Inside the Avici Exploit: On-Chain Anatomy of a Live Card Drain

How an attacker spent $190 to drain a Rain-powered Solana card contract, then bridged the proceeds to Ethereum and Tornado Cash. A full on-chain reconstruction.

Solscanner Team·Aug 28, 2026·7 min read
Inside the Avici Exploit: On-Chain Anatomy of a Live Card Drain

Today a Solana card program got drained in broad daylight. We watched it happen block by block.

@avici, a Solana-based neobank, had the balances behind its cards emptied by an attacker who spent about $190 to set the whole thing up. By the time Avici confirmed it publicly, the exploiter had already swept the funds off Solana, bridged them to Ethereum, and pushed them through Tornado Cash.

This is the full on-chain anatomy of the attack: how it was funded, how it drained, where the money went, and what the trail says about who did it. Every wallet, amount, and timestamp below is reconstructed directly from the ledger and independently verified.

What actually happened

The root cause was not Avici's wallets. Avici wallets are self-custodial and were never touched. The problem sat one layer down, in the card-balance contract operated by Avici's card-issuing partner, @raincards (Rain).

When a user tops up an Avici card, the money leaves their self-custodial wallet and moves into a shared Solana contract that holds card balances. Per Avici's own statement, Rain identified a vulnerability in a version of that card contract: an on-chain authorization flaw that let an attacker grant themselves control and pull the pooled balances. The contract has since been upgraded across every program that used it.

That last part matters, because the contract wasn't Avici's alone. Rain is the infrastructure behind a long list of neobanks, and researchers flagged users of other Rain-powered programs (including @useTria and @Solayer_Pay) drained in the same event. Avici's own reconciliation puts its share at $500,859.22 across 1,685 users, every one of whom Avici says will be refunded in full. That is Avici's slice. Because the same contract sat under multiple brands, the drainer collected from several programs at once, and our tracing of the bridged proceeds (below) lines up with the researcher consensus of a total north of $1M.

The $190 setup

The attacker's operational wallet on Solana is:

FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj

It was created today, 13:40 UTC, and funded with a single cross-chain transfer: about 1.79 SOL (roughly $190) delivered through the deBridge bridge. That's it. Just enough gas to operate. The gas came from Ethereum, via a deBridge order whose origin was a brand-new, single-use Ethereum wallet (0xa1a15f1b0d4878873f2933573e4385ab1e4df25c, one transaction in its entire history) that swapped about 0.08 WETH to USDC through PancakeSwap and bridged it over.

Draining began at 16:49 UTC and ran for hours. The wallet signed and paid the fee on every transaction itself, at machine speed: more than 21,000 transactions in a single afternoon. This was an automated drainer, not a person clicking a mouse.

The mechanism shows up clearly on-chain. Nearly every drain transaction invokes Solana's Ed25519 signature-verification program alongside a custom program (CWgkFB7ngUc9cGD1LryyhP7h6xYWtwrAjhSKKCoR1gkz). That is the fingerprint of signed-authorization draining: the attacker replaying an authorization they should never have had, converting a contract-level admin flaw into a firehose of transfers into their own wallet. Small amounts per victim, enormous count.

Where the money went

Once the draining slowed, the attacker converted and moved everything out. Starting around 18:52 UTC they swept the drainer, and the Solana wallet was empty by 19:26 UTC.

The exit route:

  1. Swap. Drained USDC and USDT were swapped to SOL across Solana DEXs (Jupiter, Orca, Raydium, Meteora). The wallets on the other side of those swaps are ordinary DEX liquidity and market-maker bots, not the attacker. This is worth stressing, because it is a common tracing trap: a wallet that touches drained funds through a swap is a counterparty, not a suspect.
  2. Relay. The consolidated SOL was pushed through fresh relay wallets the drainer funded directly, chiefly MsaXH6cGDahPQDwJjFYod7RW8QLVDZGByywWvwQ9TFu, with a final relay (7XigoEaHxpoHp819fnajGqsz329Lve9c2SXSq8KaFRVf, 887 SOL) in the last transaction.
  3. Bridge. The SOL was converted to USDC and sent through deBridge, Solana to Ethereum, in two orders totalling 456 ETH, delivered to a fresh Ethereum wallet, 0x2ce21e4921d3eb116526c3651dac0257657338d5.
  4. Mix. That wallet forwarded all of it, 455.9 ETH (about $1.1M), into Tornado Cash (0xd90e2f925da726b50c4ed8d0fb90ad053324f31b) between 19:20 and roughly 20:00 UTC.

So the confirmed laundering path is: Solana card contract, to drainer, to DEX swaps, to deBridge, to Ethereum, to Tornado Cash. The same bridge that funded the $190 setup was used to carry the proceeds out.

The timing makes one thing clear. The stolen stablecoins sat concentrated in a single, known wallet for the hours the drain was running, before they were swapped and bridged. That was the window to freeze the USDC, and researchers have pointed out that Circle did not act on it in time.

Who funded it: the EVM trail

The Solana proceeds die at Tornado Cash by design. The identity question does not run through the washed proceeds. It runs through the funding side, the Ethereum wallets that stood the operation up. That trail is more revealing.

Tracing the $190 gas backwards:

Gate.io  >  0x96d0471a…  $16.3M hub  >  0x22a10b43…  treasury  >  0x775028b2ce…  operational hub  >  0xa1a15f…  single-use  >[deBridge]>  FVNFzq (Solana)

Here is the strongest lead. Trace the funding of both hubs all the way back and they converge on the same place. The treasury and the launderer were each first gas-funded, in January 2025, from the same Gate.io hot wallet (0x0d0707963952f2fba59dd06f2b425ace40b492fe). Exchange hot wallets serve millions of users, so a shared hot-wallet origin is a lead, not a fingerprint. But it is the earliest KYC touchpoint the operation leaves, and it is shared across both branches, which is not what you would expect from two unrelated wallets.

The operator's tradecraft is consistent throughout: fresh single-use wallets, address poisoning for noise, a mesh of self-owned vanity-patterned wallets, and laundering through CIS-aligned processors (Cryptomus, Rapira) and bridges (deBridge, Symbiosis). No cluster wallet carries an ENS name, a public label, or a social handle. The dominance of Cryptomus and Rapira points to a Russian or CIS-based operation.

The person cannot be named from the chain alone. That is what the mixing and the disposable wallets are for. But the trail is not dead. The funding side terminates at KYC venues: Gate.io at the genesis of both branches, Kraken ($1.35M through the treasury), and Coinbase on the laundering hub. Those are the real identities behind the deposit accounts, and it is why Avici's report to the FBI's IC3 matters.

Full wallet reference

Solana

AddressRole
FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEjThe drainer (now emptied)
CWgkFB7ngUc9cGD1LryyhP7h6xYWtwrAjhSKKCoR1gkzDrainer program (signed-authorization)
MsaXH6cGDahPQDwJjFYod7RW8QLVDZGByywWvwQ9TFuPrimary relay for the deBridge exfil
7XigoEaHxpoHp819fnajGqsz329Lve9c2SXSq8KaFRVfFinal relay (887 SOL)

Ethereum

AddressRole
0xa1a15f1b0d4878873f2933573e4385ab1e4df25cSingle-use wallet that bridged the $190 gas
0x2ce21e4921d3eb116526c3651dac0257657338d5Exfil landing wallet (456 ETH in, all to Tornado)
0xd90e2f925da726b50c4ed8d0fb90ad053324f31bTornado Cash
0x775028b2ce02844e8947905e4d655940a76cf559Operational hub (built 8 days pre-hack)
0x22a10b43952479f7306e147789aed8e19a00fa7bTreasury (Kraken $1.35M)
0x96d0471a061593e20f0ebc8c5b8b2d056862aeffLaundering / OTC hub ($16.3M, Coinbase, Cryptomus, Rapira)
0x0d0707963952f2fba59dd06f2b425ace40b492feGate.io hot wallet (genesis gas-funder of both branches)

Minor findings and other wallets

Not everything a drainer touches is the drainer. A few notes so the picture is not misread:

Timeline (August 28, 2026, UTC)

TimeEvent
13:38Ethereum origin wallet funded
13:40deBridge delivers about $190 gas to the Solana drainer
16:49Draining begins
~18:52Attacker starts sweeping the pooled funds
19:01 to 19:58~456 ETH bridged to Ethereum via two deBridge orders
19:20 to ~20:00455.9 ETH deposited into Tornado Cash
19:26Solana drainer wallet emptied

The takeaway

Two things stand out.

The attacker's edge wasn't a zero-day on Solana. It was a shared-infrastructure authorization bug in a card contract that dozens of programs quietly relied on. When one contract sits under many brands, one flaw drains all of them, and most users never knew their card balance lived in a pool they didn't control.

And the money didn't vanish into thin air. Every step, the $190 gas, the deBridge hops, the swaps, the 455.9 ETH into Tornado, the Gate.io genesis funding and the Kraken and Coinbase throughput on the way in, is written on-chain, permanently, for anyone willing to read it. Anonymity on-chain is a choice the attacker has to keep making at every hop, and they only have to slip once.

That reading is exactly what Seek, our on-chain investigation dashboard, exists to do: trace funds across wallets, bridges, and chains, separate the counterparties from the culprits, and turn a wall of transactions into a story you can follow. We reconstructed this entire attack from the public ledger. So can you.

Get started

Start tracing wallets

Paste an address or token and get funding sources, wallet connections, and a bundle verdict in seconds. Free credits every month.

More posts