security · "crypto cards" · "Solana" · "smart-contract security"
Legacy Rain Card Contract Exploit Hits Avici and Tria Users
Roughly $1.1 million was withdrawn across card programs. Avici says its self-custody wallets were not compromised and affected balances will be reimbursed.

A vulnerability in an older version of Rain’s crypto-card contract enabled roughly $1.1 million in unauthorized withdrawals across several Solana-based card programs.
Avici reported that 1,685 users lost approximately $500,800 from balances loaded for card spending. Tria reported more than $430,000 affecting 636 users. The difference between those disclosed amounts and the broader estimate indicates that other Rain-supported programs may also have been affected.
The incident did not breach the self-custody wallets described by Avici. The vulnerable contract held funds transferred into a separate card-spending environment. That distinction limits the scope, but it also exposes a critical boundary: a self-custody product can still depend on custodial or pooled infrastructure at the point of payment.
Rain said affected programs had been upgraded from the legacy contract and that it had not observed further unauthorized transactions. Avici and Tria said affected balances would be reimbursed. Avici also reported the incident to the FBI’s Internet Crime Complaint Center.
AVICI fell sharply after the disclosure, dropping about 49% from its 24-hour high before partially recovering. The price move is a dated market reaction, not a measure of the final operational loss.
Blue Rogues interpretation: card convenience creates an additional smart-contract perimeter. Users should distinguish assets held in a self-custody wallet from funds already loaded into a card contract.
Sources:
- https://www.coindesk.com/web3/2026/08/29/a-usd1-1-million-crypto-card-hack-crashed-a-neobank-s-token-49
