Avici, a Solana-based neobank, said an attacker took $500,859.22 from the card balances of 1,685 users on Friday, adding that every affected user will be refunded in full.
The flaw was in a contract belonging to Rain, the card issuer behind Avici's Visa product, rather than in Avici's own code. Rain said its monitoring systems found "a vulnerability impacting a small number of programs using an outdated version of our Solana contracts" and that it has upgraded every program running that version. Avici said its self-custodial wallets were untouched: only the separate contract that holds balances users top their cards up with was drained.
Onchain records show the attacker moved more than the reported figure. The wallet behind the drain, FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj, sent exactly 10,000 SOL — about $1.07 million at SOL's $106.62 — in a single transfer at 19:02:45 UTC, and was empty by 19:26:34.
How the exploit unfolded
The wallet was funded with 1.79 SOL bridged through deBridge at 13:40 UTC and sat idle for three hours before its first call against the card contracts landed at 16:49:48 UTC. It signed 14,672 transactions before going quiet, 2,344 of which failed. Transaction logs show a repeating three-instruction pattern per victim:
- SubmitSignatures on the authorization program, in a transaction also invoking Solana's Ed25519 signature-verification precompile
- AddCollateralAdmin on the collateral program
- WithdrawCollateralAsset on the same program
The attacker registers itself as an administrator on a user's collateral account, then withdraws the balance. In one transaction reviewed by The Defiant, a single WithdrawCollateralAsset call moved 2,346.77 USDT out of a user's collateral account into the attacker's token account, with the wallet swapping stablecoins into SOL as it went, one fill adding 209.76 SOL. Both programs are upgradeable and share the same upgrade authority, a plain Solana account rather than a multisig.



