Avici said its card-issuing partner Rain identified a vulnerability in a version of a Solana card contract used by Avici and a small number of other programs. The contract has since been upgraded across all programs, with no further unauthorized activity observed. Avici said only the separate Solana contract holding card balances was affected, while funds in users’ self-custodial Solana and EVM wallets remained safe. A total of 1,685 users were affected, representing $500,859.22 in card balances. All affected users will receive full refunds, and Avici has filed a report with the FBI’s Internet Crime Complaint Center.