Avici's Solana card contract vulnerability exposed 1,685 users and $500,859 in card balances; partner Rain identified and patched the flaw, with full refunds promised.
Security & Exploits ·
A vulnerability in a Solana card contract has exposed 1,685 users and approximately $500,859 in card balances. Avici's card-issuing partner Rain discovered the flaw in a version of the contract that was in use across Avici and a limited number of other programs. The affected contract was specific to card balance storage, while users' self-custodial assets on Solana and EVM chains remained unaffected.
Following identification, the contract was upgraded across all participating programs, and no additional unauthorized activity has been detected since the patch. Avici has committed to providing full refunds to all impacted users and has submitted a report to the FBI's Internet Crime Complaint Center.
The scope of the vulnerability—which programs beyond Avici were affected and the specific nature of the flaw itself—remains unclear from available disclosures. The timeline from discovery to remediation and the exact window during which the vulnerability was exploitable have not been detailed.