread, touching an all-time low of $0.217 before rebounding to $0.305.

The drop came even though Avici said the incident was confined to card-funding contracts rather than user-controlled wallets. The episode nevertheless highlighted operational risk around services that combine self-custody with third-party payment rails.

Custody handoff draws attention

The breach underscored a less visible part of some crypto card products: funds may begin in a self-custodial wallet, but once loaded for card spending they can move into infrastructure managed through a separate contract. In this case, that transition point appears to have been where the vulnerability was exposed.

The distinction matters more as crypto card usage grows. Tracked spending on crypto cards more than tripled to $1.04 billion in July, with stablecoins funding 70% of more than 10 million transactions. As these products scale, the security of card-loading and settlement infrastructure is likely to draw closer scrutiny.

Refunds promised, timeline still unclear

Avici said it has filed a report with the FBI’s Internet Crime Complaint Center and has committed to making affected users whole. The company has not said when refunds will be issued or how they will be financed.

For now, the confirmed next steps are limited: Rain says the outdated contract version has been upgraded across affected programs, and Avici says reimbursements are coming for impacted card balances. Further details on the other affected programs and the full loss distribution have not been disclosed.

Source: www.coindesk.com