Trusted independent reportCross-border relevantPublication date verified
CoinDesk
A $1.1 million crypto card hack crashed a neobank's token 49%
WHAT HAPPENED
CoinDesk reports that an outdated Rain card-funding contract was exploited across several Solana-based programs, with roughly USD 1.1 million traced on-chain. Avici said USD 500,800 was taken from card balances belonging to 1,685 users, while Tria reported more than USD 430,000 lost across 636 users. Avici said the incident was limited to funds moved into the card contract after top-up and did not affect users' self-custodial wallets; Avici and Tria each pledged full reimbursement.
PUBLISHED August 29, 2026SOURCE CoinDeskLANE Web3 & stablecoin payments
KEY FIGURES
approximately USD 1.1 million
Total loss traced on-chain across affected programs
USD 500,800; 1,685 users
Avici-reported affected balances and users
more than USD 430,000; 636 users
Tria-reported affected balances and users
49%
Maximum reported AVICI token decline from its 24-hour high
WHAT TO WATCH NEXT
Watch whether follow-up sources disclose where the capital is deployed, product integration, customer migration, and corridor expansion. Also confirm the regulatory setup for the stablecoin, custody, and fiat on/off ramps.
Independent CoinDesk report using company incident statements, public terms and on-chain transaction data. Loss allocations, affected-user counts, remediation and reimbursement commitments are attributable to Avici, Tria and Rain; the complete affected-program list, reimbursement timing and independently audited controls are not established.
The page already presents the summary and analysis. This section keeps only the copy, download, and technical source record without repeating the same reading view.
View technical text
# A $1.1 million crypto card hack crashed a neobank's token 49%
> Evidence tier: B1
> Evidence type: Independent digital-asset report using named company incident disclosures and on-chain transaction data
> Source: [CoinDesk](https://www.coindesk.com/web3/2026/08/29/a-usd1-1-million-crypto-card-hack-crashed-a-neobank-s-token-49)
> Published: 2026-08-29
> Captured: 2026-08-30T02:48:53.178Z
## Source summary
CoinDesk reports that an outdated Rain card-funding contract was exploited across several Solana-based programs, with roughly USD 1.1 million traced on-chain. Avici said USD 500,800 was taken from card balances belonging to 1,685 users, while Tria reported more than USD 430,000 lost across 636 users. Avici said the incident was limited to funds moved into the card contract after top-up and did not affect users' self-custodial wallets; Avici and Tria each pledged full reimbursement.
## Why it matters
The incident identifies a concrete payment-security boundary: a wallet can remain self-custodial while funds loaded for card spending move into a third-party contract with separate administrative risk. CoinDesk reports that Rain upgraded every program using the outdated version and saw no further unauthorized activity, but the affected programs are not fully identified and the companies do not disclose reimbursement timing, funding, independent loss verification or whether controls were audited. The token's 49% intraday fall is market context, not a payment-loss measure or proof of customer adoption.
## Key numbers
- **Total loss traced on-chain across affected programs:** approximately USD 1.1 million
- **Avici-reported affected balances and users:** USD 500,800; 1,685 users
- **Tria-reported affected balances and users:** more than USD 430,000; 636 users
- **Maximum reported AVICI token decline from its 24-hour high:** 49%
## Topics and entities
- Industry lane: Web3 & stablecoin payments
- Entities: Avici / Rain / Tria
- Web3 payments
- Payment infrastructure
## Evidence and credibility note
Independent CoinDesk report using company incident statements, public terms and on-chain transaction data. Loss allocations, affected-user counts, remediation and reimbursement commitments are attributable to Avici, Tria and Rain; the complete affected-program list, reimbursement timing and independently audited controls are not established.
Date evidence: Automatically verified from JSON-LD datePublished: 2026-08-29T23:49:17.603Z
## First-party corroboration
No directly corresponding A1 company announcement is currently linked.
## Original-source traceback
[Open the original CoinDesk report](https://www.coindesk.com/web3/2026/08/29/a-usd1-1-million-crypto-card-hack-crashed-a-neobank-s-token-49)
---
This is a structured Payments Hot Markdown source summary derived from external reporting. Use the original link above to read the publisher's article; copyright remains with the original publisher.