BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

$1.1M Crypto Card Exploit Crashes AVICI Token 49% as Solana Contract Vulnerability Exposed

TLDR An exploited security flaw in a legacy Rain card smart contract resulted in approximately $1.1 million drained from various Solana-based platforms Avici suffered $500,800 in damages impa

AnonymousCryptoCompass newsroom
August 30, 2026
3 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for altcoins coverage.

TLDR

  • An exploited security flaw in a legacy Rain card smart contract resulted in approximately $1.1 million drained from various Solana-based platforms
  • Avici suffered $500,800 in damages impacting 1,685 cardholders; Tria experienced losses exceeding $430,000 affecting 636 users
  • AVICI token plummeted 49% from its daily peak, reaching an all-time low of $0.217
  • The stolen stablecoin funds were converted to SOL, transferred to Ethereum, and laundered via Tornado Cash
  • Avici and Tria have both committed to fully reimbursing impacted customers; Avici submitted a complaint to federal authorities

A security weakness in a deprecated smart contract has resulted in a $1.1 million theft targeting several Solana-based crypto card platforms, with neobanks Avici and Tria bearing the brunt of customer losses.

Rain, the infrastructure provider offering stablecoin card services as a Visa principal member, confirmed that its security monitoring identified the weakness in a legacy contract version. All platforms operating on the compromised version received immediate upgrades, with Rain confirming no subsequent malicious activity has been detected.

The perpetrator leveraged the security gap by continuously submitting signed authorizations, inserting themselves as administrators on individual card-collateral wallets, and extracting the funds.

Following the theft, the stablecoins were converted to Solana, transferred across the bridge to Ethereum, and subsequently routed through the Tornado Cash mixing service.

Avici Suffers Largest Losses

Avici, a self-custody neobank enabling users to spend cryptocurrency through a Visa-linked credit card, disclosed losses of $500,800 impacting 1,685 cardholders.

According to the platform, the breach was confined to a specific Solana smart contract housing funds deposited when customers loaded their card balances. User-controlled wallets on Solana and Ethereum-compatible chains remained secure and unaffected.

Avici committed to fully compensating all impacted card balances. Additionally, the firm submitted an official complaint to the FBI’s Internet Crime Complaint Center. Details regarding reimbursement timing and the capital source remain undisclosed.

Following the breach, the AVICI token collapsed 49% from its 24-hour peak of $0.43 to an unprecedented low of $0.217, later stabilizing around $0.378.

Avici PriceAvici Price

Tria Confirms Breach, Commits to Complete Restitution

Tria, another neobank utilizing Rain’s infrastructure, disclosed that 636 users were compromised, with aggregate losses surpassing $430,000.

Tria guaranteed complete reimbursement for affected customers. The platform’s native token also experienced volatility, declining over 10% temporarily after the incident became public.

Both companies have refrained from identifying additional affected platforms, and the comprehensive loss figure across all compromised services remains unclear.

The discrepancy between the $1.1 million tracked through blockchain analysis and Avici’s disclosed losses indicates that additional Rain-integrated platforms likely suffered breaches as well.

Industry Context

This security incident occurs amid rapid expansion in crypto card adoption. Monitored crypto-card transaction volume surged more than threefold to $1.04 billion in July, with stablecoins accounting for 70% of over 10 million transactions.

The exploit underscores a critical custody distinction for consumers. Assets stored in Avici’s self-custodial wallets remained protected, but funds transferred to card balances entered a third-party contract infrastructure where the vulnerability existed.

According to Avici’s service agreements, Third National functions as the official card issuer, with Rain supplying the underlying technological framework.

The post $1.1M Crypto Card Exploit Crashes AVICI Token 49% as Solana Contract Vulnerability Exposed appeared first on Blockonomi.