Rain’s Old Card Contract Exploited: $1.1 Million Withdrawn, AVICI Drops 49%
A vulnerability in an outdated Rain card contract led to the withdrawal of approximately $1.1 million from several programs, affecting Avici and Tria users, while the refund date remains uncertain.
A security vulnerability in an old contract used in crypto card infrastructure affected several Solana-based programs. According to information reported by CoinDesk, approximately $500,800 belonging to Avici users and over $430,000 belonging to Tria users were lost in the attack.
While 1,685 users were affected at Avici, Tria announced the number of users harmed by the attack as 636. Following the incident, Avici’s AVICI token dropped from its 24-hour level of $0.43 to as low as $0.217. The token later recovered to approximately $0.378. Tria’s token also lost more than 10% in value at one point.
Crypto card balances are held in a separate contract
Avici stated that the attack did not reach users’ self-custody wallets. The issue occurred in a separate contract that holds funds loaded for spending on cards. While assets in users’ wallets remained unaffected, card balances could be withdrawn due to the vulnerability in this contract.
Rain explained that the vulnerability originated from an old contract version and that it has updated all programs using this version. The company reported that no new unauthorized transactions have been detected following the update.
Avici and Tria announced that they will fully refund the balances of affected users. However, it has not yet been disclosed when the refunds will be made or from which source the payments will be covered. Avici also reported the incident to the FBI’s Internet Crime Complaint Center.
The total loss of approximately $1.1 million suggests that some Rain-supported programs other than Avici and Tria may have also been affected. The identities of these programs and the distribution of the losses they incurred have not been shared.