Loading live crypto market…
BREAKING

$1.1 Million Crypto Card Exploit Sends AVICI Token Down 49%

A vulnerability in an outdated Rain card contract led to roughly $1.1 million in losses across Solana-based crypto card programs. Avici reported about $500,800 affected across 1,685 users, while its AVICI token plunged as much as 49%. Avici says affected card balances will be refunded.

Crypto card exploit drains $1.1 million as AVICI token drops 49%
⚡ QUICK TAKE

A vulnerability in an outdated Rain card contract led to roughly $1.1 million in losses across Solana-based crypto card programs. Avici reported about $500,800 affected across 1,685 users, while its AVICI token plunged as much as 49%. Avici says affected card balances will be refunded.

A security flaw connected to an older version of Rain’s crypto-card contract has resulted in roughly $1.1 million being drained from multiple Solana-based programs.

One of the biggest affected platforms was Avici, a self-custodial crypto neobank that allows customers to spend crypto using a Visa-integrated card.

💰 1,685 Avici Users Affected

According to Avici, approximately $500,800 belonging to 1,685 users was affected.

The incident quickly hit the AVICI token.

AVICI dropped from a 24-hour high of approximately $0.43 to $0.217, representing a fall of around 49% and a new record low.

The token later recovered part of the decline, trading around $0.378 at the time of the original report.

⚠️ What Was Actually Hacked?

An important detail is that the attack reportedly did not compromise Avici users’ main self-custodial wallets.

The problem was connected to a Solana contract where funds were held after customers loaded money onto their crypto cards.

According to the companies, Avici's self-custodial wallets on Solana and Ethereum-compatible networks were not affected.

Avici has said that affected card balances will be refunded.

🔐 How Did the Attack Happen?

On-chain transaction analysis indicated that the attacker was able to repeatedly use a signed authorization to gain administrative access to individual card-collateral accounts.

Once that access was obtained, funds could be withdrawn from those accounts.

Rain later said the vulnerability existed in an outdated contract version being used by Avici and a small number of other programs.

Rain said the affected contract version was upgraded and that it had not observed further unauthorized activity afterward.

💸 Where Did the Stolen Crypto Go?

The stolen stablecoins were reportedly converted into SOL, moved from Solana to Ethereum and eventually sent through Tornado Cash, a crypto mixer.

That movement can make tracing the final destination of the funds considerably more difficult.

🏦 Avici Wasn't the Only Platform Hit

Another crypto neobank, Tria, reported that 636 users were affected, with losses exceeding $430,000.

Tria said it intends to reimburse affected customers completely.

Its own token also came under pressure following the incident, falling by more than 10% at one stage.

The combined on-chain losses were estimated at around $1.1 million, suggesting additional Rain-powered programs may have been affected beyond the losses publicly reported by Avici and Tria.

💳 An Important Lesson for Crypto Card Users

The incident highlights an important difference between holding crypto in a self-custodial wallet and loading that crypto onto a payment card.

Users may control the assets inside their own wallets, but once funds are transferred into infrastructure used to operate a card, those funds can interact with separate third-party smart contracts.

That means a wallet itself can remain secure while money placed into the card system is exposed to a vulnerability elsewhere in the infrastructure.

This issue is becoming increasingly important as crypto cards become more widely used for everyday payments.

🔎 What Happens Next?

Avici said it has reported the incident to the FBI's Internet Crime Complaint Center and promised to refund affected card balances.

However, at the time of the report, details about when those refunds will be completed and exactly how they will be funded had not been announced.

The immediate exploit appears to have been addressed, but the incident raises a bigger question for the growing crypto-card industry:

How secure are the third-party contracts holding crypto after users move funds out of their self-custodial wallets and into card balances?

🚨 The wallet may be self-custodial, but that doesn't necessarily mean every part of the payment system is.
KEEP READING

Related stories