Rain Cards has confirmed it will refund users affected by an exploit involving an outdated Solana card contract, while Solana-based card program Avici disclosed that the incident affected 1,685 users and approximately $500,859.22 in card balances.
According to Avici’s August 28 announcement, the vulnerability was identified by its card-issuing partner Rain in a version of a Solana card contract used to hold user card balances. The affected contract has since been upgraded across all programs, and no further unauthorized activity has been observed after the fix. Avici stressed that the incident was confined to a single smart contract rather than user wallets. Self-custodial wallets on both Solana and EVM chains were not touched and remain under users’ control.
Avici said every affected user will have their card balance refunded in full and that it has filed a report with the FBI’s Internet Crime Complaint Center. The project did not provide a timeline for completing the refunds. The vulnerable contract version was also used by a small number of other programs, though those programs were not identified. The exploit is the latest in a series of security incidents across the Solana ecosystem, following broader warnings about Solana-adjacent infrastructure, including Rust supply-chain attack risks.