BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

Avici Confirms $500,859 Refund to 1,685 Users After Rain Contract Flaw

Avici says every one of the 1,685 users hit by a card balance exploit this week will get their money back in full. The Solana based neobank confirmed the refund late on August 28, after its c

AnonymousCryptoCompass newsroom
August 29, 2026
3 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for altcoins coverage.

Avici says every one of the 1,685 users hit by a card balance exploit this week will get their money back in full. The Solana based neobank confirmed the refund late on August 28, after its card issuing partner Rain traced the breach to an outdated version of a Solana smart contract. Rain, in its own statement posted hours after the attack began, said its monitoring systems found a vulnerability affecting “a small number of programs using an outdated version of our Solana contracts.” That detail matters more than it first looks. It means the flaw sat in shared infrastructure that other Rain powered card programs also relied on, not in code unique to Avici.

On chain activity backs that framing up. A wallet address, FVNFzq…QnCEj, funded with less than $200 through the cross chain bridge deBridge, ended up holding more than $1 million in SOL and stablecoins, according to on chain trackers, well above Avici’s own confirmed loss of $500,859.22. That gap is the real open question in this story. Rain has not said, and no on chain evidence independently confirms, exactly how much of that broader total came from programs other than Avici. One outlet has named Tria and Solayer Pay among roughly 22 Rain powered card programs that used the same outdated contract, but that reporting is not yet backed by a confirmed loss figure the way Avici’s number is.

The mechanism itself was not a stolen password or a leaked private key. Reporting on the exploit describes a signature verification bug: a check meant to confirm a second, separate authorization was instead pointed back at the first one, letting Solana’s runtime accept the attacker’s own signature as valid twice. That let the attacker register themselves as an administrator on user collateral accounts, then withdraw the funds directly, without ever needing a user’s private key.

Avici’s wallets themselves were not touched. The company says user wallets are self custodial and separate from card balances, and only the Solana contract that holds top up funds for card spending was exposed.

The token market reacted before either company finished its statement. AVICI fell 49.4% over 24 hours to $0.2175, a new all time low, cutting its market capitalization to roughly $2.84 million.

Avici says it has filed a report with the FBI’s Internet Crime Complaint Center and is continuing to work with Rain and its security partners on remediation. Whether any other Rain powered card program discloses a loss of its own is the detail worth watching next.