CASABLANCA, August 30, 2026
Avici said a vulnerability in an outdated Solana card contract affected 1,685 users and $500,859.22 in card balances, prompting the crypto-card platform and its issuer partner Rain to upgrade affected deployments and promise full refunds.
The disclosure narrows a fast-moving security story into a defined customer impact: Avici said its ordinary Solana and EVM wallets were not affected because card top-ups sat in a separate Solana contract. It said the affected balances would be refunded, while Rain said it had found the issue in an older contract version used by Avici and a small number of other programs.
DefiLlama’s hacks database records an Avici loss of $500,859 on Aug. 28 and classifies it as a Rust-based withdrawal-logic flaw. That agrees with Avici’s disclosed balance figure, but it is not a final total for every program that used the older Rain deployment or a forensic accounting of the attacker’s proceeds.
The incident gives the figures more practical weight than an ordinary token move. Avici’s official update says the company had identified 1,685 affected customers and had filed a report with the FBI’s Internet Crime Complaint Center. Rain had not published a public contract-by-contract loss table or technical post-mortem at the time of publication.
AVICI touched $0.2189 on Aug. 28, its listed all-time low, before a public market-data page showed the token near $0.2673, a $3.44 million market capitalization and roughly $1.19 million in 24-hour trading volume. Those figures describe the token market, not the amount owed to card users, according to CoinMarketCap’s AVICI page.
Solana
SOLAvici Says Card Top-Ups, Not Wallets, Were Affected
Avici describes its product as a self-custody credit-card service. Its product site says users can top up cards with crypto, while its incident notice drew a distinction between a user’s normal wallet and the balance transferred into the card contract for spending.
That distinction is central to the scope. Avici said the wallet funds remained under user control, while the separate Solana card-balance contract was affected. The company did not say that private keys or seed phrases were exposed, nor did it report a compromise of its Solana or EVM wallet software.
The update also does not support a claim that Solana’s base layer failed. The stated issue was a contract version used for card balances, a dependency that sat between the app’s self-custody wallet and a card top-up. Users should treat recovery messages, refund links and requests to sign a new transaction with caution until they can confirm them through Avici’s own application or official channels.
The split between a wallet and funds moved into a spending arrangement is a recurring risk boundary. Daily Crypto Briefs recently covered Trust Wallet’s AI portfolio features, where the disclosure centered on data reaching a service provider rather than custody of a user’s assets. In Avici’s case, the operational exposure was the distinct contract used after a card top-up.
Rain Upgrade and Refund Pledge Contain the Immediate Risk
Avici said Rain had upgraded the contract across programs using the outdated version and that no further unauthorized activity had been observed. It also said it remained in contact with card-issuing and security partners while monitoring the remediation.
The most consequential statement is the refund pledge. Avici said every affected user would have their card balance refunded in full, which shifts the immediate economic loss from individual cardholders to the companies handling remediation. It is not, however, the same as a recovery of the assets taken from the vulnerable contracts.
Rain’s acknowledgement that a small number of other programs used the older contract leaves an important limit on the current picture. Avici’s $500,859.22 and 1,685-user figures apply to Avici’s reconciliation. They should not be added to early, broader on-chain estimates without a published program-by-program accounting, because that could count balances outside Avici or transactions that are not final losses more than once.
The database entry offers a useful independent check, but not all the missing answers. DefiLlama lists a withdrawal-logic classification and a rounded amount; it does not establish the attacker identity, the exact transaction path, how many programs were affected, or whether every user has already received the promised credit.
This dependency risk has appeared in other forms across onchain financial products. The Gnosis Pay incident involving a Safe delay module concerned a different product and mechanism, but both episodes show that a service can advertise user-controlled wallets while a connected authorization or settlement component still requires separate security assumptions.
$500,859 Is the Confirmed Avici Scope, Not the Whole Incident
The dedicated loss-impact review found one directly confirmed Avici figure: $500,859.22 in card balances across 1,685 users, as stated by the company and reflected in the $500,859 DefiLlama entry. The project said affected users would be made whole. It did not disclose a final total of assets removed from all Rain programs, a count of every affected contract, an attacker address, or a recovery amount.
That is why early reports that discussed a higher attacker balance should be read as observation points rather than a replacement for Avici’s reconciliation. They may capture movements tied to more than one program, changing token prices, or funds that were later returned or otherwise accounted for. The public record so far supports the Avici-specific number more firmly than a single aggregate figure for the whole event.
SOL closed near $71.92 on Aug. 1 and traded around $105.18 in the Aug. 30 market-data reading, according to CoinLore’s historical table. The change in SOL’s price does not change the disclosed Avici balance total, which Avici quoted in dollars, but it can affect the valuation of any token conversions or later recovery efforts.
The broader market’s Crypto Fear and Greed Index registered 69, labeled Greed, on Aug. 30. That reading does not measure the safety of Avici’s card system or prove the remediation is complete.
Fear & Greed Index
Aug. 30, 2026The next useful update is not another moving headline estimate. It is a technical account from Rain or Avici that identifies the vulnerable deployment, explains why it remained active, reconciles losses across affected programs and confirms the timing and completion of every refund.
Stay up to date
Get the latest crypto insights delivered to your inbox
Primary sources and further reading
| Source | Title |
|---|---|
| | Avici: official incident update |
| | Avici: official product site |
| | DefiLlama: hacks and exploits database |
| | CoinMarketCap: Avici market data |
| | CoinLore: Solana historical data |
| | Alternative.me: Crypto Fear and Greed Index |
Fact-checked by: Daily Crypto Briefs Fact-Check Desk
Related Articles
Frequently Asked Questions
How much was lost in the Avici card-contract exploit?
Avici said its reconciliation found $500,859.22 in affected card balances across 1,685 users. DefiLlama lists the same rounded $500,859 amount. This is Avici's disclosed scope, not a confirmed total for every program that used the older Rain contract.
Were Avici wallets affected by the Solana card exploit?
Avici said its regular Solana and EVM wallets remained self-custodial and were not affected. The incident was limited to the separate Solana contract that held balances topped up for card spending.
Will Avici refund card users after the exploit?
Yes. Avici said every affected user will have their card balance refunded in full. Rain also said affected users would be made whole after it upgraded deployments using the outdated Solana contract.



