$1.1 Million Rain Card Exploit Drains Neobank Funds and Craters Avici’s Token
Cryptocurrency

$1.1 Million Rain Card Exploit Drains Neobank Funds and Craters Avici’s Token

Outdated Rain card contract drained of $1.1 million in Solana exploit

A vulnerability in an outdated Rain card contract has been exploited to drain approximately $1.1 million across several Solana-based programmes, according to CoinDesk. The attack struck at the point where crypto neobanks connect to real-world payment rails: the contract that holds card balances after users top up their cards.

The single largest casualty was Avici, a self-custodial neobank, whose users lost roughly $500,800 across 1,685 accounts. The token of the self-custodial neobank, AVICI, collapsed by as much as 49 per cent in the hours after the incident became public, falling from a 24-hour high of $0.43 to a record low of $0.217. It later recovered to approximately $0.378 at the time of reporting.

A second crypto neobank, Tria, confirmed that 636 of its users were impacted, with losses topping $430,000. Tria said it would repay affected users in full, a commitment announced even as its own token slid by more than 10 per cent at one stage.

Rain, the card infrastructure provider whose contract was at the centre of the incident, said it had identified a vulnerability in an older contract version used by Avici and a small number of other programmes. The company said it had since upgraded the contract.

What was hit, and what was not

The most consequential detail to emerge is the precise location of the vulnerability. The exploit appears to have been limited to a specific Solana contract holding card balances after users topped up their cards. It did not, according to the affected companies, reach users’ self-custody wallets.

Avici stated that its Solana- and Ethereum-compatible self-custody wallets were not affected, and committed to refunding all affected card balances. That distinction matters enormously for how the incident should be read. Self-custody promises in crypto rest on the assumption that users hold their own keys and their own funds. When those funds move into a card programme, however, they sit in intermediary contracts, the plumbing that bridges on-chain balances to off-chain payment networks.

This is where the attack landed. Card top-ups flow into a contract operated through Rain’s infrastructure, and it was this older contract version that contained the flaw. The architecture of the exploit therefore maps neatly onto a familiar weakness in crypto finance: the further funds travel from a user’s own wallet into third-party contracts, the more the security posture resembles traditional finance, with all its counterparty risk, and the less it resembles the self-custody promise that attracts many users in the first place.

For a fuller picture of how incidents like this ripple across the ecosystem, see our Solana coverage, which tracks exploits, network developments and token movements on the chain.

Market reaction: trust evaporates faster than funds

The market response was brutal and instructive. AVICI’s intraday chart tells the story: a 49 per cent drawdown from $0.43 to a record low of $0.217, followed by a partial recovery to roughly $0.378 once Avici confirmed that self-custody wallets were untouched and that refunds were coming.

That pattern, panic first, differentiation second, has become a familiar signature of crypto exploits. In the initial minutes after news breaks, markets rarely distinguish between a contained contract exploit and a full protocol compromise. Everything associated with the affected name is sold first and examined later. It was only after the scope of the breach became clear that AVICI clawed back a substantial portion of its losses.

Tria’s token experienced a milder version of the same dynamic, falling more than 10 per cent at one point despite the company’s immediate pledge to make users whole. The relative severity of the two token reactions roughly tracked the relative scale of user losses, though both illustrate the same principle: a neobank’s token is, in effect, a traded claim on the credibility of its infrastructure, and that credibility is only as strong as the weakest third-party contract in the stack.

The numbers involved are modest by the standards of major protocol hacks, which routinely run into hundreds of millions of dollars. But the reaction was not proportionate to the dollar amount. It was proportionate to what the incident implied. Card products sit at the most sensitive intersection in crypto finance, the point where digital assets must behave like money in the ordinary sense, swiping at terminals, settling with card networks, holding balances that users expect to be spendable at any moment. A failure there does not just cost funds; it undermines the core product proposition.

The third-party dependency problem in crypto payments

The deeper lesson extends well beyond Avici, Tria and Rain. Crypto card programmes are almost never built entirely in-house. Issuing, processing and balance management typically run through specialised providers, and each handoff introduces another contract, another upgrade schedule and another potential point of failure. Avici and Tria did not, on the available evidence, write the vulnerable code. They integrated a card infrastructure product, and a flaw in an older version of that product’s contract drained their users’ topped-up balances.

Rain’s confirmation that it had upgraded the contract addresses the immediate technical exposure, but it also raises the questions that every neobank building on third-party rails should now be asking. How many outdated contract versions remain live across the sector? What monitoring exists to detect anomalous withdrawals from balance-holding contracts before they compound across thousands of accounts? And who bears the loss when the vulnerable code belongs to a vendor rather than the brand the user chose?

Tria’s decision to repay users in full, and Avici’s commitment to refund all affected card balances, answer the last question for now, at least for these two firms. But repayment is a balance-sheet event. It transfers the loss from users to the companies, and the token market priced that transfer immediately. Investors, not only customers, are the ones who absorb vendor risk when the brand steps up.

The incident also lands at a sensitive moment for Solana-based consumer finance more broadly. The chain has become a hub for neobanks, card products and payment experimentation precisely because of its speed and low fees. That same concentration means a single flawed contract can ripple across multiple consumer-facing brands at once, as it did here, touching at least two neobanks and several programmes. The scrutiny of Solana-based card products triggered by this episode is likely to intensify, and it is scrutiny the sector will struggle to deflect while outdated contract versions remain in production anywhere in the stack.

Closing analysis

This was, in pure financial terms, a small exploit: $1.1 million, two neobanks, several thousand affected users, and a token that lost and then largely recovered half its value within a trading session. In structural terms, it is a warning shot. The compromised surface was not a lending protocol or a bridge, the usual suspects in crypto security, but the humble card balance contract, the least glamorous and most user-facing piece of the infrastructure. Both firms responded quickly, with refunds pledged and wallets confirmed intact, and Rain patched the vulnerable contract. The sector’s task now is preventive: auditing not only first-party code but every third-party contract that touches customer balances, and retiring outdated versions before someone else finds them first. Until then, the gap between self-custody promises and card-programme reality remains the sector’s softest target, and markets have shown exactly how swiftly they will price that gap when it is exposed.

CN

CryptoGazette Newsroom

Crypto Reporter

CryptoGazette Newsroom is the lead news desk covering price action, on-chain analytics, regulation, DeFi protocols, NFTs, and institutional adoption across the cryptocurrency ecosystem. The Newsroom focuses on time-sensitive market-moving stories.