Rain Solana Card Hack Drains $500K From Avici, Token Crashes 49%

2 hour ago 2 sources negative

Key takeaways:

  • Avici token's 49% crash shows markets price operational security failures beyond actual fund recoveries.
  • Self-custody narratives mislead when users must trust shared card contracts, creating hidden counterparty risk.
  • Cross-program exploit exposure implies other Rain-based issuers may face similar undisclosed vulnerabilities.

Crypto card infrastructure provider Rain has identified a critical vulnerability in an outdated version of its Solana card contracts, leading to unauthorized withdrawals that affected 1,685 users of crypto neobank Avici and exposed $500,859.22 in customer card balances. The incident, which occurred on August 28, 2026, sent the associated neobank token crashing 49%.

The exploit targeted a specific function in Rain's contract authorization process rather than compromising the Solana network itself or stealing users' private keys. On-chain analysis shows the attacker repeatedly called functions including SubmitSignatures, AddCollateralAdmin, and WithdrawCollateralAsset, ultimately gaining administrative control over collateral accounts. With that authority, the attacker systematically drained funds from individual card-balance accounts.

Blockchain monitoring firm CertiK tracked the attacker transferring 10,000 SOL before converting approximately $1.02 million into USDC and moving value toward Ethereum. However, those larger on-chain totals reflect that the vulnerable Rain contract version was also deployed across multiple programs, not just Avici. Security firm Tria separately reported 636 affected users and approximately $431,945 in impacted balances.

Avici stressed that its regular Solana and EVM wallets remain self-custodial and were not breached. Users only became vulnerable after manually moving assets into a separate smart contract used to fund their cards — a distinction that limited the damage but underscores the structural risk when custodial payment rails are layered atop self-custody.

Rain has committed to making all affected customers whole, and Avici confirmed that Rain funded the reimbursements, with all affected balances restored. Avici additionally credited impacted users with a 10% cashback on withdrawn amounts and filed a report with the FBI's Internet Crime Complaint Center. A complete technical postmortem is expected after the forensic investigation concludes.

The incident highlights an increasingly important security boundary in crypto-linked payment cards: a product can advertise self-custody while still requiring users to transfer assets into shared smart contracts before funds become spendable. In this case, the separation between wallets and card balances contained the damage, but the shared infrastructure vulnerability across multiple applications demonstrates the counterparty risk inherent in custodial payment rails built around Bitcoin and other digital assets.

Sources
Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.