
Outdated Rain card contract exploit drains $1.1M and knocks AVICI down 49%
Avici says $500,800 was taken from 1,685 users’ card-funding balances, with refunds promised but no timeline given.
An attacker exploited a vulnerability in an outdated Rain card-funding contract on Solana, draining roughly $1.1 million across multiple programs on Aug. 29. Avici disclosed $500,800 in losses across 1,685 users and saw its AVICI token drop as much as 49% before a partial rebound as repayment pledges arrived without a stated schedule.
Key Takeaways
- A vulnerability in an outdated Rain card contract on Solana was exploited, draining roughly $1.1 million across multiple Rain-powered programs.
- Avici disclosed $500,800 stolen from 1,685 users and said the breach was confined to card-funding contracts rather than users’ self-custodial wallets.
- AVICI traded from a 24-hour high of $0.43 down to a record low of $0.217, a 49% drawdown, before bouncing to levels described as roughly $0.305 and around $0.378.
- Tria reported 636 users affected with losses totaling more than $430,000 and pledged full repayment as its token fell more than 10% at one point.
Outdated Rain Card Contract Exploit Triggers AVICI’s 49% Drawdown
A Solana exploit tied to an outdated Rain card contract turned into a token-level risk event in hours. Roughly $1.1 million was drained across several programs using the same card infrastructure, with Avici and Tria the only two programs that publicly quantified user impact.
Avici put its number at $500,800 stolen from 1,685 users. The market response was immediate. AVICI sold off from a 24-hour high of $0.43 to a record low of $0.217, a 49% drawdown, before rebounding.
The rebound print is messy. One reference point places the post-low bounce at $0.305, while another places it around $0.378 at the time of writing. That discrepancy matters less than the structure of the move: the token traded like a proxy for infrastructure trust, not like a contained incident with a clean perimeter.
Tria, another crypto neobank running a Rain-powered card setup, said 636 users were affected with losses totaling more than $430,000. It pledged to repay users in full even as its token fell more than 10% at one point.
Rain said its monitoring identified the vulnerability in an outdated contract version used by Avici and “a small number of other programs.” Rain said it upgraded every program running that version and reported no further unauthorized activity.
What Was Drained: Card-Funding Contracts vs. ‘Self-Custodial’ Wallets
The critical distinction in this incident is where the funds sat at the moment of compromise. Avici describes itself as a self-custodial neobank, but the card top-up flow creates a custody handoff that traders should model separately from wallet security.
Avici said the attack was confined to a Solana contract holding funds after customers topped up their cards. It said users’ self-custodial wallets on Solana and Ethereum-compatible networks were not affected. In other words, the breach targeted the spending balance layer, not the user-controlled wallet layer.
This is the part that tends to get mispriced. “Self-custodial” can be true for the wallet product while still being irrelevant for the card product, because card spending needs a programmatic pool of stablecoins that can be debited, authorized, and settled. That pool is a smart contract surface area, and here it was the surface area that failed.
The counterparties are also not abstract. Avici’s card terms identify Third National as the card issuer. Rain, described as a Visa principal member, provides the underlying stablecoin card infrastructure. That stack is what makes the card work. It is also what concentrates operational and smart-contract risk into a shared dependency.
The second-order effect is straightforward: once a shared rail is perceived as brittle, every token tied to programs on that rail inherits some of the risk premium, even if its own app-level wallet custody is intact.
How the Attacker Took Control and Where the Funds Went
The exploit pattern described in transaction data is operationally scalable, which helps explain why multiple programs were hit rather than a single isolated pool.
The attacker repeatedly submitted a signed authorization, added itself as an administrator to individual card-collateral accounts, and withdrew balances. That sequence implies the attacker did not need to brute force each account from scratch. It could reuse an authorization flow to escalate privileges account by account, then drain.
After extraction, the funds path followed a familiar playbook designed to reduce traceability and increase optionality. The stolen stablecoins were swapped into SOL, bridged to Ethereum, and ultimately routed through Tornado Cash.
Two implications follow. First, the SOL leg suggests the attacker optimized for liquidity and speed on Solana before moving cross-chain. Second, the bridge to Ethereum and Tornado Cash routing signals intent to obscure the trail rather than immediately cash out through a single venue.
Rain said it upgraded every program running the outdated contract version and saw no further unauthorized activity. That is the containment claim. What remains unknown is whether any other deployments or adjacent contracts share similar authorization or admin-assignment patterns that could be abused under different conditions.
Refund Promises, Unknown Exposure, and the Crypto-Card Growth Backdrop
Refund pledges are doing the sentiment work right now, but execution details are the real catalyst. Avici pledged full refunds for all affected card balances and said it filed a report with the FBI’s Internet Crime Complaint Center. It did not say when refunds would arrive or how they would be funded.
The gap between the roughly $1.1 million traced on-chain and Avici’s $500,800 disclosure implies other Rain-powered programs were also hit. Rain said a “small number” of other programs were affected, but neither Rain nor the impacted programs identified the full list or disclosed per-program loss totals beyond Avici and Tria.
That uncertainty is not academic for traders. If additional programs disclose losses, the market will reprice the incident from “two affected apps” to “shared rail failure,” and the discount rate on any token tied to that rail tends to widen.
The backdrop is growth. Tracked crypto-card spending more than tripled to $1.04 billion in July, with stablecoins funding 70% of more than 10 million transactions. More volume means more balances sitting in card-collateral contracts, and more incentive for attackers to hunt for outdated deployments and permissioning mistakes.
Near-term, four signals matter more than narratives:
Avici needs to publish refund timing and the funding source, whether that is treasury, insurance, partner support, or another mechanism. Without that, the promise reads as intent, not settlement.
Rain needs to make remediation legible. “Upgraded every program running that version” is a claim that traders will want corroborated by clear contract-version mapping and confirmation that no outdated deployments remain live.
The market also needs the missing exposure map. Identifying the other affected programs and their loss totals is the difference between a one-off headline and a systemic repricing of crypto-card rails.
Finally, the on-chain trail is still a live variable even after Tornado Cash routing. Any clustering or linkage to known entities would change the probability of recovery, and it would also change how counterparties price the risk of future attempts.
My Read: This Is Infrastructure Risk Showing Up as Token Volatility
I read the AVICI move as the market pricing a shared-dependency failure, not a one-app mishap. The numbers support that framing. Roughly $1.1 million drained across multiple programs is not a “user got phished” story. It is a rail-level exploit that happened to express itself through smaller-cap tokens with thin liquidity.
The threshold that matters is not the bounce from $0.217. It is whether Avici can turn “full refunds” into dated, funded repayments. If Avici publishes a clear schedule and a credible funding source, the overhang compresses and the token can trade back toward app-specific fundamentals rather than platform trust. If the timeline stays open-ended, the token keeps wearing a financing discount because the liability is real even if the wallet layer was untouched.
There is also a second threshold sitting behind Rain’s remediation statement. If Rain’s “upgraded every program running that version” holds up and no additional programs surface with meaningful losses, the incident stays bounded and the market can treat it as a legacy-deployment failure. If more programs disclose losses, or if another outdated deployment is found, the story shifts from “outdated contract” to “process control,” and that is when the risk premium becomes structural.
The exploit mechanics point to scale. Reusing a signed authorization to add admin rights across many card-collateral accounts is the kind of pattern that turns a bug into a sweep. That is why the identity of the other affected programs matters. It tells you whether this was opportunistic scanning that found a few soft targets, or a repeatable method applied across a broader surface.
The practical confirmation point is simple: refunds with dates and funding, plus a complete accounting of affected programs, would turn this back into an isolated incident. Without those two disclosures, AVICI’s volatility is the market’s way of pricing infrastructure uncertainty into a token that cannot escape its dependencies.