Avici confirms Solana card contract flaw hit 1,685 users, pledges full refunds
Security & Exploits ·
The company said all affected card balances will be made whole after a vulnerability in its Solana-based card contracts was identified and patched.
Avici disclosed that 1,685 card users were exposed by the bug, with roughly $500,859 in card balances affected, according to details shared on X. The company said card partner Rain identified and patched the flaw, and that full refunds would be issued to every user whose funds were exposed.
The vulnerability sat in outdated Solana contracts underpinning Avici's card program rather than in a single user-facing app, meaning the exposure applied across the affected neobank-style card infrastructure rather than to isolated transactions. Coverage of the incident, reported by wublockchain.xyz, frames it within a broader pattern of Solana-linked contract issues surfacing in card and neobank integrations this period.
The Avici case follows a related disclosure from Rain itself, which said outdated Solana contracts had affected a small number of its neobank programs and that affected users would be compensated. The overlap between the two disclosures — Avici naming Rain as the party that identified and patched its own contract flaw — points to a shared underlying code dependency between the two card operations rather than two unconnected incidents.
Neither disclosure has detailed the technical root cause of the vulnerability, such as whether it involved access control, contract logic, or another class of flaw. It also remains unclear how many of the 1,685 affected users have received refunds to date, whether other card partners relying on the same outdated Solana contracts face similar exposure, and whether any funds were actually lost to an external actor or the flaw was patched before exploitation occurred.