The Security Incident: Legacy Contract Flaw Exposes Card Balances
On August 29, crypto banking project Avici disclosed a security incident. The issue stemmed from a vulnerability in a legacy Solana card contract utilized by its card issuance partner, Rain. The affected contract has now been upgraded across all relevant projects, and monitoring indicates no further unauthorized activity has been detected.
Scope Clarified: Core User Assets Remain Secure
Avici clarified that the exploit was limited to a standalone Solana contract dedicated to holding user card balances post-top-up. Crucially, user primary Avici wallets are architecturally segregated from these card balances. As a result, funds held in users' self-custody wallets on both Solana and EVM chains were completely unaffected and remain secure.
A thorough review confirmed that card balances belonging to 1,685 users were impacted, with total losses amounting to approximately $500,900.
Official Response: Full Refunds and Law Enforcement Engagement
In response, Avici has implemented several key measures:
- Full Refund Guarantee: The project has committed to fully reimbursing all affected users for their lost card balances.
- Law Enforcement Report: A formal report has been filed with the Internet Crime Complaint Center (IC3) of the U.S. Federal Bureau of Investigation (FBI).
- Contract Upgrades: The vulnerable contract has been replaced and upgraded to prevent similar risks.
Incident Context and Fund Movement
Earlier reports indicated the incident resulted in a total loss of approximately $1.02 million in assets. The attacker's methods involved transferring 10,000 stolen SOL to a new wallet, swapping it for roughly $1.02 million USDC, and then bridging the funds to obtain about 418 ETH, effectively moving and obfuscating the capital.