News linked to both this project and an event.
Odaily News, Avici announced that its card partner Rain discovered today a vulnerability in an old Solana card contract used by Avici and a few other projects. The relevant contract has now been upgraded across all projects, and no further unauthorized activity has been detected. This incident only affected the standalone Solana contract used to hold post-deposit card balances; users' Avici wallets and card balances are isolated from each other, and funds in Solana and EVM self-custody wallets are safe and unaffected. Upon review, a total of 1,685 users were affected, with combined card balances of approximately $500,900. Avici has committed to fully refunding card balances to all affected users and has filed a report with the FBI's Internet Crime Complaint Center (IC3). Previously reported, Avici, a crypto banking project, saw its native token AVICI allegedly suffer a hacker attack, with losses of approximately $1.02 million. The attacker transferred 10,000 SOL stolen from the project to another wallet, converted it into approximately $1.02 million USDC, and then swapped the funds into approximately 418 ETH via cross-chain operations.
Avici stated that its card-issuing partner, Rain, discovered a vulnerability in a specific version of the Solana card contract used by Avici and a few other projects. The relevant contracts have since been upgraded, and no further unauthorized activity has been detected to date. Avici clarified that user wallets and card balances are independent, meaning funds in Solana and EVM wallets remain unaffected; this incident only impacted the isolated Solana contract designated for storing card balances. Current reconciliations indicate that 1,685 users were affected, involving card balances totaling $500,859.22. All affected users will receive full refunds.