$1.1 Million Crypto Card Hack Sent Neobank Token Down 49%
Key Takeaways
- •A vulnerability in an outdated Rain card contract led to the theft of approximately $1.1 million across multiple Solana-based programs.
- •Avici lost $500,800 from 1,685 users and saw its AVICI token drop as much as 49%, while Tria reported over $430,000 in losses affecting 636 users.
- •Both Avici and Tria committed to refunding affected users, and Avici filed a report with the FBI's Internet Crime Complaint Center.
- •The attacker gained administrator access to card-collateral accounts, withdrew stablecoins, swapped them into SOL, bridged to Ethereum, and routed funds through sanctioned mixer Tornado Cash.
- •Rain identified and upgraded the outdated contract version across all programs using it and reported no further unauthorized activity.

A vulnerability in an outdated Rain card contract drained roughly $1.1 million across several Solana-based programs, including $500,800 from 1,685 Avici users, sending the neobank's AVICI token down as much as 49%.
AVICI, a self-custodial neobank that lets users spend crypto through a Visa-integrated credit card, fell from a 24-hour high of $0.43 to a record low of $0.217 before recovering to around $0.378 at the time of writing.
Tria, another crypto neobank, reported that 636 of its users were affected, with losses totaling more than $430,000. The company vowed to repay users in full, even as its token at one point dropped more than 10%.
Avici said the attack was confined to a Solana contract holding funds after customers topped up their cards. Its self-custodial wallets on Solana and Ethereum-compatible networks were unaffected, and the company said every affected card balance would be refunded.
Rain said its monitoring identified the vulnerability in an outdated contract version used by Avici and a small number of other programs. It upgraded every program running that version and reported no further unauthorized activity.
According to Avici's terms, Third National is the card issuer, while Rain, a Visa principal member, provides the underlying stablecoin card infrastructure.
Transaction data show the attacker repeatedly submitted a signed authorization, added itself as an administrator to individual card-collateral accounts, and withdrew the balances. The stolen stablecoins were swapped into solana (SOL), bridged to Ethereum, and ultimately sent through the crypto mixer Tornado Cash, a protocol the U.S. Treasury Department sanctioned in 2022 for its use in laundering stolen funds, which typically complicates both tracing and recovery.
The gap between the roughly $1.1 million traced onchain and Avici's reported loss indicates that other Rain-powered programs were also hit. Neither company has identified those programs or disclosed the total amount each lost.
The incident highlights the custody handoff that underlies some self-custodial crypto cards: while users controlled money held in Avici wallets, funds loaded for spending moved into a third-party contract. Smart-contract exploits of this kind—where a flaw in shared infrastructure affects multiple dependent programs at once—are a recurring pattern across crypto, and third-party infrastructure dependencies mean a single outdated contract version can expose customers of several services simultaneously.
That distinction is becoming more significant as tracked crypto-card spending more than tripled to $1.04 billion in July, with stablecoins funding 70% of more than 10 million transactions. As more consumer funds flow through intermediary contracts rather than user-controlled wallets, the incident points to questions buyers can watch for: whether card programs disclose their custody architecture, contract audit practices, and refund timelines for compromised balances.
Avici said it filed a report with the Federal Bureau of Investigation's Internet Crime Complaint Center. It has not said when the refunds will arrive or how they will be funded.
Source: CoinDesk