A significant vulnerability in an outdated smart contract has triggered a massive $1.1 million hack across several Solana-based crypto card programs, primarily affecting the neobanks Avici and Tria. The incident marks a troubling trend in the rapidly evolving landscape of digital finance, where security remains a top concern.
According to on-chain data, the breach saw a substantial amount of funds exiting card collateral accounts on the Solana platform, with the attacker exploiting a flaw to drain resources. Avici was hit the hardest, suffering losses of approximately $500,800 that impacted 1,685 users, while Tria reported over $430,000 in losses affecting 636 users.
The AVICI token has seen a drastic decline, plummeting 49% from a 24-hour high of $0.43 to a record low of $0.217, before making a slight recovery to around $0.378.
In a tweet alerting users, reports indicated that the attack involved the use of a cross-chain bridge to fund the attacker’s wallet, emphasizing the sophisticated methods employed in the breach. Following the incident, Rain, which provides the underlying infrastructure for these stablecoin card programs as a Visa principal member, stated that its monitoring systems had identified the flaw in the outdated contract version.
Rain swiftly upgraded all programs running that version and reassured users that no further unauthorized activity was detected. However, the damage had already been done. The attacker manipulated the vulnerability by repeatedly submitting a signed authorization that allowed them to add themselves as administrators to individual card-collateral accounts, thereby withdrawing balances at will.
Avici Takes the Brunt of the Attack
Avici, a self-custodial neobank enabling users to spend cryptocurrency via a Visa-integrated credit card, has committed to refunding every affected card balance. The company also reported the incident to the FBI’s Internet Crime Complaint Center, although no specific timeline or funding source for the refunds has been disclosed.
Importantly, Avici clarified that the attack was limited to a Solana contract holding funds after customers topped up their cards, and that self-custodial wallets on Solana and Ethereum-compatible networks remained unaffected.
Tria Also Affected
Similarly, Tria confirmed that 636 of its users were impacted, with losses exceeding $430,000. The company has also pledged to repay users in full, although its token experienced a decline of more than 10% following the news of the hack.
Neither Avici nor Tria has disclosed the names of other affected programs, and the total losses across all impacted platforms have not been fully accounted for. The discrepancy between the $1.1 million tracked on-chain and Avici’s reported figure suggests that additional Rain-powered programs may have also been compromised.
The Growing Context of Crypto Card Usage
This incident unfolds against the backdrop of rapidly increasing crypto card usage, which has surged over the past months, with spending exceeding $1.04 billion in July alone. Stablecoins accounted for 70% of over 10 million transactions, highlighting the growing reliance on digital currencies for everyday spending.
The hack serves as a stark reminder of the critical custody distinctions in the crypto realm. While funds held in Avici’s self-custodial wallets were safe, money loaded onto cards transitioned into a third-party contract, which ultimately became the target of the exploit. Avici’s terms identify Third National as the card issuer, with Rain providing the necessary infrastructure layer beneath it.
As the crypto landscape continues to evolve, incidents like this underscore the importance of security and due diligence for both service providers and users alike.
