Today a Solana card program got drained in broad daylight. We watched it happen block by block.
@avici, a Solana-based neobank, had the balances behind its cards emptied by an attacker who spent about $190 to set the whole thing up. By the time Avici confirmed it publicly, the exploiter had already swept the funds off Solana, bridged them to Ethereum, and pushed them through Tornado Cash.
This is the full on-chain anatomy of the attack: how it was funded, how it drained, where the money went, and what the trail says about who did it. Every wallet, amount, and timestamp below is reconstructed directly from the ledger and independently verified.
What actually happened
The root cause was not Avici's wallets. Avici wallets are self-custodial and were never touched. The problem sat one layer down, in the card-balance contract operated by Avici's card-issuing partner, @raincards (Rain).
When a user tops up an Avici card, the money leaves their self-custodial wallet and moves into a shared Solana contract that holds card balances. Per Avici's own statement, Rain identified a vulnerability in a version of that card contract: an on-chain authorization flaw that let an attacker grant themselves control and pull the pooled balances. The contract has since been upgraded across every program that used it.
That last part matters, because the contract wasn't Avici's alone. Rain is the infrastructure behind a long list of neobanks, and researchers flagged users of other Rain-powered programs (including @useTria and @Solayer_Pay) drained in the same event. Avici's own reconciliation puts its share at $500,859.22 across 1,685 users, every one of whom Avici says will be refunded in full. That is Avici's slice. Because the same contract sat under multiple brands, the drainer collected from several programs at once, and our tracing of the bridged proceeds (below) lines up with the researcher consensus of a total north of $1M.
The $190 setup
The attacker's operational wallet on Solana is:
FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj
It was created today, 13:40 UTC, and funded with a single cross-chain transfer: about 1.79 SOL (roughly $190) delivered through the deBridge bridge. That's it. Just enough gas to operate. The gas came from Ethereum, via a deBridge order whose origin was a brand-new, single-use Ethereum wallet (0xa1a15f1b0d4878873f2933573e4385ab1e4df25c, one transaction in its entire history) that swapped about 0.08 WETH to USDC through PancakeSwap and bridged it over.
Draining began at 16:49 UTC and ran for hours. The wallet signed and paid the fee on every transaction itself, at machine speed: more than 21,000 transactions in a single afternoon. This was an automated drainer, not a person clicking a mouse.
The mechanism shows up clearly on-chain. Nearly every drain transaction invokes Solana's Ed25519 signature-verification program alongside a custom program (CWgkFB7ngUc9cGD1LryyhP7h6xYWtwrAjhSKKCoR1gkz). That is the fingerprint of signed-authorization draining: the attacker replaying an authorization they should never have had, converting a contract-level admin flaw into a firehose of transfers into their own wallet. Small amounts per victim, enormous count.
Where the money went
Once the draining slowed, the attacker converted and moved everything out. Starting around 18:52 UTC they swept the drainer, and the Solana wallet was empty by 19:26 UTC.
The exit route:
- Swap. Drained USDC and USDT were swapped to SOL across Solana DEXs (Jupiter, Orca, Raydium, Meteora). The wallets on the other side of those swaps are ordinary DEX liquidity and market-maker bots, not the attacker. This is worth stressing, because it is a common tracing trap: a wallet that touches drained funds through a swap is a counterparty, not a suspect.
- Relay. The consolidated SOL was pushed through fresh relay wallets the drainer funded directly, chiefly
MsaXH6cGDahPQDwJjFYod7RW8QLVDZGByywWvwQ9TFu, with a final relay (7XigoEaHxpoHp819fnajGqsz329Lve9c2SXSq8KaFRVf, 887 SOL) in the last transaction. - Bridge. The SOL was converted to USDC and sent through deBridge, Solana to Ethereum, in two orders totalling 456 ETH, delivered to a fresh Ethereum wallet,
0x2ce21e4921d3eb116526c3651dac0257657338d5. - Mix. That wallet forwarded all of it, 455.9 ETH (about $1.1M), into Tornado Cash (
0xd90e2f925da726b50c4ed8d0fb90ad053324f31b) between 19:20 and roughly 20:00 UTC.
So the confirmed laundering path is: Solana card contract, to drainer, to DEX swaps, to deBridge, to Ethereum, to Tornado Cash. The same bridge that funded the $190 setup was used to carry the proceeds out.
The timing makes one thing clear. The stolen stablecoins sat concentrated in a single, known wallet for the hours the drain was running, before they were swapped and bridged. That was the window to freeze the USDC, and researchers have pointed out that Circle did not act on it in time.
Who funded it: the EVM trail
The Solana proceeds die at Tornado Cash by design. The identity question does not run through the washed proceeds. It runs through the funding side, the Ethereum wallets that stood the operation up. That trail is more revealing.
Tracing the $190 gas backwards:
Gate.io > 0x96d0471a… $16.3M hub > 0x22a10b43… treasury > 0x775028b2ce… operational hub > 0xa1a15f… single-use >[deBridge]> FVNFzq (Solana)
0x775028b2ce02844e8947905e4d655940a76cf559: the operational hub. It funded the drainer's bridge wallet plus roughly eight other disposable wallets, and it was running an address-poisoning spam campaign at the same time. Tellingly, this wallet was built just eight days before the hack (first funded 2026-08-20 with about $57K in one shot from the treasury), which points to deliberate, recent staging.0x22a10b43952479f7306e147789aed8e19a00fa7b: the treasury behind it. About $2.45M of lifetime exchange throughput (per Arkham), dominated by Kraken ($1.35M), with Bybit, Binance, and OKX behind it.0x96d0471a061593e20f0ebc8c5b8b2d056862aeff: a professional laundering and OTC hub the operation routed through, with about $16.3M of lifetime throughput via Cryptomus, Rapira, Binance, OKX, KuCoin, and Coinbase.
Here is the strongest lead. Trace the funding of both hubs all the way back and they converge on the same place. The treasury and the launderer were each first gas-funded, in January 2025, from the same Gate.io hot wallet (0x0d0707963952f2fba59dd06f2b425ace40b492fe). Exchange hot wallets serve millions of users, so a shared hot-wallet origin is a lead, not a fingerprint. But it is the earliest KYC touchpoint the operation leaves, and it is shared across both branches, which is not what you would expect from two unrelated wallets.
The operator's tradecraft is consistent throughout: fresh single-use wallets, address poisoning for noise, a mesh of self-owned vanity-patterned wallets, and laundering through CIS-aligned processors (Cryptomus, Rapira) and bridges (deBridge, Symbiosis). No cluster wallet carries an ENS name, a public label, or a social handle. The dominance of Cryptomus and Rapira points to a Russian or CIS-based operation.
The person cannot be named from the chain alone. That is what the mixing and the disposable wallets are for. But the trail is not dead. The funding side terminates at KYC venues: Gate.io at the genesis of both branches, Kraken ($1.35M through the treasury), and Coinbase on the laundering hub. Those are the real identities behind the deposit accounts, and it is why Avici's report to the FBI's IC3 matters.
Full wallet reference
Solana
| Address | Role |
|---|---|
FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj | The drainer (now emptied) |
CWgkFB7ngUc9cGD1LryyhP7h6xYWtwrAjhSKKCoR1gkz | Drainer program (signed-authorization) |
MsaXH6cGDahPQDwJjFYod7RW8QLVDZGByywWvwQ9TFu | Primary relay for the deBridge exfil |
7XigoEaHxpoHp819fnajGqsz329Lve9c2SXSq8KaFRVf | Final relay (887 SOL) |
Ethereum
| Address | Role |
|---|---|
0xa1a15f1b0d4878873f2933573e4385ab1e4df25c | Single-use wallet that bridged the $190 gas |
0x2ce21e4921d3eb116526c3651dac0257657338d5 | Exfil landing wallet (456 ETH in, all to Tornado) |
0xd90e2f925da726b50c4ed8d0fb90ad053324f31b | Tornado Cash |
0x775028b2ce02844e8947905e4d655940a76cf559 | Operational hub (built 8 days pre-hack) |
0x22a10b43952479f7306e147789aed8e19a00fa7b | Treasury (Kraken $1.35M) |
0x96d0471a061593e20f0ebc8c5b8b2d056862aeff | Laundering / OTC hub ($16.3M, Coinbase, Cryptomus, Rapira) |
0x0d0707963952f2fba59dd06f2b425ace40b492fe | Gate.io hot wallet (genesis gas-funder of both branches) |
Minor findings and other wallets
Not everything a drainer touches is the drainer. A few notes so the picture is not misread:
- Market-maker bots, not the attacker.
FkaLnX17cXZGyeu3kZGdHCNdFMJJzBrPPYVvd18B3MZpand similar high-frequency wallets appear on the other side of the swaps. One of them ran over 15,000 swaps in about 90 minutes across every Solana DEX. It received zero direct transfers from the drainer. Its balance is trading float, not stolen funds. - Protocol vaults are swap-throughs.
7s1da8Dduu…(Jupiter Lend Supply Vault),8ekCy2jH…(Tessera V Authority AMM), andGtwzYxBQ…(Aquifer USDC Vault) are routing venues, not attacker addresses. - Two bridge orders, not one. The exfil to Ethereum went out as two deBridge orders (418 ETH and 37.5 ETH) into the same landing wallet, delivered between 19:01 and 19:58 UTC.
- A self-owned laundering mesh. The treasury's largest outflows go to a cluster of vanity-patterned wallets sharing a prefix and suffix (the
0x9396…8358family), which the operator uses to shuffle funds before touching exchanges. - The deeper genealogy is noise. Trace the funding past Gate.io and it dissolves into generic, years-old exchange plumbing from as far back as 2015. Gate is the last meaningful, operation-specific touchpoint. Everything before it is shared history that belongs to no one.
Timeline (August 28, 2026, UTC)
| Time | Event |
|---|---|
| 13:38 | Ethereum origin wallet funded |
| 13:40 | deBridge delivers about $190 gas to the Solana drainer |
| 16:49 | Draining begins |
| ~18:52 | Attacker starts sweeping the pooled funds |
| 19:01 to 19:58 | ~456 ETH bridged to Ethereum via two deBridge orders |
| 19:20 to ~20:00 | 455.9 ETH deposited into Tornado Cash |
| 19:26 | Solana drainer wallet emptied |
The takeaway
Two things stand out.
The attacker's edge wasn't a zero-day on Solana. It was a shared-infrastructure authorization bug in a card contract that dozens of programs quietly relied on. When one contract sits under many brands, one flaw drains all of them, and most users never knew their card balance lived in a pool they didn't control.
And the money didn't vanish into thin air. Every step, the $190 gas, the deBridge hops, the swaps, the 455.9 ETH into Tornado, the Gate.io genesis funding and the Kraken and Coinbase throughput on the way in, is written on-chain, permanently, for anyone willing to read it. Anonymity on-chain is a choice the attacker has to keep making at every hop, and they only have to slip once.
That reading is exactly what Seek, our on-chain investigation dashboard, exists to do: trace funds across wallets, bridges, and chains, separate the counterparties from the culprits, and turn a wall of transactions into a story you can follow. We reconstructed this entire attack from the public ledger. So can you.


