Highlights

  • Rain, Avici's card-issuing infrastructure partner, has identified a vulnerability in a Solana card contract affecting 1,685 Avici users and $500,859 in balances.
  • The flaw sits in a contract version also used by "a small number of other programs," per Rain's disclosure.
  • The disclosure follows an active exploit days earlier that drained over $1 million from Avici users via a chain of three contract calls.
  • Both of Avici's on-chain programs shared a single standard account for upgrade authority instead of a multisig — the root cause investigators pointed to.
  • The AVICI token fell 49.4% in 24 hours during the earlier attack, and the scope disclosure could reopen scrutiny of the token and the platform's security posture.

Rain, the stablecoin payment infrastructure provider that powers Avici's Visa- and Mastercard-linked card rails, has disclosed that a vulnerability in a version of its Solana card contract affected 1,685 Avici users and $500,859 in account balances. Wu Blockchain reported the disclosure, noting Avici confirmed the flawed contract version was also used by a small number of other programs beyond its own platform.

Rain Says Solana Card Bug Exposed 1,685 Avici Users, $500K
Image via @WuBlockchain on X

A Disclosure That Follows a Live Exploit

The scoping disclosure lands just over a week after Avici, a Solana-based crypto card and collateral platform, suffered an active attack that drained more than $1 million from user accounts. Investigators traced the exploit to a specific sequence: attackers called Avici's authorization program's SubmitSignatures function, then invoked the collateral program's AddCollateralAdmin, before executing WithdrawCollateralAsset to pull funds out — a chain on-chain analysts linked to roughly 125 distinct sender accounts, with individual transfers ranging from about $9 to more than $26,000. Avici took nearly two hours to publicly acknowledge the breach after the first theft was detected, and a separate wave of phishing sites impersonating the platform siphoned off more than $600,000 in a parallel scam during the same window.

Root Cause: Shared Upgrade Authority

The structural weakness investigators flagged was that both of Avici's on-chain programs were upgradable but shared the same standard Solana account for upgrade permissions, rather than routing changes through a multisig. That single point of control is what let an attacker escalate from a signature-submission call into direct withdrawal authority. Rain's newly disclosed figures — 1,685 affected users and $500,859 in balances — suggest the exposure window was broader than the roughly $1 million initially confirmed as stolen, encompassing accounts whose funds were put at risk even if not all were ultimately drained.

Market and Ecosystem Fallout

The AVICI token had already fallen 49.4% over 24 hours during the initial exploit, dropping to roughly $0.2175 with a market cap near $2.84 million — a level that leaves little room for confidence to rebuild quickly. Because Rain's infrastructure reportedly underpins card products beyond Avici alone, the disclosure raises a broader question for the Solana card-and-stablecoin niche: how many other issuers are running the same contract version, and whether shared-infrastructure risk of this kind needs its own audit standard separate from the app layer built on top of it.

What Comes Next

Avici and Rain have not indicated whether affected users will be made whole, or on what timeline a patched contract with multisig-gated upgrade authority will roll out across dependent programs. The next concrete marker to watch is whether other platforms built on the same Rain contract version confirm their own exposure, and whether Solana's broader card-infrastructure ecosystem moves toward mandatory multisig upgrade authority as a baseline security requirement following this incident.

Related: MANTRA's Post-Mortem: Aug 20 Exploit Moved 720.9M Tokens, No Keys Compromised