Avici Neobank Loses Over $500K in Smart Contract Exploit

Here's what it means for you.
If you use crypto banking services, this incident highlights the importance of understanding the underlying technology and its vulnerabilities.
Why it matters
This exploit underscores systemic risks in decentralized finance (DeFi) platforms, particularly those relying on outdated smart contracts.
What happened (in 30 seconds)
- On August 28, 2026, Avici, a Solana-based neobank, suffered a smart contract exploit that drained over $500,000 from user card balances.
- The attack exploited a vulnerability in an outdated contract from card-issuing partner Rain, allowing unauthorized withdrawals from collateral accounts.
- Avici has pledged full refunds to affected users and reported the incident to the FBI, while parallel phishing campaigns have caused additional losses exceeding $600,000.
The context you actually need
- Avici operates as a self-custodial neobank, allowing users to maintain control over their funds while providing services like Visa spend cards.
- The exploit was made possible due to a flaw in a legacy smart contract, revealing the risks associated with relying on third-party contracts in DeFi.
- Phishing attacks targeting Avici users have been ongoing since late 2025, indicating a broader trend of cyber threats in the crypto space.
What's really happening
On August 28, 2026, Avici's neobank platform fell victim to a smart contract exploit that drained approximately $500,859.22 from the card balances of 1,685 users. The exploit was executed by an attacker who spent around $190 to manipulate an outdated version of a Solana contract operated by Rain, Avici's card-issuing partner. The attacker leveraged a series of chained contract calls—SubmitSignatures, AddCollateralAdmin, and WithdrawCollateralAsset—to gain unauthorized admin access to collateral accounts, enabling them to withdraw funds.
The exploit's impact was significant, as it affected multiple programs utilizing the legacy contract, with Avici's losses being the most pronounced. On-chain activity revealed that the attacker quickly transferred 10,000 SOL to obscure their tracks, bridging the funds to Ethereum and mixing them via Tornado Cash. Avici confirmed the exploit within hours, assuring users that their self-custodial wallets remained untouched and committing to full refunds for those affected.
In the aftermath, the AVICI governance token experienced a sharp decline of 40-49%, reaching record lows before a partial recovery. This incident has raised broader concerns about the security of Solana-based neobanks and the reliability of their card products. Rain has since upgraded the affected contracts to mitigate future risks, but the incident has left a lingering caution among users and investors alike.
Moreover, the parallel phishing campaigns that emerged during this period have compounded user losses, with reports indicating that these scams have collectively drained over $600,000 from Avici users. This highlights the dual threat of smart contract vulnerabilities and social engineering attacks in the crypto space, emphasizing the need for enhanced security measures and user education.
Who feels it first (and how)
- Crypto users: Individuals using Avici's services are directly impacted by the loss of funds and the potential for further phishing attacks.
- Investors in AVICI token: Those holding the token have seen significant value loss, affecting their investment portfolios.
- DeFi platforms: Other decentralized finance services may face increased scrutiny and caution from users, impacting their growth and adoption rates.
- Regulatory bodies: Increased incidents may prompt regulators to impose stricter guidelines on DeFi platforms, affecting operational frameworks.
What to watch next
- Contract upgrades: Monitor how quickly and effectively Avici and Rain implement security upgrades to prevent future exploits, as this will influence user trust.
- Market response: Watch for fluctuations in the AVICI token price and user engagement levels, which may indicate broader market sentiment towards Solana-based neobanks.
- Phishing trends: Keep an eye on the evolution of phishing tactics targeting crypto users, as these could lead to further losses and necessitate enhanced security protocols.
The exploit drained $500,859.22 from Avici users due to a smart contract vulnerability.
Increased scrutiny and caution among users of DeFi platforms will persist, impacting user engagement and investment.
The long-term effects on Avici's reputation and user base remain uncertain, as trust in the platform may take time to rebuild.
Frequently Asked Questions
- Why it matters?
- This exploit underscores systemic risks in decentralized finance (DeFi) platforms, particularly those relying on outdated smart contracts.
- What happened (in 30 seconds)?
- On August 28, 2026, Avici, a Solana-based neobank, suffered a smart contract exploit that drained over $500,000 from user card balances. The attack exploited a vulnerability in an outdated contract from card-issuing partner Rain, allowing unauthorized withdrawals from collateral accounts. Avici has pledged full refunds to affected users and reported the incident to the FBI, while parallel phishing campaigns have caused additional losses exceeding $600,000.
- What's really happening?
- On August 28, 2026, Avici's neobank platform fell victim to a smart contract exploit that drained approximately $500,859.22 from the card balances of 1,685 users. The exploit was executed by an attacker who spent around $190 to manipulate an outdated version of a Solana contract operated by Rain, Avici's card-issuing partner. The attacker leveraged a series of chained contract calls—SubmitSignatures, AddCollateralAdmin, and WithdrawCollateralAsset—to gain unauthorized admin access to collateral
- Who feels it first (and how)?
- Crypto users: Individuals using Avici's services are directly impacted by the loss of funds and the potential for further phishing attacks. Investors in AVICI token: Those holding the token have seen significant value loss, affecting their investment portfolios. DeFi platforms: Other decentralized finance services may face increased scrutiny and caution from users, impacting their growth and adoption rates. Regulatory bodies: Increased incidents may prompt regulators to impose stricter gui
- What to watch next?
- Contract upgrades: Monitor how quickly and effectively Avici and Rain implement security upgrades to prevent future exploits, as this will influence user trust. Market response: Watch for fluctuations in the AVICI token price and user engagement levels, which may indicate broader market sentiment towards Solana-based neobanks. Phishing trends: Keep an eye on the evolution of phishing tactics targeting crypto users, as these could lead to further losses and necessitate enhanced security proto
Covers blockchain, cryptocurrency news, project analysis, and market insights.
"CoinDesk is a well-established cryptocurrency and blockchain news provider, offering comprehensive insights, market data, and industry research."
— A47 Editor
A $1.1 million crypto card hack crashed a neobank's token 49%
A neobank's AVICI token plummeted by 49% following a $1.1 million hack of its crypto card system, marking a significant drop from a 24-hour high and reaching a record low before recovering slightly.
Research, news, and analysis on blockchain startups, DeFi, and regulations.
"Crypto Briefing provides research, news, and analysis on blockchain startups, DeFi, and crypto regulations with investor-focused coverage."
— A47 Editor
Avici to refund $500K after Solana card contract vulnerability
Avici has announced plans to refund $500,000 following a vulnerability discovered in its Solana card contract, which raised significant concerns regarding the security of decentralized finance (DeFi) products. This incident highlights the ongoing cha...
Real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors.
"Crypto News delivers real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors."
— A47 Editor
Avici attack drains over $1M from Solana users
An ongoing attack against the Solana-based crypto card platform Avici has drained over $1 million from user collateral accounts, causing its AVICI token to reach an all-time low. The attacker reportedly added administrators before executing withdrawa...
Research, news, and analysis on blockchain startups, DeFi, and regulations.
"Crypto Briefing provides research, news, and analysis on blockchain startups, DeFi, and crypto regulations with investor-focused coverage."
— A47 Editor
Avici neobank hacked, over $600K drained from user accounts
The Avici neobank has suffered a significant security breach, resulting in over $600,000 being drained from user accounts. This incident underscores vulnerabilities in user-driven custody models and highlights the pressing need for enhanced vigilance...