Crypto Card Balance Contracts Vulnerable to Attacks: Lessons From Solana Exploit
A recent exploit on the Solana blockchain highlights a crucial aspect of crypto cards that users should be aware of. On August 28, an attacker targeted the card balance contract of Avici, a neobank on the Solana network, draining funds from user accounts without compromising their private keys.
The attack worked by exploiting a vulnerability in the payout logic of Avici's program, written in Rust, allowing the attacker to withdraw collateral assets. The exploit was not a one-off but part of a 14,672-transaction series, with 2,344 failing attempts.
A card balance contract is a separate smart contract on a blockchain that holds funds transferred from users' wallets for payment purposes. This incident shows how vulnerable these contracts can be to attacks, leaving users exposed even if their self-custodied wallets are untouched.
The extent of the damage varies depending on whether one counts the total outflow or individual customer card balances. Avici reported 1,685 affected users and $500,859 in card balances, while an on-chain estimate put the loss at around $1.07 million. The discrepancy highlights the importance of verifying information during incidents.