Avici says the security incident that drained funds from some Solana card-balance contracts is now resolved, with every affected user refunded in full and an extra 10% cashback added on top of what was withdrawn. The update came from the company's official account on August 29, 2026, following an earlier post confirming that reimbursements were underway.
The refunds close out an incident that hit the same infrastructure behind two other cards this week. Avici's card-issuing partner, Rain, also serves Tria and Jupiter, and a shared Solana card contract was the common point of failure across all three.
The exploit and what it reached
The unauthorized transfers were limited to card-balance contracts on Solana that held funds users had moved in through Avici's Top Up flow. Money sitting in a regular Avici wallet was never exposed. According to the company, the wallets, whether Solana, EVM, or another chain, are self-custodial and stayed under user control throughout.
That split is by design. Avici keeps the spend-from-your-own-wallet balance separate from card balances, which is why you have to manually top up before spending. Combining the two would make the app simpler, but the separation is what kept the damage contained to the card contracts. EVM card balances, onramps, offramps, and swaps were also unaffected.
For a cardholder, the practical read is straightforward: if you had topped up your Solana card balance in the hours before the incident, that amount was restored and boosted by 10%. Anything held in your wallet needed no action.
Rain absorbed the cost
Rain covered all reimbursements in full. That matters because it means affected users were not left waiting on Avici's own treasury or asked to file individual claims against an insurer. The issuer identified the vulnerability, patched the Solana contract across the programs that used it, and funded the restoration.
The 10% cashback is Avici's own addition, applied to the withdrawn amount rather than to a user's whole balance. It functions as an apology payment on top of being made whole, not a rewards-rate change to the card itself.
Onchain visibility cut both ways
Avici framed the episode around a point that is easy to miss: because balances live onchain, the movement was visible and independently verifiable as it happened, rather than hidden inside a private ledger. That transparency is part of why the scope could be confirmed quickly. It also means the losses were public in real time, which is uncomfortable during an active incident but useful for verification afterward.
A full postmortem is still pending. Until it lands, the exact mechanism of the contract vulnerability has not been detailed publicly, though Rain has stated the flaw is fixed and no further unauthorized activity has been seen. Avici credited Solana, Rain, Helius, MetaDAO, ZeroShadow, and Asymmetric for their response.
The broader lesson for anyone spending stablecoins through a card sits with counterparty design. On a self-custody card, the wallet stays yours, but the moment funds move into a shared card-balance contract they inherit that contract's risk. This week showed both sides of that trade: the contract was the thing that got hit, and the wallet separation is the thing that limited it.
Overview
Avici has refunded every affected Solana card balance in full and added a 10% cashback on the withdrawn amounts, closing the active phase of an exploit that targeted a card-balance contract shared across Rain's card programs. Self-custodial wallets and EVM balances were never at risk, Rain funded the reimbursements, and the Solana contract has been patched. A full postmortem is still to come.



