The promise of spending cryptocurrency seamlessly through a Visa card collided with harsh reality this week when an exploit in outdated smart contract infrastructure drained approximately $1.1 million from multiple Solana-based programs. The most visible casualty was AVICI, the native token of a self-custodial neobank, which plummeted 49% from its 24-hour high before staging a partial recovery.
The incident has reignited critical questions about the security architecture underlying crypto debit and credit card services, particularly as spending through such products surged past $1 billion in July alone. For users who believed their funds remained under their control, the breach exposed a crucial vulnerability in the custody handoff that occurs when crypto is loaded for card spending.
The Anatomy of a $1.1 Million Exploit
According to on-chain transaction analysis, the attacker exploited a vulnerability in an outdated version of a Rain contract—infrastructure that powers stablecoin card services for multiple crypto neobanks. Rain, which operates as a Visa principal member providing underlying card infrastructure, confirmed that its monitoring systems detected the flaw in a legacy contract version being used by Avici and several other programs.
The attack methodology was methodical and devastating. Transaction data reveals that the attacker repeatedly submitted signed authorizations to add themselves as an administrator to individual card-collateral accounts. Once administrative access was established, the attacker systematically withdrew balances from these accounts.
The stolen stablecoins followed a familiar laundering path: conversion to Solana's native SOL token, bridging to Ethereum, and ultimately routing through Tornado Cash, the sanctioned cryptocurrency mixer that remains a preferred tool for obscuring illicit fund flows despite regulatory crackdowns.
Avici reported that 1,685 of its users lost a combined $500,800 in the breach. Tria, another crypto neobank utilizing Rain's infrastructure, disclosed that 636 of its users suffered losses exceeding $430,000. The gap between the roughly $1.1 million traced on-chain and these reported figures suggests additional Rain-powered programs were compromised, though neither company has identified these services or disclosed their specific losses.
Token Carnage and Market Fallout
The market reaction was swift and punishing. AVICI, which enables users to spend cryptocurrency through Visa-integrated credit cards while maintaining self-custody of their broader holdings, cratered from a 24-hour high of $0.43 to an all-time low of $0.217—a devastating 49% collapse in a matter of hours.
The token managed to claw back some losses, trading around $0.378 at last check, but the damage to investor confidence extends far beyond the price chart. For a project positioning itself as a bridge between traditional payment rails and decentralized finance, a security breach of this magnitude strikes at the core value proposition.
Tria's token also suffered, dropping more than 10% before stabilizing. Both companies have pledged to make affected users whole, though neither has specified timelines for refunds or explained how these repayments will be funded.
For cryptocurrency investors evaluating projects in this space, the incident serves as a reminder that smart contract risk extends beyond the protocols users interact with directly. Even those who carefully track their Bitcoin investment returns may not fully appreciate the layered custody risks embedded in seemingly straightforward crypto card products.
The Custody Illusion in Crypto Card Services
Perhaps the most significant revelation from this breach involves the disconnect between marketing claims of self-custody and the operational reality of crypto card spending. Avici positions itself as a self-custodial neobank, and technically, user funds held in Avici wallets on Solana and Ethereum-compatible networks remained secure during the attack.
However, the funds that users loaded for card spending moved into a third-party contract controlled by Rain's infrastructure. This distinction—between funds users truly control and funds staged for spending through traditional payment networks—proved material when that third-party contract contained a critical vulnerability.
Rain confirmed it has since upgraded every program running the vulnerable contract version and reported no further unauthorized activity. However, the incident exposes a fundamental tension in crypto card products: integrating with legacy payment infrastructure like Visa necessarily introduces custodial chokepoints, regardless of how the broader wallet architecture is designed.
This tension becomes increasingly important as crypto card usage accelerates. Tracked spending through such products more than tripled to $1.04 billion in July, with stablecoins funding 70% of the more than 10 million transactions recorded. As adoption grows, so does the attack surface represented by these custody handoff points.
Regulatory and Recovery Implications
Avici disclosed that it has filed a report with the Federal Bureau of Investigation's Internet Crime Complaint Center, signaling that U.S. law enforcement is now involved in investigating the breach. Given the use of Tornado Cash to obfuscate fund flows, recovery prospects appear limited, though blockchain analytics firms have demonstrated increasing capability to trace funds through mixing services.
The involvement of Third National as the card issuer, combined with Rain's role as a Visa principal member, creates an interesting regulatory intersection. Traditional financial regulators may take interest in a breach affecting card infrastructure, even if the underlying exploit occurred entirely on-chain.
For affected users, the path to recovery remains unclear. Both Avici and Tria have committed to refunds, but the mechanics of fulfilling these promises—particularly for a token that just lost half its value—present significant challenges. If companies repay in fiat or stablecoins, they must source these funds from somewhere. If they repay in native tokens, users may receive assets worth substantially less than their original deposits.
Lessons for the Crypto Card Sector
The incident offers several critical lessons for the rapidly growing crypto card industry. First, smart contract auditing must extend to all infrastructure layers, including third-party dependencies like payment processor contracts. A vulnerability in an outdated contract version suggests either inadequate version management or insufficient auditing of legacy code.
Second, transparency about custody arrangements deserves greater emphasis. Marketing language emphasizing self-custody may obscure the reality that certain functions—like loading funds for card spending—necessarily involve transferring assets to contracts outside user control.
Third, the incident highlights concentration risk in infrastructure providers. Multiple neobanks relying on shared Rain infrastructure meant a single vulnerability cascaded across several platforms and thousands of users.
For Rain specifically, the breach raises questions about its contract upgrade and deprecation policies. How long had the vulnerable contract version remained in use? Why were some programs still utilizing outdated code? These questions matter not just for understanding this incident but for assessing systemic risk across other Rain-powered services.
Looking Ahead: Trust Rebuilding and Industry Standards
The coming weeks will test whether AVICI and affected platforms can rebuild user trust. Timely, transparent communication about refund processes will prove essential. So too will independent post-mortem analysis explaining exactly what went wrong and what preventive measures have been implemented.
For the broader crypto card sector, the incident may accelerate industry discussions about security standards and best practices. As traditional financial institutions increasingly explore crypto card products, establishing robust security frameworks becomes imperative—both for protecting users and for demonstrating the sector's readiness for mainstream adoption.
The billion-dollar monthly volume flowing through crypto cards represents genuine product-market fit. Users clearly want the convenience of spending cryptocurrency through familiar payment networks. The challenge now is ensuring that the infrastructure connecting decentralized assets to centralized payment rails doesn't become the sector's Achilles heel.
With the FBI now investigating and affected platforms scrambling to make users whole, the full consequences of this breach may take months to fully materialize. For now, it stands as a stark reminder that in cryptocurrency, security is only as strong as the weakest link in an increasingly complex chain of custody.