Solana-based card project Avici discloses security vulnerability
Solana-based card project Avici revealed that its card issuing partner Rain discovered a vulnerability in a version of the Solana card contract used to store user card balances. The project described the incident in an August 28 announcement. The affected contracts have subsequently been upgraded in all procedures, and Avici said no unauthorized activity has been observed since the repair.
Scope of impact
According to Avici, the incident was limited to a single smart contract and did not affect the user's wallet. When users recharge their cards, the funds are transferred to a separate Solana contract, which holds the card balance, and only this contract is affected. The company said Avici's self-managed wallet, which holds funds on both Solana and EVM chains, was unaffected and remained in user control. The project party pointed out that the isolation design between the card balance and the self-managed wallet prevented the further spread of damage.
Impact Scale
Avici's reconciliation results showed that a total of 1685 users were affected, involving a total card balance of US$500,859.22. The company pointed out that the version of the vulnerability contract was also used by a few other programs, but did not disclose the specific names of these programs or whether they suffered losses. Avici did not elaborate on how the vulnerability was exploited or how long the vulnerability might have existed before Rain discovered it.
Refunds and Regulatory Reports
Avici said each affected user will receive a full refund of their card balance and has submitted a report to the FBI's Internet Crime Complaint Center, the U.S. body that compiles cybercrime complaints. The company said it was in close contact with card issuing partners and security partners and was closely monitoring the repair work, but did not provide a specific timetable for completing the refund.
Frequent security risks in the Solana ecosystem
This disclosure is the latest in a series of security incidents in the Solana ecosystem. Avici has previously launched a virtual IBAN account on Solana, one of many card and payment projects built on the network. The incident follows broader warnings about Solana-related infrastructure, including what researchers point to a supply chain attack on Rust that put Solana-related build pipelines at risk. As card products increasingly store funds in on-chain contracts, this incident highlights the security burden borne by issuers managing these contracts.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
SOL