Solana Neobank Avici förlorar över 1 miljon dollar efter att angripare utnyttjat Rain-utfärdat kortkontrakt
Card balances are supposed to be the boring part of crypto. You lock some USDC, spend it like a normal Visa card, and the smart contract handles the rest. Nobody expects the "boring part" to be the attack surface. On August 28, that's exactly what happened to Avici, a Solana-based neobank that markets itself as self-custodial down to the wallet level.
An attacker drained collateral straight out of user card vaults, funds that Avici's own documentation says only a user's wallet can touch. The company confirmed the breach on X within roughly two hours of the first theft, writing that it was " aware of an issue affecting card balance withdrawals and are closely monitoring the situation," while it worked with partners on a fix.
How The Money Moved
On-chain sleuths reconstructed the attack path fairly quickly: the exploiter called SubmitSignatures on Avici's authorization program, then AddCollateralAdmin on the collateral program, and finished with WithdrawCollateralAsset to pull the funds out. In plain terms, the attacker granted themselves admin rights over accounts they had no business touching, then walked out with what was inside.
An independent researcher, @inno_sol, was tracking the drain live and flagged it as active on X, noting a wallet address and an amount that kept climbing as the attack continued in real time. That's part of why the final number is messy. Early on-chain estimates put the damage above $1 million, and the attacker's wallet did briefly hold roughly 10,005 SOL, worth around $1.07 million at the time, plus about $11,600 in USDC and USDT. Once things settled, Avici's own reconciliation and DefiLlama's hack tracker both landed on a smaller, more precise figure: $500,859.22, affecting 1,685 users. I'd take the lower number as the operative one since it's the one tied to an actual refund commitment, but it's worth sitting with the fact that a $500K breach briefly looked, in real time, like a $1M one. That gap is basically the fog of war in crypto security reporting.
Rain, and Where Tria Fits In
The root cause traces back to Rain, the stablecoin payment infrastructure provider that issues Visa- and Mastercard-linked cards for a whole roster of crypto neobanks. Avici said Rain identified the flaw in "a version of a Solana card contract used by Avici, and a small number of other programs " before patching it across the board.
That phrasing matters, because Avici isn't the only Rain client. Tria, another self-custodial card app that has processed north of $100 million in transaction volume, also runs its international card program on Rain's issuing infrastructure, according to its own card terms. Tria itself posted about the situation on X, in a thread the company published as the story developed. I wasn't able to independently confirm, through public reporting, that Tria user funds were actually taken, and no outlet I checked has published loss figures for Tria the way they have for Avici. So take the shared-infrastructure link as established and the shared-losses claim as unconfirmed until Tria or Rain says otherwise. That's a meaningfully different claim than "Tria got hacked too," and the distinction matters if you're a Tria cardholder deciding whether to panic.
The Aftermath
AVICI, the project's token, did not take it well. It fell roughly 39-49% depending on which snapshot you check, touching an all-time low near $0.2175-$0.2189 before clawing back some ground to trade around $0.27-$0.31. That's a token shedding close to a fifth of its market cap over an exploit that, by the company's own final count, moved half a million dollars. Markets don't wait for reconciliation.

Meanwhile, the stolen SOL didn't sit still. Reports tracked roughly 10,000 SOL converted into about $1.02 million in USDC. From there it hopped chains and came out the other side as around 418 ETH, which landed in Tornado Cash. Mixing through Tornado Cash is the default final move for anyone trying to make tracing someone else's problem.
Not An Isolated Week
Avici wasn't the only name in the incident log that week. A day later, the Ethereum lending protocol Ajna lost about $775,000 to what monitoring firm Defimon Alerts described as liquidation accounting manipulation, with roughly $173,700 of that coming from a single syrupUSDC pool. Defimon says it flagged the setup more than an hour before the first exploit transaction and warned the team directly. Ajna didn't react in time.
None of this is really about smart contract bugs anymore, or at least not primarily. A CoinGecko security report covering January 2025 through July 2026 counted over 245 incidents totaling $3.63 billion in losses, and 147 of those hit protocols that had actually been audited. Compromised keys, signers, and infrastructure, not flaws an audit would catch, accounted for the overwhelming majority of what got stolen in a separate Hacken analysis of Q2 2026 losses. Avici's contract wasn't some unaudited fly-by-night deployment; it was a shared piece of card infrastructure with an upgrade authority that turned out to be a single standard account instead of a multisig. That's an operational choice, not a code review failure, and operational choices are exactly what's been getting exploited all year.
Avici says every affected user will be made whole, which is really the only option that keeps a self-custodial product credible after a week like this. But "self-custodial" as a marketing line and "self-custodial" as an actual guarantee turned out to be two different things. $500,000 walked out through the gap between them.
5% insättningsbonus upp till 100 ädelstenar

0% avgifter på insättningar och uttag.


11% insättningsbonus + FreeSpin
EXTRA 10% INSÄTTNINGSBONUS + GRATIS 2 HJULSPINN
Gratis case och 100% välkomstbonus
5 gratisfodral, daglig gratis & bonus

3 gratis casinos och en bonus på 5% på alla kontantinsättningar.

+5% till insättning


Kommentarer