An attacker exploited a vulnerability affecting Avici, a Solana-based neobank, draining more than $1 million in total proceeds from card-related balances. Avici confirmed losses of $500,859.22 affecting 1,685 of its users and pledged full refunds.
The incident targeted an outdated version of a Solana contract operated by card issuer Rain, which powered Avici’s Visa product. Self-custodial user wallets remained unaffected; only the separate contract holding funds topped up for card spending was drained.
The Drivers of This Development
The attacker funded a new wallet with a small amount of SOL via bridge and then repeatedly called authorization and withdrawal instructions on the vulnerable contract. By chaining signature submission, administrator addition, and collateral withdrawal functions, the attacker gained unauthorized control over user collateral accounts and extracted balances. On-chain activity showed the wallet accumulating thousands of SOL plus stablecoins before bridging proceeds to Ethereum and routing them through a mixer. Rain identified the issue as impacting a limited number of programs still running the outdated contract version and upgraded those deployments. For perspective, the low setup cost relative to the extracted value highlights how authorization flaws in shared infrastructure can enable rapid, high-impact drains once discovered.
It is important to note the fundamental difference between a compromise of core self-custodial wallets and an exploit limited to a card-balance contract: users who had not moved funds into the card system were not affected, narrowing the blast radius while still causing significant losses for those who had.
Impact and Broader Context
Avici stated that all affected users will be made whole and reported the incident to the FBI’s Internet Crime Complaint Center. The AVICI token experienced sharp downward pressure amid the news. The attacker’s rapid conversion and cross-chain movement of funds complicated immediate recovery efforts.
This development sparks important discussions about security risks in crypto neobanks and shared card-issuing infrastructure. Supporters of the platforms emphasize the quick detection, contract upgrades, and commitment to full user reimbursement as responsible crisis management. Critics highlight the presence of an outdated contract version in production and the ease with which an attacker escalated privileges across multiple accounts. Analysts observe that while the absolute loss is smaller than many major DeFi exploits, the incident underscores ongoing challenges in maintaining secure, up-to-date authorization logic for consumer-facing crypto products that bridge on-chain balances to traditional payment rails.
Looking ahead, the execution of refunds and any further forensic details or law-enforcement updates will shape user confidence in Avici and similar services. This analysis is based on company statements and on-chain reporting for accuracy and reliability. Final loss figures, recovery progress, and any additional affected programs remain subject to ongoing investigation.
