Key Takeaways
- An outdated Rain card contract vulnerability led to the theft of approximately $1.1 million from several Solana-based platforms
- Avici suffered $500,800 in losses impacting 1,685 cardholders; Tria experienced over $430,000 in damages affecting 636 users
- AVICI token plummeted 49% from its daily peak, reaching an all-time low of $0.217
- Hackers converted stolen stablecoins to SOL, transferred them to Ethereum, and laundered funds via Tornado Cash
- Avici and Tria have committed to full user reimbursement; Avici contacted the FBI regarding the incident
A security flaw in an obsolete smart contract has resulted in a $1.1 million theft targeting several Solana-based crypto card services, with neobanks Avici and Tria bearing the brunt of user losses.
According to Raināthe Visa principal member supplying the core stablecoin card infrastructureāits security monitoring detected the weakness in a legacy contract version. Rain promptly upgraded all platforms operating on the compromised version and confirmed no additional unauthorized transactions occurred.
The perpetrator leveraged the security gap by continuously submitting signed authorizations, granting themselves administrator privileges on individual card-collateral accounts before draining the funds.
Following the theft, the attacker converted the stablecoins to Solana, transferred assets to Ethereum, and obscured the trail using Tornado Cash mixing service.
Avici Suffers Largest Losses
Avici, a self-custody neobank enabling crypto spending through Visa-integrated credit cards, disclosed $500,800 in stolen funds affecting 1,685 account holders.
According to the platform, the breach was confined to a specific Solana contract holding customer funds deposited for card top-ups. User-controlled wallets on Solana and Ethereum-based networks remained secure.
Avici committed to reimbursing all compromised card balances in full. The company has submitted a formal complaint to the FBI’s Internet Crime Complaint Center. Details regarding reimbursement timelines and funding mechanisms remain undisclosed.
Following the breach, AVICI token value collapsed 49% from a 24-hour peak of $0.43 to an unprecedented low of $0.217 before partially rebounding to approximately $0.378.

Tria Confirms Losses, Pledges Complete Restitution
Tria, another neobank utilizing Rain’s infrastructure, confirmed 636 users were compromised, resulting in losses exceeding $430,000.
Tria announced plans for complete user compensation. The platform’s native token also declined, experiencing a temporary drop of over 10% following the breach announcement.
Neither platform has identified additional affected Rain-powered services, and the comprehensive loss figure across all impacted platforms remains unclear.
The discrepancy between the $1.1 million tracked through blockchain analysis and Avici’s confirmed losses indicates additional Rain-integrated platforms likely suffered breaches as well.
Industry Context and Implications
This security incident occurs amid rapid expansion in crypto card adoption. Monitored crypto-card transaction volume surged over 300% to reach $1.04 billion in July, with stablecoins accounting for 70% of more than 10 million transactions.
The breach underscores a critical custody distinction for crypto card users. While funds maintained in Avici’s self-custody wallets remained protected, capital loaded onto cards transferred into third-party contract infrastructureāthe precise location where the vulnerability was exploited.
Avici’s service agreement designates Third National as the card issuer, with Rain functioning as the underlying infrastructure provider.





