Avici Hit by $500K Attack After Partner's Outdated Solana Contract Exploited
Avici, a Solana-based neobank, has pledged to refund all affected users after an attacker exploited an outdated contract supplied by its issuing partner Rain. The attack drained $500,859.22 from customer card balances, with early onchain estimates suggesting the loss could have been over $1 million.
The vulnerable infrastructure was a separate Solana contract holding balances that users had moved into the card system, not Avici's self-custodial wallets or the Solana protocol itself. Rain identified the vulnerability in an outdated version of its Solana contracts and has since upgraded all affected deployments.
Avici has filed a report with the FBI's Internet Crime Complaint Center and is working closely with Rain to reconcile the transactions and restore affected card balances. Every user will receive a full refund, according to Avici.