Avici Discloses Solana Card Contract Vulnerability Affecting 1,685 Users
0
0

Solana-based card program Avici has disclosed that its card-issuing partner Rain identified a vulnerability in a version of a Solana card contract used to hold user card balances, an incident the project described in an August 28 announcement. The affected contract has since been upgraded across all programs, and Avici said no further unauthorized activity has been observed after the fix.
What Was Affected
According to Avici, the incident was confined to a single smart contract rather than user wallets. When a user tops up a card, funds move into a separate Solana contract that holds the card balance, and only this contract was affected. Avici’s self-custodial wallets, which hold funds on both Solana and EVM chains, were not touched and remain under users’ control, the company said. The separation between card balances and self-custodial wallets kept the damage from spreading further, according to the project.
Scale of the Impact
Avici’s reconciliation shows 1,685 users were affected, representing $500,859.22 in card balances. The company noted the vulnerable contract version was also used by a small number of other programs, though it did not identify those programs or disclose whether they suffered losses. Avici did not specify how the vulnerability was exploited or how long it may have been present before Rain discovered it.
Refunds and Regulatory Report
Avici said every affected user will have their card balance refunded in full, and that it has filed a report with the FBI’s Internet Crime Complaint Center, the U.S. clearinghouse for cybercrime complaints. The company said it remains in close contact with its card-issuing and security partners and is monitoring the remediation closely, though it did not provide a timeline for completing the refunds.
A Recurring Solana Security Concern
The disclosure is the latest in a string of security incidents across the Solana ecosystem. Avici, which earlier launched virtual IBAN accounts on Solana, is among several card and payments projects building on the network. The episode follows broader warnings about Solana-adjacent infrastructure, including a Rust supply-chain attack that researchers said put Solana-adjacent build pipelines at risk. As card products increasingly hold funds in on-chain contracts, the incident underscores the security burden that falls on the issuers managing those contracts.
0
0
Securely connect the portfolio you’re using to start.






