Crypto card infrastructure provider Rain has identified a critical vulnerability in an outdated version of its Solana card contracts, leading to unauthorized withdrawals that affected 1,685 users of crypto neobank Avici and exposed $500,859.22 in customer card balances. The incident, which occurred on August 28, 2026, sent the associated neobank token crashing 49%.
The exploit targeted a specific function in Rain's contract authorization process rather than compromising the Solana network itself or stealing users' private keys. On-chain analysis shows the attacker repeatedly called functions including SubmitSignatures, AddCollateralAdmin, and WithdrawCollateralAsset, ultimately gaining administrative control over collateral accounts. With that authority, the attacker systematically drained funds from individual card-balance accounts.
Blockchain monitoring firm CertiK tracked the attacker transferring 10,000 SOL before converting approximately $1.02 million into USDC and moving value toward Ethereum. However, those larger on-chain totals reflect that the vulnerable Rain contract version was also deployed across multiple programs, not just Avici. Security firm Tria separately reported 636 affected users and approximately $431,945 in impacted balances.
Avici stressed that its regular Solana and EVM wallets remain self-custodial and were not breached. Users only became vulnerable after manually moving assets into a separate smart contract used to fund their cards — a distinction that limited the damage but underscores the structural risk when custodial payment rails are layered atop self-custody.
Rain has committed to making all affected customers whole, and Avici confirmed that Rain funded the reimbursements, with all affected balances restored. Avici additionally credited impacted users with a 10% cashback on withdrawn amounts and filed a report with the FBI's Internet Crime Complaint Center. A complete technical postmortem is expected after the forensic investigation concludes.
The incident highlights an increasingly important security boundary in crypto-linked payment cards: a product can advertise self-custody while still requiring users to transfer assets into shared smart contracts before funds become spendable. In this case, the separation between wallets and card balances contained the damage, but the shared infrastructure vulnerability across multiple applications demonstrates the counterparty risk inherent in custodial payment rails built around Bitcoin and other digital assets.