The number that matters here isn’t $1.1 million. It’s $500,800, drained from 1,685 Avici users because of a contract version nobody had bothered to retire.
That’s the piece of the attack Avici has actually put a figure on. The rest of the roughly $1.1 million traced onchain went somewhere else, into other programs running the same outdated Rain card contract, and neither company will say which ones.
The token took it worse than the balance sheet
AVICI fell from a 24-hour high of $0.43 to a record low of $0.217, a drop of as much as 49%, before clawing back to around $0.378 at the time of writing.
Avici is a self-custodial neobank that lets you spend crypto through a Visa-integrated credit card. The pitch is that you hold your own keys. The hack is a fairly direct test of what that promise covers.
Where the money actually sat
Avici said the attack was confined to a Solana contract that holds funds after customers top up their cards. Self-custodial wallets on Solana and Ethereum-compatible networks weren’t touched, and the company said every affected card balance would be refunded.
That’s the custody handoff nobody puts on the landing page. You control the money in your Avici wallet. The moment you load it for spending, it moves into a third-party contract, and your control over it ends there.
Read Avici’s terms and you’ll find Third National named as the card issuer. Rain, a Visa principal member, provides the stablecoin card infrastructure underneath.
Avici wasn’t alone
Tria, another crypto neobank, said 636 of its users were affected for losses totaling more than $430,000. It vowed to repay users in full. Its own token fell more than 10% at one point.
Add Avici’s $500,800 to Tria’s $430,000 and you’re still short of the $1.1 million traced onchain. The gap is the story: other Rain-powered programs got hit too, and nobody has named them or said what each lost.
The attack itself was repetitive, not clever
Transaction data show the attacker submitted a signed authorization over and over, added itself as an administrator on individual card-collateral accounts, then withdrew the balances.
From there it’s the usual laundry cycle. Stolen stablecoins swapped into solana (SOL), bridged to Ethereum, pushed through crypto mixer Tornado Cash.
Rain said its monitoring caught the vulnerability in an outdated contract version used by Avici and a small number of other programs. It upgraded every program running that version and reported no further unauthorized activity.
Why an old contract version is a scaling problem
Tracked crypto-card spending more than tripled to $1.04 billion in July, with stablecoins funding 70% of more than 10 million transactions. Every one of those top-ups is a handoff into somebody else’s contract.
The infrastructure layer is shared. That’s efficient right up until a stale version is deployed across several programs at once, and then one bug is everyone’s bug.
What Avici hasn’t answered yet
Avici said it filed a report with the Federal Bureau of Investigation’s Internet Crime Complaint Center. It hasn’t said when refunds will arrive or where the money to fund them comes from.
Both matter more than the filing. An IC3 report is a formality; a funded refund plan with a date on it is a commitment.
If you’re holding a balance on a crypto card right now, the practical move is to stop treating loaded funds as self-custodial money. Keep them in the wallet you control until the moment you need to spend, and top up small. The 1,685 Avici users who learned that distinction this week learned it at an average of about $297 each.