Security Incident and Risk Intelligence

Avici Commits to Full Refunds Totaling Half a Million Following Solana Card Contract Vulnerability

According to reporting by Crypto Briefing, Avici announced plans to fully refund over five hundred thousand dollars in affected user balances following a security flaw in a Solana card contract. The publication stated that issuing partner Rain discovered the flaw, impacting one thousand six hundred eighty-five users. This report is based on media reporting and has not been officially confirmed by an official or first-party source. This development is not officially confirmed.

Avici logo and Solana ecosystem security reporting illustration
Image: Crypto Briefing

Overview of the Reported Incident

According to reporting published by Crypto Briefing, a notable security vulnerability recently affected a Solana card contract utilized by the digital asset platform Avici through its card issuing partner Rain. The publication stated that the incident compromised card balances belonging to one thousand six hundred eighty-five individual users, creating immediate operational and financial remediation challenges for the platform management team. The total financial impact reported by the media outlet amounted to precisely five hundred thousand, eight hundred fifty-nine dollars and twenty-two cents in vulnerable card balances across the ecosystem.

The discovery of the flaw initiated a sequence of technical responses designed to halt unauthorized activities and secure the remaining operational infrastructure. Independent news coverage emphasized that while the card issuing mechanism encountered severe disruption, the core wallet architecture maintained by Avici was structured independently from the compromised top-up contract. Consequently, the organization initiated immediate remedial protocols to address user concerns while cooperating closely with relevant technological partners to assess the exact scope of the breach.

Technical Analysis of the Solana Contract Flaw

The security deficiency identified in the published reports stemmed from the specific operational mechanics governing how card balances were funded and managed on the Solana blockchain network. When participating users initiated top-up transactions to load funds onto their respective crypto payment cards, these assets were temporarily transferred out of their primary self-custodial wallets into a distinct smart contract dedicated to card issuance operations. This segregation of funds created a specialized vulnerability vector that targeted the intermediary contract rather than the foundational user accounts.

Card issuing partner Rain reportedly identified the software vulnerability during routine system monitoring and immediately alerted the affected platforms sharing the underlying contract architecture. The technical team implemented emergency contract upgrades across all vulnerable programs to eliminate the exposed attack surface and prevent subsequent unauthorized token movements. Industry analysts monitoring the situation noted that prompt remediation successfully halted further exploitation, although forensic evaluations of the exact vulnerability mechanism remained ongoing according to available public disclosures.

Custody Separation and Self-Custodial Security

A significant aspect emphasized in the reporting by Crypto Briefing involved the structural separation maintained between Avici user wallets and the compromised card issuing balances. The platform maintained that both its Solana and Ethereum Virtual Machine wallets operated on a strictly self-custodial basis, ensuring that private keys and primary crypto assets remained under the absolute control of individual account holders throughout the duration of the security event. This architectural design successfully prevented the exploit from extending into the broader user portfolio reserves.

Financial analysts reviewing the incident noted that architectural compartmentalization is a crucial risk mitigation strategy for modern cryptocurrency platforms offering hybrid services like debit cards and staking. By isolating the payment spending pool from the primary wealth storage vaults, the platform limited the damage exclusively to active card top-up balances. This structural containment reassured market participants regarding the integrity of the underlying wallet infrastructure, even as the specific card issuing contracts required urgent patching and comprehensive technical verification.

Remediation Commitments and Regulatory Engagement

In response to the security breach, Avici public relations channels communicated a firm commitment to execute full financial restitution for all individuals impacted by the smart contract vulnerability. Company representatives confirmed that every single user who suffered a balance reduction as a result of the compromised top-up contract would receive a comprehensive refund covering the exact amount lost. The total compensation commitment aligns with the reported aggregate deficit of over five hundred thousand dollars, demonstrating an aggressive approach to restoring user confidence.

Furthermore, the organization engaged with external legal and law enforcement authorities to investigate the origin of the exploit and pursue potential bad actors. Avici formally filed an incident report with the Federal Bureau of Investigation Internet Crime Complaint Center, signaling active cooperation with cybercrime investigators. Concurrently, the platform maintained open communication lines with its card issuing partner Rain and specialized cybersecurity consultants to monitor ongoing remediation efforts and harden the system against future vulnerabilities.

Conclusion on Reported Findings and Unconfirmed Elements

In conclusion, media reporting by Crypto Briefing indicates that Avici and its partner Rain experienced a Solana card contract vulnerability affecting one thousand six hundred eighty-five users and impacting five hundred thousand, eight hundred fifty-nine dollars and twenty-two dollars in card balances. Avici has committed to full refunds for all affected users, confirmed that self-custodial wallets remain safe, and reported the incident to the FBI Internet Crime Complaint Center. However, readers must note that this event is based on media reporting and has not been officially confirmed by an official or first-party source.

Moving forward, affected card users must monitor official Avici channels for verified refund distribution announcements and avoid clicking unverified links concerning the security incident. The rating impact remains set at no score change due to the preliminary nature of the disclosures. The primary action for users is to verify all balance adjustments directly within official application dashboards while awaiting further independent confirmation of the platform's remediation progress.

Cexvia conclusion

Conclusion on Reported Remediation and Unconfirmed Scope

Crypto Briefing reported that Avici experienced a security breach involving a Solana card contract utilized by its issuing partner Rain, impacting one thousand six hundred eighty-five users and a total of five hundred thousand, eight hundred fifty-nine dollars and twenty-two cents. Avici stated intentions to fully refund all impacted balances and filed a report with the FBI Internet Crime Complaint Center. This claim is not officially confirmed.

Risk meaning
The reported vulnerability highlights structural counterparty and integration risks when decentralized finance protocols interface with specialized card issuing infrastructure on alternative blockchains like Solana. Card balance top-up mechanisms frequently require moving assets away from secure self-custodial wallets into dedicated intermediary contracts, thereby introducing isolated attack vectors that can compromise user funds even if the core custody infrastructure remains secure and uncompromised during the security event.
User action
Users of crypto payment cards and integrated financial applications should carefully review the custody models of their preferred providers, distinguishing clearly between self-custodial underlying wallets and auxiliary spending contracts. Individuals affected by card balance incidents should monitor official communication channels from the platform, verify refund disbursement procedures directly within verified application dashboards, and exercise heightened vigilance against phishing communications exploiting the remediation period.
FBI Internet Crime Complaint Center