Back to news

Avici hack: $500,859 stolen from 1,685 users through vulnerable Rain contract

Attackers stole $500,859 from 1,685 Avici users through a vulnerable Rain Solana contract. Avici promised full refunds but gave no payment timetable.

White Avici Visa Signature card with gold chip

Avici Card artwork from the reviewed card profile

Incident status

What is confirmed now

Stolen from Avici balances
$500,859
Avici users affected
1,685
Attack status, provider claim
Stopped
Refund status
Promised

Confirmed statements and limits

  • Avici says unauthorized withdrawals took $500,859.22 from 1,685 users.
  • Rain and Avici say all programs using the vulnerable contract were upgraded.
  • Avici has promised full refunds but has not published a payment timetable.
  • The complete cross-program loss and technical root cause remain unpublished.
Read Avici's update View Avici Card profile

One official incident statement and one internal card profile. Neither is an affiliate link.

The attack and confirmed losses

The hack targeted the separate Solana contract that held Avici card balances. Avici's current reconciliation says $500,859.22 was taken through unauthorized withdrawals from 1,685 users. Onchain analysis places the first known malicious transaction at 16:49:48 UTC.

Avici acknowledged an issue affecting card-balance withdrawals at 18:42 UTC, almost two hours after that first identified transaction. At 20:20 UTC, Tria reported unauthorized withdrawals involving USDC and USDT topped up to Solana card balances.

Rain published its incident statement at 20:26 UTC. The company said a small number of programs used a vulnerable, outdated version of its Solana contracts. Rain says it upgraded every program using that version and stopped the exploit. Tria later said its card-balance issue had been resolved.

At 20:44 UTC, Avici said its current reconciliation identified 1,685 affected users and $500,859.22 taken from card balances. Avici promised to refund every affected balance in full, said no further unauthorized activity had been observed and reported the hack to the FBI's Internet Crime Complaint Center. It did not say when refunds would be paid.

How the withdrawals were executed

The Defiant identified a suspected address that received 1.79 SOL through deBridge at about 13:40 UTC and first interacted with Avici-related contracts at 16:49:48 UTC. At 18:58 UTC, the address held 10,005 SOL plus about $11,600 in USDC and USDT, worth more than $1 million at the prices used in that report.

Suspected addressFVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj

That point-in-time balance is not an official final loss. Transactions reviewed by The Defiant repeatedly used signature-submission and Ed25519 verification calls before functions labelled AddCollateralAdmin and WithdrawCollateralAsset. One reviewed withdrawal moved 2,346.77 USDT from a collateral account.

A public tracker counted 125 distinct sending accounts in its observation window. The suspected address had signed 14,672 transactions, of which 2,344 failed. Neither number is a verified victim count, and they do not support the circulating claim that more than 9,000 users were drained.

By 22:33 UTC, Solscan showed the suspected address with 0 SOL and $0 total value and marked the base account as no longer existing onchain. Its recent activity table listed swaps and outbound transfers, including one transfer of 886.94 SOL. This changes the earlier balance snapshot but does not establish the full destination trail or show that any money was recovered.

Solscan records that final 886.94 SOL moving through two intermediary addresses. At 19:34:39 UTC, the last address swapped 886.92 SOL for about 91,716 USDC and submitted 90,961.83 USDC to Ethereum through deBridge. A second deBridge order at 19:35:44 UTC submitted another 747.03 USDC.

The Ethereum address identified in the new onchain analysis is marked by Etherscan as funded by deBridge. Its transaction history contains 22 deposits to the Tornado Cash Router totalling 455.8 ETH: four deposits of 100 ETH, five of 10 ETH, five of 1 ETH and eight of 0.1 ETH. Etherscan showed 0.036 ETH left at the latest source check.

The earlier address balance should not be presented as Avici's loss. Avici's current reconciliation remains $500,859.22. The path and ownership of value beyond that amount have not been publicly allocated across other affected programs, swaps or unrelated activity.

The transaction sequence shows abuse of an authorization path. It does not yet show whether the underlying cause was faulty signature validation, a compromised trusted signer or backend service, or valid signatures obtained through phishing. Rain's forensic investigation has not published a technical conclusion.

Which card programs were affected?

Public statements reviewed for this update connect the incident to Avici and to reports from Tria users. Rain has not named every affected program. Solayer Pay said at 20:31 UTC that it was not affected and that its funds remained secure and operational.

Rain describes Rain-Managed and Partner-Managed operating models, but its incident statement does not map affected programs to either model. A list of companies that use Rain infrastructure is not evidence that every listed product was exposed.

Avici says its self-custodial Solana and EVM wallets were separate from the affected card-balance contract and remained safe. The observed admin-change path shows why a self-custody label does not, by itself, describe every authorization mechanism that can affect a separate card balance. This is a control-model observation, not a final root-cause finding.

Claims not supported by current evidence

These claims should not be treated as established facts:

  • More than 9,000 users were affected.
  • The full $1.11 million attributed to the cross-chain route was taken from Avici users.
  • Circle received a verified freeze request, had a defined opportunity to stop the funds and declined to act.
  • Every product in circulating lists of Rain clients was affected.
  • All Rain-managed programs were affected while every self-managed program was safe.

The suspected Solana address was initially funded through deBridge. The later Solscan and Etherscan records now support a route back through deBridge and 22 deposits from the identified Ethereum address to Tornado Cash. They do not establish that the full amount routed through that address was taken from Avici users. No primary incident statement reviewed for this update confirms the total cross-program loss or the Circle allegation.

What affected users should do now

  1. Check the card balance and recent Solana USDC or USDT transactions in the provider's official app and a block explorer.
  2. Save transaction IDs, timestamps and screenshots for any withdrawal that was not authorized.
  3. Contact the provider through its official support channel and ask how reimbursement will be handled.
  4. Ignore unsolicited recovery messages, links or requests for a seed phrase, private key or passkey.
  5. Follow notices from the specific card provider. A general Rain customer list does not prove that a program was exposed.

What remains unknown

The next material updates are the complete affected-program list, total loss across all programs, the destination or recovery status of the transferred funds, technical root-cause analysis, reimbursement timetable and findings from the third-party forensic investigation.