Risk Radar

Risk Detail / high

Avici / Rain Solana Card Contract Exploit: What Users Need to Know

Avici says an older Rain Solana card-balance contract exploit affected 1,685 users and $500,859.22 in confirmed balances. Self-custody wallets were not affected.

August 30, 2026Last updated 10:30 UTC3 min read

What happened

Avici disclosed that an older Rain Solana card-balance contract was exploited.

The company identified 1,685 affected users and $500,859.22 in confirmed Avici card balances impacted by the incident.

Avici says customer self-custody wallets were not affected.

That distinction is central to the risk assessment. The affected asset pool was tied to the card-balance contract rather than users’ independently controlled wallet balances.

Why the contract boundary matters

Crypto card products often combine several layers:

  • a self-custody wallet;
  • a card funding or spending balance;
  • smart contracts;
  • payment processors;
  • off-chain settlement infrastructure.

An incident in one layer does not automatically mean every asset associated with the product is compromised.

For Avici users, the key question is therefore where funds were held at the time of the exploit.

According to the disclosure, the confirmed affected balances were in the card contract. Self-custody wallet funds were not part of the confirmed loss set.

Confirmed impact

The currently confirmed Avici-specific impact is:

  • Affected users: 1,685
  • Confirmed affected balances: $500,859.22
  • Self-custody wallets: Not affected, according to Avici
  • Compensation: Full refunds promised

Broader on-chain figures above $1 million have been discussed in connection with attacker flows. Those larger figures may include activity across multiple programs or contracts and should not automatically be described as Avici customer losses.

CEXVia therefore uses the confirmed $500,859.22 figure for Avici-specific customer impact unless a later reconciliation expands it.

Refund commitment

Avici has committed to reimbursing affected users in full.

The main operational risk now shifts from exploit containment to execution:

  • when refunds begin;
  • whether every affected user is automatically identified;
  • whether claims are required;
  • what asset or currency refunds use;
  • whether there are jurisdictional restrictions;
  • whether all impacted balances are restored one-for-one.

A reimbursement promise materially lowers expected user loss if executed, but it does not close the incident until funds are actually returned.

What users should verify

Affected users should keep records of:

  1. their pre-incident card balance;
  2. transaction history;
  3. any Avici or Rain notice;
  4. refund status;
  5. support ticket numbers.

Users should be cautious of phishing messages claiming to process refunds. A legitimate reimbursement process should not require a seed phrase or private key.

Risk assessment

High.

The exploit affected a production balance contract and more than 1,600 users.

The rating is moderated by the limited confirmed loss amount relative to larger protocol incidents, the stated separation from self-custody wallets and the commitment to reimburse users.

What to watch next

CEXVia will monitor refund completion, the final technical root cause, whether Rain or Avici retires or upgrades the affected contract architecture and whether broader attacker-flow estimates can be reconciled with confirmed customer losses.

FAQ

How much did Avici users lose?

Avici confirmed $500,859.22 in affected card balances.

How many users were affected?

1,685 users were identified as affected.

Were self-custody wallets hacked?

Avici says self-custody wallets were not affected.

Will users be refunded?

Avici has promised full reimbursement. The incident remains open until refunds are completed.

Why are some reports showing a larger loss?

Broader on-chain attacker flows may include funds from multiple programs or contracts. CEXVia separates those figures from confirmed Avici customer losses.