Avici said an attacker stole $500,859.22 from the card balances of 1,685 users on Friday, adding that every affected user will be refunded in full.
The company said the flaw was not in Avici’s own code. It was in a contract run by Rain, the card issuer behind Avici’s Visa product. Rain said its monitoring systems detected "a vulnerability impacting a small number of programs using an outdated version of our Solana contracts" and that every program running that version has been upgraded. Avici said its self-custodial wallets were not affected. What was drained was a separate contract that held the balances users loaded onto their cards.
On-chain transfers exceeded the disclosed loss
On-chain records show the attacker moved more than the $500,859.22 figure disclosed by Avici. The wallet used in the drain, FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj, sent exactly 10,000 SOL in a single transfer at 19:02:45 UTC. At SOL’s price of $106.62, that transfer was worth about $1.07 million. The wallet was empty by 19:26:34.
The gap between the disclosed user losses and the on-chain movement matches Rain’s account that more than one program was running the vulnerable contract.
Rain and Avici responses
At 20:26 UTC, Rain said it had "engaged third-party forensics experts to investigate, and will work with law enforcement and relevant regulatory authorities." It added: "All affected users will be made whole."
Avici said it has filed a report with the FBI’s Internet Crime Complaint Center. "We are deeply sorry for the concern and inconvenience this has caused," the company said.
Neither company has said how long the outdated contract had been deployed, why the programs using it were not upgraded earlier, or how the attacker discovered it. The report also notes that Rain settles card transactions with Visa in stablecoins and issues cards for Western Union’s Stablecard, which launched on Aug. 4.
Add admin, then withdraw
The attacker wallet was funded with 1.79 SOL bridged through deBridge at 13:40 UTC and then sat idle for about three hours. Its first call against the card contracts landed at 16:49:48 UTC. The address signed 14,672 transactions in total, 2,344 of which failed, before activity stopped.
Transaction logs show the same three-step pattern repeated across victims. The wallet first called SubmitSignatures on the authorization program in a transaction that also invoked Solana’s Ed25519 signature-verification precompile. It then called AddCollateralAdmin on the collateral program, followed by WithdrawCollateralAsset on that same program. In effect, the attacker registered itself as an administrator on a user’s collateral account and then withdrew the balance.
In one transaction reviewed by The Defiant, a single WithdrawCollateralAsset call moved 2,346.77 USDT from a user’s collateral account to the attacker’s token account. The wallet swapped the stolen stablecoins into SOL along the way, with one fill adding 209.76 SOL.
Both programs are upgradeable and share the same upgrade authority. That authority is a plain Solana account rather than a multisig.
Where the 10,000 SOL went
The 10,000 SOL left the attacker’s wallet at 19:02:45 while the drain was still in progress, then moved again 33 seconds later. The receiving address, MsaXH6cGDahPQDwJjFYod7RW8QLVDZGByywWvwQ9TFu, split the balance at 19:03:18 into two transfers of 6,999.98 SOL and 2,999.99 SOL, sending them to two other addresses before emptying itself.
Those two destination addresses hold 82,910 SOL and 110,472 SOL. They sign thousands of transactions an hour and carry long lists of memecoin balances. The Defiant said that profile is consistent with exchange or market-maker hot wallets.
Nearly two hours before a public statement
Avici’s first public statement came at 18:42 UTC, one hour and 53 minutes after the first drain transaction. It said only that the company was "aware of an issue affecting card balance withdrawals." Users had already posted about missing balances before that statement appeared.
At 18:44 UTC, one user wrote, "i just got drained of all my balance from my @avici acc," adding, "waiting to hear from the project."
AVICI token hit a record low
According to CoinGecko, AVICI traded at $0.2175, down 49.4% over 24 hours, with a market capitalization of $2.84 million and 24-hour trading volume of $656,543. The token set a record low on Friday after having reached $7.56 on Nov. 26, 2025.
The token trades mostly on MetaDAO’s futarchy automated market maker, which handles about 58% of volume. The rest is split across LBank, KCEX, and MEXC.
Avici fundraising and company details
Avici raised funds through MetaDAO in October 2025 in one of the Solana launches that helped revive the ICO model. The team capped the sale at $3.5 million against $34,206,976 in commitments, refunded 89.8% of committed USDC, and set an initial token price of $0.35 on a fully diluted valuation of $4,515,000 across a supply of 12.9 million tokens. The Defiant said AVICI now trades at about 62% of that ICO price.
The company is registered as Avici Inc. in San Francisco and does not name its team on its website. On Aug. 24, it said it would be among the first neobanks to offer Coinbase’s tokenized stocks on Base.
Broader security backdrop
The report said wallet-level compromises have made up a growing share of losses in 2026, citing Trust Wallet’s $7 million browser extension hack and thefts involving Coldcard hardware wallets. DeFi logged about 70 exploits and roughly $746 million stolen in the second quarter, the most hacked quarter on record.

