Outdated Solana card contract drained $1.1 million as Avici token plunged 49%
A vulnerability in an outdated Rain card contract drained roughly $1.1 million across several Solana-based programmes on Tuesday, triggering one of the sharpest intraday token collapses seen in the neobanking sector this quarter. AVICI, the token of the self-custodial neobank Avici, fell as much as 49 per cent during the session before stabilising, according to CoinDesk.
The bulk of the losses hit Avici directly. Approximately $500,800 was taken from 1,685 Avici users after an attacker exploited a weakness in a version of a Solana card contract used by the platform’s payments infrastructure. AVICI tumbled from a 24-hour high of $0.43 to a record low of $0.217 in the wake of the incident, a collapse of almost exactly half its value in a matter of hours. The token subsequently recovered to around $0.378 at the time of writing, still well below its pre-exploit level.
Avici was not the only victim. Tria, another crypto neobank built on the same card infrastructure, confirmed that 636 of its users were affected, with losses exceeding $430,000. Tria said it would repay affected users in full, a commitment it made even as its own token dropped by more than 10 per cent at one point. The combined user losses across the two platforms account for the substantial majority of the $1.1 million total drained.
Shared infrastructure, shared contagion
The critical detail in this incident is what was not breached. According to the reporting, the problem was not described as a broad failure of Avici’s entire platform, but as a flaw in the card infrastructure used by Avici and several other programmes. Rain, the card provider behind the affected contracts, said it had identified a vulnerability in a version of a Solana card contract used by Avici and confirmed that affected balances would be refunded in full.
That distinction matters enormously for how the market should read this event. A single outdated contract sitting in the payments layer served multiple neobanking services simultaneously. When that contract failed, the damage propagated horizontally across every programme that had integrated it. Avici lost roughly half a million dollars and nearly half its market value. Tria lost more than $430,000 and a tenth of its token price. One exploit, two neobanks, more than 2,300 affected users between them, and a combined token drawdown that erased significant shareholder value in hours.
This is the architectural risk that comes with on-chain financial products. Traditional banking outages tend to be siloed: when one issuer’s card processing fails, competitors are unaffected. Shared smart contract infrastructure inverts that logic. Every integrator inherits the security posture of the weakest contract in its stack, and in this case the weakness appears to have sat in a contract version described as outdated, raising uncomfortable questions about why it remained live in production systems handling real customer balances.
The speed of the token reaction is equally instructive. AVICI’s 49 per cent intraday collapse was not a measured repricing of a balance sheet; it was a reflexive liquidity event. Holders who saw reports of a card contract drain had no immediate way to distinguish between a contained infrastructure flaw and a full platform compromise, so they sold first and asked questions later. The partial recovery to $0.378 suggests the market gradually absorbed Rain’s refund commitment and the clarification that the core platform was not broadly compromised, but the episode demonstrates how thin the informational buffer is for tokens attached to operational businesses.
For readers tracking similar episodes, our DeFi coverage has documented a recurring pattern: exploits in shared contracts produce faster and deeper token drawdowns than attacks on isolated wallets, precisely because the blast radius is harder to bound in real time.
Refund pledges and the market’s verdict
Both Rain and Tria moved quickly to commit to full reimbursement. Rain said affected balances would be refunded in full, and Tria independently confirmed it would repay its 636 affected users, covering losses in excess of $430,000. For Tria, that pledge is a direct balance sheet hit, and the market’s initial response was a token decline of more than 10 per cent, a comparatively modest reaction that may reflect confidence that the reimbursement is absorbable.
The refund commitments are the right crisis response, but they do not fully resolve the economic damage. AVICI’s record low of $0.217 marked an all-time nadir for the token, and even after recovering to roughly $0.378, holders remain well underwater relative to the session high. Reputationally, a neobank whose core proposition is self-custody and modern payments infrastructure has now been associated with a six-figure user fund drain. Rebuilding that trust takes longer than processing a refund.
There is also the question of what the $1.1 million total comprises. The confirmed figures from Avici and Tria account for roughly $930,000 of user losses, with the remainder spread across what the reporting described as several other Solana-based programmes affected by the same contract vulnerability. Those smaller integrators, and their users, face the same questions about reimbursement, and it remains to be seen whether Rain’s refund commitment extends uniformly across every affected service.
The regulatory dimension is harder to ignore after an episode like this. Crypto card products occupy contested territory in most jurisdictions, sitting at the intersection of payment services regulation, consumer protection rules and digital asset frameworks. An exploit that drains funds directly from consumer card balances, affecting more than 2,300 users across at least two platforms, is precisely the kind of incident that invites supervisory attention. Firms operating in the United Kingdom under the FCA’s evolving crypto regime, or in the EU under MiCA, should expect that incidents involving shared payment contracts will be examined not just for the loss amounts but for the due diligence performed before integration. A neobank that plugs into a third-party card contract is outsourcing part of its security perimeter, and regulators increasingly expect boards to treat that outsourcing with the same rigour as internal code.
What the exploit signals for on-chain neobanking
The broader implication is that infrastructure concentration risk has arrived in crypto finance. The sector has spent years discussing the systemic risk posed by large exchanges and lending protocols, but this incident illustrates a quieter channel: payment rails. Card contracts are meant to be the boring, commoditised layer of the crypto stack. When that layer carries a vulnerability, every downstream product inherits it, and the market repricing is instant and indiscriminate.
Three lessons stand out. First, contract version management is a first-order security issue. A vulnerability in an outdated version of a live contract suggests either a lag in upgrades or an integrator running legacy code against real funds, and both possibilities demand process reform. Second, token markets punish ambiguity. The 49 per cent AVICI crash happened before the scope of the breach was clear; the recovery followed the clarification and refund pledges. Projects that can communicate containment fast will limit drawdowns, and those that cannot will not. Third, shared infrastructure demands shared accountability. Rain’s commitment to refund affected balances is the correct posture, but the episode will inevitably push neobanks to demand audits, bug bounty coverage and contractual indemnities from their infrastructure providers.
For the sector’s trajectory, this is unlikely to be the last incident of its kind. As more neobanks build on common Solana programmes and shared card rails, the graph of exposure grows denser. Investors in platform tokens are, whether they realise it or not, taking a position on the security of every contract their platform touches.
The closing read: a $1.1 million drain is a modest loss by the standards of crypto’s exploit history, but the mechanics here are the story. One outdated contract, multiple platforms, thousands of users, a record-low token and a 49 per cent intraday wipeout, all inside a single session. The refunds will land, the price may stabilise, and the sector will move on. The structural lesson will linger: in on-chain finance, your risk is your infrastructure’s risk, and the market now prices that reality in minutes rather than days.