$1.1 Million Crypto Card Exploit Drives Avici Token Down 49%
Key Takeaways
- •An outdated Rain card contract was exploited to seize administrative control of card-collateral accounts and withdraw roughly $1.1 million across several Solana-based programs.
- •Avici reported approximately $500,800 stolen from 1,685 users, while Tria disclosed losses exceeding $430,000 affecting 636 users; both firms pledged full reimbursement without specifying a timetable.
- •The breach affected only funds held for card spending, leaving users' self-custodied primary wallets untouched.
- •Rain upgraded the vulnerable contract version and reported no additional unauthorized activity after the patches.
- •The stolen funds were converted to SOL and routed through the sanctioned mixer Tornado Cash, and the total traced on-chain exceeds disclosed losses, indicating other programs may have been affected.

A security exploit in crypto card infrastructure drained roughly $1.1 million from several Solana-based programs, triggering a sharp sell-off in Avici's AVICI token. The token dropped as much as 49%, falling from a 24-hour high of about $0.43 to a record low near $0.217 before partially recovering.
The incident has renewed concerns about security risks in crypto payment infrastructure, particularly in self-custody systems that rely on third-party contracts to process card spending. It also highlights a broader structural issue in the sector: when many platforms depend on the same underlying vendor or contract template, a single vulnerability can propagate losses across multiple companies at once, similar to how shared smart contract libraries have amplified past exploits across otherwise unrelated protocols.
Card Contract Exploit Triggers Losses
The attack targeted an outdated Rain card contract used by Avici and other programs. The vulnerability enabled the attacker to gain administrative control over individual card-collateral accounts and withdraw their balances.
Avici said approximately $500,800 was taken from 1,685 users. According to the company, the breach affected funds held for card spending, while users' self-custodied wallets remained unaffected. That distinction matters because it defines the practical boundary of user exposure: assets left in the primary wallet were untouched, while funds moved into the card-spending system were not.
Another crypto neobank, Tria, reported losses exceeding $430,000 involving 636 users. Its token also fell more than 10% following the incident.
Both Avici and Tria pledged to fully reimburse affected users, though neither company has disclosed a final timetable for the repayments. Whether those reimbursements are completed, and how quickly, is likely to shape user trust in both platforms going forward.
Rain Patches Vulnerable Contracts
Rain said it identified the issue in an outdated version of its card contract and upgraded programs still running the affected version. The company reported no additional unauthorized activity after the upgrades.
Blockchain transaction data showed that the stolen stablecoins were converted into Solana's SOL, moved across networks, and eventually sent through Tornado Cash, a cryptocurrency mixing service that was sanctioned by the U.S. Treasury's Office of Foreign Assets Control in 2022. Routing funds through mixers is a common laundering step in crypto thefts because it obscures the on-chain trail.
The roughly $1.1 million traced on-chain exceeds the losses disclosed by Avici and Tria, suggesting other programs using the same infrastructure may also have been affected, although their identities and losses remain undisclosed. That gap leaves open the possibility of further disclosures as on-chain analysts continue tracing the funds.
The incident underscores a key risk for crypto card users: even when customers control their primary wallets, funds transferred into payment systems can fall under separate third-party smart contracts. It also illustrates the dependencies that emerge as crypto neobanks build spending products on shared contract infrastructure, where patching outdated versions across all downstream users becomes the vendor's responsibility.
Avici said it reported the incident to the FBI's Internet Crime Complaint Center. The breach comes as crypto card usage expands, raising the importance of security controls across the payment infrastructure supporting digital assets.