⚠️ Exploit Breakdown:
Aug 28: the card-balance collateral program behind #
Solana# crypto neobank
@avici took a sustained hit. Avici says 1,685 users were affected, ~$500K drained. Full refunds promised.
Attacker abused a signature-verification / auth-logic bug in Rain’s legacy Solana card contract, then ran the same 3-step loop across a pile of user collateral accounts:
(1) Submit a crafted signature bundle — SubmitSignatures
(2) Register themselves as admin — AddCollateralAdmin
(3) Pull the collateral — WithdrawCollateralAsset
Stolen USDC/USDT was periodically swapped to SOL and moved out. One tx:
Root cause is not a stolen upgrade key, and not a Solana L1 bug. The program mis-parsed / mis-bound the Ed25519 verify result, so the attacker’s own signature could pass as a legit admin authorization.
Attacker: FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj
Hit program: 26DkA98jjctzPkBEteUsN935CR4dsKx3XvjrtE7MeL4a
Example attack tx:
UPDATE: All affected card balances will be refunded in full
Earlier today, our card-issuing partner, Rain, identified a vulnerability in an version of a Solana card contract used by Avici and a small number of other programs. The contract has now been upgraded across all programs, and no further unauthorised activity has been observed.
Avici wallets and card balances are separate. Avici wallets are self-custodial and remain under users’ control.
When users top up their cards, funds move into a separate Solana contract that holds their card balance. Only this contract was affected.
Note: Funds held in Avici’s Solana and EVM wallets are safe and were not affected.
Our current reconciliation shows that 1,685 users were affected, representing $500,859.22 in card balances.
Every affected user will have their card balance refunded in full. We remain in close contact with our card-issuing and security partners and are monitoring the remediation closely.
Avici has also filed a report with the FBI’s Internet Crime Complaint Center. We are deeply sorry for the concern and inconvenience this has caused.
Show more