Solana Bank Avici Card Vulnerability: Can Compensation Restore Trust?

CN
15 hours ago

In the rapidly expanding narrative of the Solana ecosystem, Avici has branded itself as a "new type of bank," splitting the user card balances into independent Solana contracts and then connecting on-chain assets to everyday payment scenarios through card contracts provided by partner Rain. However, in a recent attack, this seemingly secure structure revealed its weaknesses: an old version of a Rain-issued Solana card contract, which had already expired, contained a security flaw that hackers exploited to launch unauthorized fund withdrawals directly from the accounts related to card balances. After reconciliation, Avici confirmed that the total amount of affected funds was $500,859.22, approximately $500,900, all sourced from card balances, while assets held in users' self-custodied Solana and EVM wallets were unaffected. When the incident was officially disclosed on August 29, 2026, Avici and Rain had already completed upgrades and patches to the old contract, promising full refunds to all affected users, emphasizing that users would be "made whole." The issue is that for users who view "on-chain banks" as the next step, a vulnerability originating from a fundamental contract, resulting in about $500,000 in card balances being drained, raises the question of whether trust in such emerging crypto banks has already fractured, potentially even more than the attack itself.

Expired card contract locked by hackers: known and unknown aspects of the attack chain

The incident with Rain involved an "expired" version of the Solana card contract. According to official statements, this old contract was supposed to be replaced but continued to be used by a handful of access points within the ecosystem, including Avici. Rain's monitoring system was the first to detect anomalies: a few projects still using the old version of the Solana card contract had security vulnerabilities, and the hackers took advantage of this, rather than targeting individual users, it was more a "lockdown" of the entire old contract chain.

More critically, the attack did not directly target users' self-custodied Solana or EVM wallets but precisely struck the accounts related to card balances. The hackers exploited the flaws of the old contract to make unauthorized withdrawals from these accounts tied to card funds, and Avici later confirmed that the drained card balance amounted to $500,859.22. The affected scope specifically includes Avici and several other projects or programs using Rain's old card contract, but the identity of the attackers, the specific timing of the attack, and further details on the method of invocation have not been publicly disclosed, nor has there been any revelation of the individual loss scale for other projects. As of August 29, 2026, publicly available information only emphasized that the contract has been upgraded and patched, with no new unauthorized activity detected so far. In the absence of on-chain addresses and technical details, the external discussions can only focus on the structural risks exposed by this shared contract architecture rather than simplifying it to a fully understood isolated incident.

New banks relying on third-party card issuance: how security responsibility is distributed on-chain

Avici positions itself as a new bank within the Solana ecosystem, but in its card products, it actually leverages partner Rain’s card issuance infrastructure: card balances are stored in independent Solana contracts, isolated from users' self-custodied Solana and EVM wallet assets. The responsibility for card issuance and settlement logic falls to the Solana card contract provided by Rain. The vulnerability exploited in this incident was precisely in one of Rain's expired version contracts, not in wallets where users hold their private keys. However, for ordinary users, the technical details of "who wrote the contract" and "who issued the card" are often merely that – details, while the frontend showcases Avici's brand and products, making the incident naturally perceived as "an issue with the Avici bank," thus transforming the choice of third-party infrastructure on-chain into reputational risks for the primary responsible party.

After the incident, Rain confirmed externally that it had completed upgrades and patches for all relevant projects' old Solana card contracts and switched these projects to secure version contracts; meanwhile, Avici provided a clear figure after reconciliation: the total scale of affected card balance funds was $500,859.22, about $500,900, and promised full refunds to all affected users, emphasizing that users would be "made whole." From the user's perspective, this means that the direct financial loss is likely to be covered, but current public information has not disclosed the specifics of the compensation execution progress and timetable; outsiders can only temporarily regard this as a promise. In a new bank model relying on shared contracts and third-party infrastructure, this incident has exposed a reality: on-chain security responsibilities can be divided, but trust will disproportionately center on the frontend brand.

Single contract implicates multiple projects: Solana ecosystem exposes single point of vulnerability

In this incident, Avici was not the only participant to "step on a landmine." After conducting internal checks, Rain confirmed that the affected scope also included a few other projects or programs connected to its old Solana card contract. As long as card balance funds were held under this expired contract, they faced the risk of being impacted by the same vulnerability. In other words, multiple products that appear independent in the eyes of users essentially share the same underlying "veins," and if attacked, it could form a chain reaction within the ecosystem.

This is not an isolated case but a common pattern in the current public chain ecosystem: during this wave of rapid launch of financial products in Solana, a single contract and single card issuance infrastructure are reused by multiple frontend projects, amplifying efficiency while concentrating security. When Rain completed the upgrade of the old contract and reported no new unauthorized activities, the technical "hemorrhaging" seemed to have come to an end, but specific details about which projects were affected and their individual loss scales have hardly been disclosed. In an environment where contract sharing has become the default choice, whether the information disclosure is complete will directly determine whether users are trusting a particular brand or the entire set of underlying infrastructure.

Isolation of card balances and self-custodied wallets: design details mitigate the impact

In this incident, a key yet easily overlooked detail is Avici's asset architecture: funds used by users for card purchases are concentrated in independent Solana contracts, while the Solana wallets and wallets accessing the EVM ecosystem that users control are always kept out of this card contract logic. After the old Rain contract was exploited, it was confirmed that approximately $500,859.22 of the loss was concentrated in accounts associated with card balances, and officials have repeatedly emphasized that funds in self-custodied wallets were unaffected, with no evidence showing the vulnerability extending to broader accounts or other asset categories. In other words, what was opened was the "card balance hatch," not the entire ship.

From the perspective of on-chain financial products, this kind of asset isolation and permission layering directly determines the scope of the incident's impact. The card balance contract acts as an independent "compartment," even if breached, the attack path cannot naturally penetrate into the Solana and EVM wallets where users hold their private keys; the users' most critical self-custodied assets were not exposed because they accessed the same brand's card services. This provides a minimal safety baseline for the subsequent trust restoration: users can clearly distinguish between "passively held card funds" and "assets they control," and it serves as a wake-up call for other on-chain financial products—under the unavoidable premise of shared infrastructure, drawing contract boundaries and permission layers in advance to outline the "firewall" for incidents often determines whether a vulnerability leads to localized damage or systemic disaster.

From full compensation to subsequent review: a trust test for emerging crypto banks

In terms of results, the "wound" from this incident was clearly delineated: the vulnerability only tore open card balance accounts under the old version of the Solana card contract, resulting in about $500,859.22 in damage, while users’ self-custodied Solana and EVM wallets remained safely beyond the boundary. After the torrent of unauthorized withdrawals ceased, Avici and Rain completed the upgrade and patching of the old contract before August 29, 2026, and provided a full refund commitment, attempting to bridge the trust gap with the assurance that "users will be fully compensated." This rapid response and clear amount of compensation have a practical effect in alleviating panic and proving that the product architecture was not completely compromised, but it only answers "who will pay," and for now, it cannot answer "why the error occurred and whether it can happen again." The subsequent factors that will truly determine whether users are willing to continue entrusting their card balances to similar infrastructures include several public variables: whether the compensation is delivered as promised without discounts, how other projects still using Rain's old card contract disclose their own damages and rectifications, and whether this incident is elevated to a systematic security review, with stricter scrutiny and reform applied to everything from the management of expired contracts to monitoring and emergency processes.

Join our community to discuss and grow stronger together!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink