Latest News

Rain Identifies Solana Card Contract Vulnerability…

Crypto card infrastructure provider Rain identified a vulnerability in an outdated version of its Solana card contracts after unauthorized withdrawals affected 1,685 users of crypto neobank Avici, exposing $500,859.22 in customer card balances. The incident occurred on August 28 and was confined to contracts used to hold funds transferred into Avici’s Solana card system.

Avici stressed that its regular Solana and EVM wallets are self-custodial and were not affected. Users only became exposed after manually moving assets from those wallets into a separate smart contract used to fund their cards. Rain said its monitoring systems discovered the vulnerability affecting a small number of programs still using an outdated version of its Solana contracts.All affected deployments have since been upgraded, and Rain said it observed no further unauthorized activity after the remediation.

Authorization Flaw Allowed Funds to Be Withdrawn

On-chain analysis indicates the attacker exploited the contract’s authorization process rather than compromising Solana itself or stealing users’ private keys. The attack involved repeated calls to functions including SubmitSignatures, AddCollateralAdmin and WithdrawCollateralAsset. Researchers examining the transactions found that the attacker could submit signatures and exploit a flaw in the verification process to obtain administrative authority over collateral accounts.

Once that authority was established, assets could be systematically withdrawn from individual card-balance accounts. The attacker reportedly began with less than $200 worth of funds used to establish the attack wallet and pay transaction costs. Early blockchain monitoring produced loss estimates above $1 million. CertiK, for example, tracked an attacker transferring 10,000 SOL before converting approximately $1.02 million into USDC and subsequently moving value toward Ethereum. Those figures should not be interpreted as Avici’s loss. Avici’s completed reconciliation identified exactly 1,685 affected customers representing $500,859.22. The larger on-chain totals reflect that the vulnerable Rain contract version was also used by other programs. Tria separately reported 636 affected users and approximately $431,945 in impacted balances.

Rain Reimburses Users as Investigation Continues

Rain committed to making all affected customers whole and engaged third-party forensic specialists while working with law enforcement and relevant regulators. Avici subsequently confirmed that Rain funded the reimbursements and that all affected Avici balances had been restored. Avici went further by crediting affected customers with an additional 10% cashback based on the amount withdrawn. The company said EVM card balances, swaps, onramps and offramps were unaffected alongside its self-custodial wallets. Avici also filed a report with the FBI’s Internet Crime Complaint Center and said a complete postmortem will be released after the investigation concludes. The incident highlights an increasingly important security boundary in crypto-linked payment cards.

A product can advertise self-custody while still requiring users to transfer assets into separate smart contracts before those funds become spendable through a card. At that point, the security model changes from protecting a user’s private keys to protecting the shared infrastructure governing card balances.In Avici’s case, deliberately separating wallets from card balances limited the damage. A compromise of the card infrastructure did not provide access to assets remaining in users’ self-custodial wallets.But the incident also exposed risks created when multiple consumer applications depend on common infrastructure supplied by a third-party card provider. Rain issues crypto-linked cards and provides payment infrastructure to multiple companies, meaning a vulnerability in a shared contract version can potentially affect several products simultaneously.

That appears to explain the difference between Avici’s $500,859 confirmed impact and the more than $1 million observed moving through attacker-controlled addresses. Rain says the outdated contracts have now been upgraded across every affected program. The remaining question is how the vulnerable authorization logic remained deployed and exploitable across multiple applications. Until Rain and Avici publish their full technical postmortems, that root cause remains unresolved — even though the immediate financial losses to affected Avici customers have now been reimbursed.

You may also like