Solana-based card program Avici has disclosed that its card-issuing partner Rain identified a vulnerability in a version of a Solana card contract used to hold user card balances, an incident
A
AnonymousCryptoCompass newsroom
August 29, 2026
2 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for policy coverage.
Solana-based card program Avici has disclosed that its card-issuing partner Rain identified a vulnerability in a version of a Solana card contract used to hold user card balances, an incident the project described in an August 28 announcement. The affected contract has since been upgraded across all programs, and Avici said no further unauthorized activity has been observed after the fix.
What Was Affected
According to Avici, the incident was confined to a single smart contract rather than user wallets. When a user tops up a card, funds move into a separate Solana contract that holds the card balance, and only this contract was affected. Avici’s self-custodial wallets, which hold funds on both Solana and EVM chains, were not touched and remain under users’ control, the company said. The separation between card balances and self-custodial wallets kept the damage from spreading further, according to the project.
Scale of the Impact
Avici’s reconciliation shows 1,685 users were affected, representing $500,859.22 in card balances. The company noted the vulnerable contract version was also used by a small number of other programs, though it did not identify those programs or disclose whether they suffered losses. Avici did not specify how the vulnerability was exploited or how long it may have been present before Rain discovered it.
Refunds and Regulatory Report
Avici said every affected user will have their card balance refunded in full, and that it has filed a report with the FBI’s Internet Crime Complaint Center, the U.S. clearinghouse for cybercrime complaints. The company said it remains in close contact with its card-issuing and security partners and is monitoring the remediation closely, though it did not provide a timeline for completing the refunds.
A Recurring Solana Security Concern
The disclosure is the latest in a string of security incidents across the Solana ecosystem. Avici, which earlier launched virtual IBAN accounts on Solana, is among several card and payments projects building on the network. The episode follows broader warnings about Solana-adjacent infrastructure, including a Rust supply-chain attack that researchers said put Solana-adjacent build pipelines at risk. As card products increasingly hold funds in on-chain contracts, the incident underscores the security burden that falls on the issuers managing those contracts.
The proposed fund aims to deliver biweekly payouts using an options-based strategy tied to Zcash exposure. Grayscale has filed paperwork for a new exchange-traded fund named the ZCSH High Inc
The NFT marketplace says outdated smart contract approvals left $5.7 million in assets exposed, and has published a process for owners to reclaim rescued NFTs. Magic Eden has confirmed that a
Grayscale filed a registration statement with the U.S. Securities and Exchange Commission on September 25 to register the ZCSH High Income ETF, an actively managed fund designed to earn incom