Summary
An attacker exploited a vulnerability in an outdated Rain card smart contract on August 28, 2026, draining approximately $1.1 million across two Solana-based crypto neobanks, Avici and Tria, and causing the Avici AVICI token to collapse 49 percent from its 24-hour high to a record low of $0.217 before partially recovering. Avici, a self-custodial neobank that enables users to spend cryptocurrency via a Visa-integrated card, lost approximately $500,800 from 1,685 affected users. Tria, a separate crypto neobank using the same Rain card infrastructure, lost more than $430,000 from 636 affected users. The attack chain exploited three functions in sequence: the attacker first called SubmitSignatures on Avici's authorization program, then called AddCollateralAdmin on the collateral program, and finally called WithdrawCollateralAsset to move the funds. The vulnerability resided in card-funding contracts that hold users' stablecoin deposits after they top up their cards for spending. Self-custodial wallets on Solana and Ethereum-compatible networks were not affected. Both Avici and Tria confirmed full refunds for all affected balances. Avici said the card-funding contracts were separate from its self-custody infrastructure and that the self-custodial design of the broader system limited the blast radius. Rain, which provides the card contract infrastructure used by both neobanks, has not issued a public statement.
Timeline
| Date | Event |
|---|---|
| Aug 28, 2026 17:00 UTC | Attacker begins drain of Avici and Tria card-funding contracts — exploit chain: SubmitSignatures, AddCollateralAdmin, WithdrawCollateralAsset |
| Aug 28, 2026 | Avici posts on X acknowledging issue with card balance withdrawals — investigation begins |
| Aug 28, 2026 | AVICI token drops 49% from $0.43 to record low of $0.217 — partially recovers to $0.305 |
| Aug 28, 2026 | Total drain confirmed: Avici $500,800 from 1,685 users, Tria $430,000+ from 636 users |
| Aug 29, 2026 | Avici and Tria both pledge full refunds to affected users — self-custodial wallets confirmed unaffected |
| Aug 30, 2026 | Rain has not issued a public statement — investigation ongoing |
Domain Intelligence
| Domain | Score | DKIM | SPF | DMARC | Status |
|---|---|---|---|---|---|
| avici.io | 70.57 | ✓ | ✓ | ✓ | Live |
Context
avici.io scores 70.57 — a score reflecting a young domain with a developing network graph position at the time of capture. Crypto neobanks occupy a specific risk position in the self-custody security landscape. The value proposition is explicit: users retain custody of their funds through self-custodial wallets while gaining the usability of a conventional payment card. The card-funding contract that bridges those two worlds is where the trust model is most exposed. Self-custody protects the primary wallet. The contract that holds card-spending deposits operates under different custody assumptions and, in this case, under a different security posture than the wallets it was designed to serve. The Rain card contract infrastructure affected in this exploit was described as outdated at the time of exploitation. Both neobanks pledged full refunds, which is the correct response. The open question is whether the Rain card contract infrastructure shared by other neobanks carries the same vulnerability.
The Trust Observatory · thetrustobservatory.com · August 30, 2026