Immediate Market Impact
The most recent confirmed fact is that a Solana crypto card hack siphoned roughly $1.1 million from card-funding contracts used by several crypto neobanks. Avici, the self-custodial neobank that issues a Visa-integrated crypto card, saw its native AVICI token plunge 49% from a 24-hour high of $0.43 to a record low of $0.217 before modestly recovering to $0.305. The price shock was mirrored in Tria, another neobank, whose token fell more than 10% after losing over $430,000 affecting 636 users. Both firms have publicly committed to reimbursing every affected card balance, but the timeline for refunds remains unclear.
Technical Anatomy of the Exploit
Rain, a Visa principal member that supplies the underlying stablecoin card infrastructure, identified the vulnerability in an outdated version of its "Rain" smart contract. The contract, still in use by Avici and a handful of other programs, allowed an attacker to repeatedly submit a signed authorization, elevate itself to an administrator role on individual card-collateral accounts, and withdraw the stored stablecoin balances. Once withdrawn, the funds were converted to SOL, bridged to Ethereum, and funneled through the Tornado Cash mixer, obscuring the trail.
The on-chain forensic trace shows a discrepancy between the $1.1 million total moved and the $500,800 loss reported by Avici. This gap suggests that additional Rain-powered programs were compromised, though neither Rain nor the affected platforms have disclosed their identities or loss amounts.
Solana crypto card hack Overview
The incident highlights a systemic design flaw: the separation between user-controlled wallets and the custodial layer that processes card top-ups. While users retain full control over their self-custodial wallets on Solana and EVM-compatible networks, the card-top-up process deposits assets into a third-party contract managed by Rain. This handoff creates a single point of failure that can be exploited despite the “non-custodial” label presented to users.
Broader Market Context
Crypto-card spending has more than tripled to $1.04 billion in July, with stablecoins accounting for roughly 70% of over 10 million transactions. The rapid growth of this niche amplifies systemic risk: a single contract flaw can cascade across multiple platforms, eroding confidence in the broader ecosystem. The AVICI token’s 49% slide illustrates how on-chain vulnerabilities translate into immediate market volatility, affecting not only token holders but also liquidity providers and DeFi protocols that integrate neobank tokens.
Regulatory and Law-Enforcement Response
Avici filed an incident report with the FBI’s Internet Crime Complaint Center (IC3), signaling that the breach meets the threshold for federal investigation. While no charges have been announced, the involvement of a U.S. law-enforcement agency may set a precedent for future crypto-card incidents, potentially prompting tighter oversight of third-party contract providers.
Risk Mitigation for Users and Providers
For end-users, the primary safeguard is to limit the amount of capital allocated to card-funding contracts and to monitor on-chain activity via block explorers such as Etherscan. Providers should adopt a rigorous contract upgrade policy, retire legacy code promptly, and implement multi-signature governance for administrative functions. Continuous monitoring tools, like those offered by Rain, must be complemented by independent audits to detect privilege escalations before they can be abused.
Operational Changes Expected
Rain has already upgraded every program running the vulnerable contract version and reported no further unauthorized activity. Avici’s public commitment to full refunds suggests a short-term liquidity strain; the firm may need to tap reserve funds or external capital to honor the reimbursements. In parallel, the neobank’s token may experience heightened volatility as investors reassess the risk profile of platforms that rely on third-party infrastructure.
What to Watch Next
- Refund Execution: The speed and source of Avici’s reimbursements will indicate the firm’s financial resilience.
- Further Contract Audits: Expect a wave of third-party audits across Solana-based card providers as the industry reacts to the exploit.
- Regulatory Signals: Any guidance from the SEC or FinCEN regarding custodial responsibilities for crypto-card issuers could reshape compliance requirements.
- Liquidity Shifts: Monitoring protocol liquidity stats on protocol liquidity stats will reveal whether AVICI and related tokens lose depth, potentially amplifying price swings.
Institutional Takeaway
The hack demonstrates that even “self-custodial” solutions can harbor hidden custodial layers that become attack vectors. As crypto-card usage scales, the industry must reconcile user-experience goals with robust security engineering. Stakeholders—users, developers, auditors, and regulators—should treat contract versioning and privilege management as core components of risk management, not optional afterthoughts.
Related coverage
- Dormant Bitcoin Wallets Rebalancing, Not Dumping
- Manchester Airports Group data breach exposes 8.9M travelers' details, operations unaffected
- Manchester Airports data breach: FulcrumSec claims 86 GB theft and its fallout