Solana-based neobank Avici will refund 1,685 users in full after an attacker exploited an outdated card contract supplied by its issuing partner Rain, draining $500,859.22 from customer card balances.
The final reconciliation came after early onchain estimates put the attack above $1 million as funds rapidly accumulated in attacker-controlled addresses. Avici’s self-custodial Solana and EVM wallets were not affected. The vulnerable infrastructure was the separate Solana contract holding balances that users had moved into the card system.
Outdated Rain Contract Allowed Unauthorized Withdrawals
Rain identified the vulnerability in an outdated version of its Solana contracts used by Avici and a small number of other programs. Every deployment still running the affected version has since been upgraded, with no further unauthorized activity detected after the fix.
The first identified malicious interaction reached Avici-related contracts at 16:49:48 UTC. The attacker repeatedly called SubmitSignatures, followed by AddCollateralAdmin and WithdrawCollateralAsset, creating a route to add administrative authority before removing assets from individual collateral accounts. The attacker address ultimately signed 14,672 transactions, including 2,344 failed attempts.
One reviewed transaction removed 2,346.77 USDT from a single collateral account. The wallet had initially received just 1.79 SOL through deBridge before beginning the attack, then converted portions of the extracted stablecoins into SOL as the drain continued.
The failure sits in the card infrastructure rather than Solana itself or Avici’s self-custodial wallet system. Users only became exposed after moving assets from their wallets into the separate contract used to maintain spendable card balances.
Avici Promises Full Refunds and Contacts FBI
Every affected card balance will be restored under Avici’s refund commitment. The company has also filed a report with the FBI’s Internet Crime Complaint Center and remains in contact with Rain and security partners while the transactions are reconciled.
Rain has brought in third-party forensic investigators and plans to work with law enforcement and relevant regulators. Its remediation covers all programs that were still using the vulnerable Solana contract version, rather than only the Avici deployment.
The separation between current and legacy contracts resembles June’s Raydium drain, where a logic flaw remained exploitable in deprecated Solana liquidity pools even though those pools had already disappeared from Raydium’s current interface.
Another Solana protocol, Allbridge Core, paused operations in July after a separate flash-loan attack manipulated stablecoin pool accounting and extracted more than $1 million.
AVICI Falls to Record Low During Drain
AVICI sold off sharply as users began sharing missing card balances and the attack remained active. The token fell to an all-time low near $0.219, roughly half its intraday high of $0.446, before recovering part of the decline.
AVICI was trading near $0.27 after the refund announcement, still down roughly 38% over 24 hours, with a market capitalization around $3.4 million and 24-hour trading volume near $1.2 million.


Be the first to comment