An attacker exploited an outdated Solana smart contract in Rain’s crypto-card payment infrastructure, replaying signed authorizations to appoint themselves collateral-account administrator and withdraw card balances. The campaign stole about $1.1 million across several card programs, including more than $500,000 from 1,685 Avici users and over $430,000 from 636 Tria users. On-chain records showed repeated use of the SubmitSignatures, AddCollateralAdmin, and WithdrawCollateralAsset instructions; one observed wallet accumulated roughly 10,005 SOL, alongside USDC and USDT.
The attacker exchanged stolen stablecoins for SOL, bridged funds to Ethereum, and used Tornado Cash to obscure their trail. Rain upgraded all programs using the vulnerable contract version, while Avici and Tria said customers would be fully reimbursed; Avici also filed a complaint with the FBI’s IC3. Avici initially acknowledged a card-balance withdrawal issue nearly two hours after the first drain, and its AVICI token fell about 49% as the incident emerged.

Track how attackers are adapting to this technology.
10 events from the most recent confirmed update back to the earliest known activity.
AVICI fell roughly 49%, declining from about $0.43 to an all-time low near $0.217 before partially recovering to around $0.378. Tria's token fell by more than 10%.
Transaction analysis found that the attacker swapped stolen stablecoins for SOL, bridged assets to Ethereum, and routed them through the Tornado Cash mixer.
Avici and Tria said they would fully compensate affected customers. Avici also reported filing a complaint with the FBI Internet Crime Complaint Center (IC3).
Avici reported losses exceeding $500,000 affecting 1,685 users, while Tria reported more than $430,000 stolen from 636 users. The incident was assessed as affecting about $1.1 million across multiple Rain-linked card programs.
Rain updated every program running the vulnerable contract version and said it observed no further unauthorized-access incidents after the updates.
Rain's monitoring system identified a vulnerability in an outdated Solana smart contract used by Avici and other crypto-card programs, which enabled unauthorized withdrawals across multiple programs.
By 18:58 UTC, the attacker wallet held 10,005.03 SOL, valued at about $1.07 million, plus approximately $11,600 in USDC and USDT. An on-chain tracker identified 125 distinct sending accounts during its observation period.
At 18:42 UTC, Avici publicly acknowledged an issue affecting card-balance withdrawals and said it was working with relevant partners to resolve it.
At 16:49:48 UTC, the attacker began transacting against Avici contracts, replaying signed authorizations, adding itself as a collateral-account administrator, and withdrawing victim funds.
The wallet later used in the attack was funded with 1.79 SOL bridged through deBridge at 13:40 UTC.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.