Smiley face
Weather     Live Markets

Outdated Rain Card Contract Exploit Drains $1.1M From Solana Neobanks, Sending AVICI Token Into a 49% Tailspin

The coordinated attack against shared card infrastructure exposed a major fault line in crypto banking — and left thousands of users waiting to see whether promised refunds will arrive.

A vulnerability in an outdated Rain card contract has siphoned roughly $1.1 million across several Solana-based programs, delivering a painful shock to one of the crypto industry’s most promising niches: the neobank. The heaviest blow landed on Avici, a self-custodial financial platform that lets users spend cryptocurrency through a Visa-integrated credit card. According to the company, the exploit drained $500,800 from the card balances of 1,685 customers — a modest haul by the standards of the broader DeFi ecosystem, which has witnessed billion-dollar bridge hacks, but a devastating event for a consumer-facing product built on trust. Markets reacted with immediate severity. AVICI, the platform’s native token, collapsed as much as 49% from its 24-hour high of $0.43, plunging to an all-time low of $0.217 before recovering to approximately $0.378 at the time of writing. The episode underscores a painful reality for the crypto card sector: the convenience of spending digital assets at point-of-sale terminals is only as reliable as the infrastructure that supports it. Rain’s contract acted as shared plumbing for multiple projects, and when a flaw emerged in one legacy version of that code, the blast radius stretched across several programs at once. It is also a stark reminder that Solana, for all its celebrated speed and low transaction costs, remains just as exposed as any other network when contracts are left unpatched. As crypto banks race to capture mainstream users, incidents like this raise uncomfortable questions about whether the foundations beneath their sleek applications are being kept up to date. For the wider crypto payments industry, the episode serves as an early-warning signal at a time when card-linked products are multiplying rapidly.

Avici moved quickly to explain the scope of the breach. The attack, the company said, was confined to a Solana contract that holds funds after customers top up their cards — a critical piece of the payment process, since those pooled balances are used to settle transactions with Visa’s network. What remained untouched were Avici’s self-custodial wallets on both Solana and Ethereum-compatible networks. That distinction is essential to understanding the modern crypto payment stack. Self-custodial wallets are controlled by private keys held exclusively by the user, offering a degree of independence that conventional bank accounts cannot match. Card top-up contracts, however, are a different story: they aggregate user funds and rely entirely on the integrity of code. When that code is outdated or flawed, the money inside becomes a target. Avici has promised to refund every affected card balance, a pledge that should go a long way toward repairing the immediate financial wounds of the 1,685 users who were hit. Yet the reputational damage may take far longer to heal. The AVICI token’s partial recovery to $0.378 suggests that some traders interpreted the sell-off as an overreaction, particularly in light of the express refund commitment. But the fact remains that the token established an all-time low in the middle of a routine security incident, illustrating just how fragile sentiment can be in an industry where confidence is the true currency. The coming weeks will test whether Avici can rebuild that confidence through transparent communication and flawless execution of its restitution plan — or whether the memory of this exploit lingers like a persistent background risk in the minds of its customers. For those following Solana security news, the incident also reinforces the importance of scrutinizing the exact custody structures that card programs advertise, since the gap between marketing and engineering is often where vulnerabilities hide.

Tria, another Solana-based crypto neobank, found itself in the same blast radius. The platform reported that 636 of its users were caught up in the exploit, with combined losses exceeding $430,000. In a statement, Tria vowed to repay affected users in full, a commitment that stands out in an industry where remediation is often messy, delayed, or conditional at best. Too frequently, victims of DeFi attacks are left waiting for weeks while teams negotiate with hackers, pass emergency governance proposals, or quietly declare losses unrecoverable. Tria’s immediate and unambiguous promise of restitution is therefore a meaningful signal — not just for its own users, but for the wider crypto neobank sector, which is desperate to distance itself from the cowboy reputation of early decentralized finance. The market, however, was not entirely convinced at first. Tria’s token plunged more than 10% at one point, reflecting the jitters that spread through the ecosystem as news of the attack circulated. That both Avici and Tria were compromised simultaneously highlights a systemic vulnerability: when many projects build on the same shared infrastructure, one weak link can compromise them all. For the crypto card industry, this is a particularly uncomfortable truth. These platforms are marketing themselves as the safe, user-friendly gateway to digital assets, promising everything that traditional banks provide — except, in most cases, the regulatory protections. Incidents like this expose the gap between promise and practice, forcing companies to confront a challenging question: if users cannot fully control their funds during a card top-up, and the contracts holding those funds are vulnerable to attack, what exactly does “self-custody” mean in practice? The answer matters not only for the affected users but also for the broader adoption of blockchain-based banking, which will never gain mainstream acceptance if it cannot offer security comparable to the systems it hopes to replace.

At the center of the incident is Rain, the card infrastructure provider whose contract served as the vector for the exploit. Rain said its monitoring systems detected the vulnerability in an outdated contract version used by Avici and a small number of other programs. The company responded by upgrading every program running that version and, critically, reported no further unauthorized activity after the containment effort. For those unfamiliar with the technical mechanics of blockchain development, it is worth pausing to explain why outdated contracts become such fertile ground for attackers. Smart contracts on Solana — and on most blockchains — are effectively immutable once deployed; updating a program typically requires deploying a new version and migrating users. Over time, live contract versions can multiply across the network, and older ones are often forgotten, holding funds and executing logic long after their maintainers have moved on. Automated bots prowl these historical deployments relentlessly, testing legacy versions for flaws that have long since been patched elsewhere. The Rain incident is a textbook case of this dynamic. Left unaddressed, an obsolete version of the code became a ticking time bomb, and the moment a threat actor discovered the flaw, the clock began counting down. Rain’s swift upgrade of all affected programs prevented the attack from expanding further, and that decisive action deserves recognition. Nevertheless, the episode raises pointed questions about contract lifecycle management across the broader ecosystem. If monitoring systems can identify vulnerable versions, why are those versions still live in the first place? Why are mandatory upgrade paths not enforced? The answers vary from project to project, but they usually come down to the same factors: resource constraints, engineering priorities, and the industry-wide tendency to focus on user growth rather than infrastructure maintenance. Security auditors have long warned that code hygiene is the first casualty of ambitious roadmaps, and this incident offers a textbook example of that principle in action.

The broader implications of the exploit extend far beyond the affected companies. For Solana, it adds another layer to a security narrative that has been scrutinized for years. The network has delivered impressive technical performance, earning a loyal following among developers and users who value speed and low fees over Ethereum’s more established (though costlier) ecosystem. Yet Solana’s history of high-profile bridge exploits, network outages, and contract vulnerabilities has repeatedly raised concerns about the maturity of its security posture. This latest incident will do little to silence those critics. For the wider crypto neobank sector, the stakes are even higher. These platforms operate at the intersection of decentralized finance and traditional payment infrastructure, where expectations around consumer protection are deeply engrained. When a user swipes a card issued by a conventional bank, transactions are insured, monitored, and reversible. Crypto card programs cannot offer those guarantees. There is no FDIC insurance, no central switch to reverse suspicious transactions, no ubiquitous fraud-detection team working around the clock. The result is a fundamental asymmetry: companies promise the seamless experience of a modern bank while operating on infrastructure that lacks banking’s most important safety nets. The vulnerability in Rain’s contract is a vivid illustration of that asymmetry. A user who entrusts their card balance to a neobank’s contract is making an implicit bet on the code’s correctness — and as this week’s events demonstrate, that bet can fail. The defense rests on rigorous audits, continuous monitoring, prompt patching, and the sometimes shaky goodwill of founders willing to back their promises with treasury funds. For the industry as a whole, the lesson is that security must be treated as an ongoing commitment rather than a one-time checkbox ahead of a token launch.

Where do things go from here? For Avici and Tria, the priority is clear: deliver on the promise of full restitution, communicate openly about the technical details of the exploit, and demonstrate that the systems holding user funds have been hardened against future attacks. Rain, too, has signaled that it is taking the matter seriously, upgrading all affected contract versions and confirming that no further unauthorized activity has been detected. These are the right immediate steps. But the long-term consequences of this incident will stretch far beyond the refund process. Regulators are already circling the crypto card sector, and events like this give them leverage to demand stricter oversight, more rigorous security standards, and clearer disclosures about where user funds are held. Meanwhile, investors will be watching how both tokens perform in the aftermath, parsing whether the market punishes disorganization or rewards transparent crisis management. For the wider industry, the episode is a valuable case study in the risks of shared infrastructure and the importance of disciplined code maintenance. The crypto neobank model — a Visa card linked to a self-custodial wallet, topped up on demand — is still young enough to evolve. The question now is whether the sector’s architects will internalize the lessons of the Rain contract exploit or wait for the next breach to force their hand. Ultimately, the users affected by this attack will decide with their feet: whether to return their balances to these platforms, or whether the memory of watching their funds vanish — even temporarily — proves too heavy to overcome. Trust, once dented, is not repaired by refunds alone. It is repaired by time, by transparency, and by proof that the code people depend on is worthy of the money it holds. That proof will have to be demonstrated in code, in conduct, and in the quiet consistency of day-to-day operations long after the headlines fade.

Share.
Leave A Reply