Crypto neobank Avici has completed full refunds for all 1,685 users affected by a recent security incident. This crypto card vulnerability drained approximately $500,859.20 to $500,859.22 from their card balances. The breach stemmed from an outdated Solana contract managed by Rain, Avici’s card-issuing partner, with refunds fully processed by August 30, 2026.
The incident, which also impacted 636 users of crypto bank Tria, highlighted persistent security challenges within the expanding digital asset sector. While Avici’s self-custodial Solana and EVM wallets were not affected, only the separate Solana contract holding card balances was compromised. Rain, headquartered in New York City, has since confirmed the underlying vulnerability is resolved.
Swift Resolution After Critical Crypto Card Vulnerability
Avici moved quickly to address the exploit and reassure its user base. The company’s first public statement on August 29, 2026, at 18:42 UTC, confirmed an issue affecting card balance withdrawals. This rapid communication aimed to restore confidence and mitigate user concerns.
Rain, a major crypto card infrastructure provider, confirmed the vulnerability lay in an outdated version of its Solana card contract. The firm clarified that only a “small number of programs” using these older versions were affected. This delineation helped define the scope of the problem.
The total financial impact from the breach was substantial, reaching approximately $1.1 million across all affected programs, including Avici and Tria. Such events underscore the continuous need for robust security frameworks within the rapidly evolving crypto card landscape. This incident provides a stark lesson for the industry.
Understanding the Exploit Mechanics
The attackers exploited a critical flaw that granted them unauthorized administrative privileges. This access allowed them to manipulate users’ card collateral accounts directly. The method involved a precise sequence of on-chain actions to exfiltrate funds.
Specifically, the attacker repeatedly called SubmitSignatures on Avici’s authorization program. They then used AddCollateralAdmin on its collateral program, effectively gaining control over the assets. Finally, WithdrawCollateralAsset calls were made to pull funds.
This technical exploit demonstrates the complex attack vectors present in decentralized finance. The vulnerability was not in Avici’s core self-custodial wallets, but rather in the interface connecting these assets to card spending. This distinction is crucial for understanding asset security layers.
Impact on Affected Programs and Market Dynamics
The crypto card vulnerability extended beyond just Avici users, impacting other programs leveraging Rain’s services. Crypto bank Tria also reported significant losses from the breach. The full extent of the affected parties and financial impact is detailed below.
Rain’s infrastructure powers most crypto cards, emphasizing its central role in the market. This widespread reliance means that a vulnerability in its system carried potential systemic risks across the entire industry. The incident raises serious questions about single points of failure in an otherwise diverse ecosystem. Indeed, vulnerabilities have been confirmed in other significant blockchain projects recently.
Ensuring Future Security and Industry Resilience
The rapid and full repayment by Avici and Rain serves as a vital step in maintaining user confidence. Such actions are crucial for the broader vision of bridging digital assets with everyday transactions. Avici Inc. is registered in San Francisco, while Rain is headquartered in New York City.
However, this incident also provides a stark reminder of the continuous need for rigorous security audits and prompt patch deployment. As more users adopt crypto cards for daily spending, the stakes for preventing similar exploits grow significantly. The industry must learn from such events.
The market requires continuous innovation in security protocols to safeguard user funds effectively. This particular breach emphasized that even established services can face unexpected challenges. Efforts to enhance SEC custody rule changes may influence future operational standards for crypto service providers. Protecting assets remains paramount for sustained growth in the altcoin sector.
