🚨👀💳 CRITICAL SECURITY WARNING FOR SOLANA CRYPTO CARD USERS

An on-chain exploit hit crypto card infrastructure on 28 August 2026, draining hundreds of thousands of dollars from card spending balances across multiple applications.

The root cause was an outdated smart contract used by crypto card provider Rain. A vulnerability in the authorization code allowed an attacker to bypass permissions, assign admin status to their own wallet, and withdraw deposited card collateral directly from user vaults.

The damage across connected platforms:
🔴 Avici: $500,859.22 stolen from 1,685 cardholder accounts
🟡 Tria: Unauthorized USDC and USDT withdrawals detected before containment
🟢 Solayer: Confirmed user funds and contracts remained completely safe

Why did multiple apps get hit together?
Most crypto card apps do not build banking rails and vault code from zero. They connect to shared Card-as-a-Service providers. Because several apps ran the exact same underlying Rain smart contract code, one flaw in the shared vault logic exposed every app using that outdated version.

Current status:
🔵 Avici confirmed that all 1,685 affected users will receive a 100% full refund, and reported the case to federal cybercrime authorities.
🔵 The AVICI token dropped by over 40% following the news.
🔵 Rain confirmed all vulnerable programs were upgraded to secure versions, halting the exploit.

Security rule: Never store life savings in crypto card spending balances. Treat card vaults as disposable spending wallets and only deposit what you plan to spend immediately.

do you use crypto cards for daily spending? 👇

#CryptoCards #Solana #CyberSecurity #DeFi #Web3