Crypto News

Avici and Rain Refund Users After Solana Contract Exploit Drains $500K in Card Balances

Aug 29, 2026 16:55 solana hack neobank rain avici
Avici and Rain Refund Users After Solana Contract Exploit Drains $500K in Card Balances

Outdated Solana Contract Used to Drain Card Balances

An attacker exploited a flaw in an outdated version of a Solana smart contract belonging to Rain, the card issuer behind Avici's Visa product, draining $500,859.22 from 1,685 users on Friday.

Both Avici and Rain have said every affected user will be refunded in full. Avici said its own self-custodial wallets were not touched; only the separate contract that holds user card balances was compromised.

What Happened on the Blockchain

  • The attacker's wallet moved more than the $500,859 figure — onchain records show it sent exactly 10,000 SOL (about $1.07 million at $106.62 per SOL) in one transfer at 19:02:45 UTC.
  • The wallet had been sitting idle for three hours after receiving 1.79 SOL bridged at 13:40 UTC, then began calling Rain's card contracts at 16:49:48 UTC.
  • It signed 14,672 transactions before going quiet, 2,344 of which failed.
  • The attack pattern repeated across users: register as an administrator on a victim's collateral account, then withdraw their balance.
  • The wallet was emptied by 19:26:34 UTC, supporting Rain's claim that more than one program ran the vulnerable contract.

How the Exploit Worked

Transaction logs show the attacker used a three-step pattern against each victim. First, it called SubmitSignatures on the authorization program along with Solana's Ed25519 signature-verification precompile. Then it called AddCollateralAdmin to register itself as an administrator on the user's collateral account. Finally, it called WithdrawCollateralAsset to move funds to its own wallet.

In one reviewed transaction, a single WithdrawCollateralAsset call moved 2,346.77 USDT from a user's collateral account. The attacker swapped stablecoins into SOL as it went, with one fill adding 209.76 SOL.

Both programs involved are upgradeable and share the same upgrade authority — a regular Solana account rather than a multisig wallet.

What Companies Are Saying

Rain said its monitoring systems found "a vulnerability impacting a small number of programs using an outdated version of our Solana contracts" and that it has upgraded every program running that version. It added that it has engaged third-party forensics experts and will work with law enforcement and regulatory authorities.

Avici filed a report with the FBI's Internet Crime Complaint Center and apologized for the inconvenience.

Timeline and Community Reaction

Avici's first public statement came at 18:42 UTC, about one hour and 53 minutes after the first drain transaction. Users had been posting about missing balances before the announcement. One user wrote at 18:44 UTC: "i just got drained of all my balance from my @avici acc," adding they were "waiting to hear from the project."

Unclear Details

Neither company has disclosed how long the outdated contract had been deployed, why the programs running it were not upgraded earlier, or how the attacker discovered the flaw.

Token Price Impact

The AVICI token dropped to $0.2175, down 49.4% over 24 hours, with a market capitalization of $2.84 million and $656,543 in 24-hour volume, according to CoinGecko. It set a record low on Friday, having previously reached $7.56 on November 26, 2025.

Background

Avici raised through MetaDAO in October 2025, capping its ICO at $3.5 million against $34,206,976 in commitments. The team refunded 89.8% of committed USDC and set an initial price of $0.35. The company is registered as Avici Inc. in San Francisco and did not name its team on its website.

Sources

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!