Avici to fully refund users after Solana card contract vulnerability affects 1,685 accounts
Key Takeaways
- •Avici said a vulnerability in a Solana card contract affected $500,859.22 in card balances.
- •The company said 1,685 users were impacted and every affected user will receive a full refund.
- •Rain, Avici’s card issuing partner, identified the vulnerability earlier Friday.
- •Avici said its self-custodial Solana and EVM wallets remained under users’ control and were not affected.
- •The company said the contract has been upgraded across affected programs and no further unauthorized activity has been observed.

Avici said it will fully refund users affected by a vulnerability in a Solana card contract that impacted $500,859.22 in card balances.
The company said its card issuing partner Rain identified the vulnerability earlier Friday in a version of a Solana card contract used by Avici and a small number of other programs.
The contract has since been upgraded across all affected programs, with no further unauthorized activity observed.
According to Avici, 1,685 users were affected. The company said every affected user will receive a full refund of their card balance.
Avici said its wallets and card balances operate separately. Its Solana and EVM wallets are self custodial and remained under users’ control throughout the incident.
Funds moved into a separate Solana contract when users topped up their cards, and Avici said only that contract was affected. That separation is relevant because it limits the incident to card balances rather than the broader self-custodial wallets users held on the platform.
The company said it remains in contact with its card issuing and security partners while monitoring the remediation. Avici has also filed a report with the FBI’s Internet Crime Complaint Center, underscoring the incident’s security and incident-response dimension as card-issuing infrastructure continues to be a point of focus across crypto-linked payment products.