Blogs

Avici Attack: How a $1M+ Exploit Hit the Solana Crypto Neobank

30 August 2026  ·  Updated 30 August 2026

Gabriel Caetano

Gabriel Caetano

DEBIT-CARD

Avici Attack: How a $1M+ Exploit Hit the Solana Crypto Neobank

The Avici attack exposed a vulnerability in outdated card infrastructure, affecting 1,685 users and draining over $500K from Avici as wider losses topped $1M. Learn how the exploit worked, where the funds went and what happened next.

attaque-avici-exploit-neobanque-crypto

Avici Attack: How a $1M+ Exploit Devastated Solana's Crypto Neobank

If you hold funds in a crypto neobank, the Avici attack is a wake-up call. On August 28, 2026, an attacker exploited an outdated card contract and drained user balances across several Solana programs, with roughly $1.1 million across several Solana-based programs, including $500,800 from 1,685 Avici users, sending the neobank's AVICI token down as much as 49%. This guide breaks down how the exploit worked, where the money went, and what it means for crypto card security. That said, the incident targeted card collateral contracts, not the underlying Solana network itself.

Holding crypto and want full control of your funds? Bleap's self-custodial Mastercard lets you spend crypto anywhere Mastercard is accepted, with 0% FX fees and up to 20% cashback. Get the Bleap card →

1. What Is Avici? The Solana Neobank Behind the Breach

AVICI is a self-custodial neobank that enables users to spend their crypto via a Visa-integrated credit card. Its model blends DeFi-native banking with real-world card spending on Solana. When customers top up their cards, those funds move into on-chain collateral contracts that back their spending.

That structure is where the risk sat. Avici's terms identify Third National as the card issuer, while Rain, a Visa principal member, provides the underlying stablecoin card infrastructure. The breach was not in Avici's core product but in a shared piece of contract infrastructure.

Why the Neobank Model Creates a Specific Risk Profile

Custodied balances sitting in on-chain contracts create concentrated, predictable targets. Admin-level permissions embedded in card contract logic are the weak point, and reliance on shared third-party infrastructure adds systemic exposure. The incident highlights a key risk for crypto card users. Even when customers control their primary wallets, funds transferred into payment systems can become subject to separate third-party smart contracts.

2. How the Avici Attack Unfolded: A Step-by-Step Breakdown

The attack was deliberate, not opportunistic. The suspected attacker's wallet received its first funding through cross-chain bridge deBridge at 13:40 UTC, when 1.79 SOL arrived from another network, then sat dormant for roughly three hours before its first call touching Avici's programs at 16:49:48 UTC. On-chain researchers also flagged a parallel phishing scheme using fake Avici sites to trick users into connecting wallets.

The "Add Admin, Then Withdraw" Exploit Explained

The core of the exploit was an administrative escalation. The hacker first ran a function called SubmitSignatures on Avici's authorization program, then they called AddCollateralAdmin on Avici's collateral program, and finally they ran WithdrawCollateralAsset to take the funds out. By inserting itself as an admin on individual accounts, the attacker bypassed user-facing checks entirely. The attacker submitted a specially created signature bundle, called AddCollateralAdmin, which incorrectly gave them admin access to more than 1,100 user collateral accounts. The attacker could then withdraw funds from those accounts one by one.

The Smart Contract Vulnerability at the Core

The flaw lived in permission logic. The issue involved an outdated signature and permission check in infrastructure provided by Rain, Avici's card-issuing partner. Critically, on-chain admin escalation should require multi-signature or time-lock safeguards. Instead, both affected programs were upgradeable and shared one upgrade authority, a standard account rather than a multisignature setup.

3. Stolen Funds and the Tornado Cash Laundering Trail

Once drained, the money was quickly obscured. The stolen stablecoins were swapped into solana (SOL), bridged to Ethereum and ultimately sent through crypto mixer Tornado Cash. Tornado Cash pools deposits from many users and breaks the on-chain link between source and destination, making funds far harder to trace. This is why recovery is so difficult once assets pass through a mixer, and why blockchain analytics firms are typically engaged to follow the trail before laundering completes.

4. Scale of the Breach: 1,685 Affected Users and $1M+ in Losses

The confirmed Avici figure landed at $500,859.22 drained from customer card balances across 1,685 users. The primary target was card collateral accounts. The exploit was limited to Solana card contracts holding balances added through its Top Up system. Regular Solana and EVM wallets, along with EVM card balances, onramps, offramps and swaps, were not affected. The drain moved fast: the attacker address ultimately signed 14,672 transactions, including 2,344 failed attempts.

Your crypto should stay under your control, not locked in someone else's contract. With Bleap's self-custodial Mastercard, you keep control of your funds while spending anywhere, with 0% FX fees and up to 20% cashback. Open a Bleap account →

5. AVICI Token Crash: The Market Reacts

The market reacted immediately. AVICI fell from a 24-hour high of $0.43 to a record low of $0.217 before recovering to around $0.378. The crash reflected a collapse in confidence over custodied funds and protocol security. Worse, following the exploit the AVICI token fell by about 39% in 24 hours, touching a new all-time low, leaving it down by over 96% from the peak of $7.61 that it hit in November 2025. Sharp sell-offs like this are a familiar pattern after DeFi security exploits.

6. Avici Incident Response: From Attack to Acknowledgment

Avici's first public word came quickly, if cautiously. Avici acknowledged the situation about one hour and 53 minutes after the first reported transaction, writing that it was aware of an issue affecting card balance withdrawals and working directly with relevant partners. The company did not call the event an exploit, confirm the loss amount, or say how many customers were affected. Beyond public statements, the firm submitted an official complaint to the FBI's Internet Crime Complaint Center.

7. The Rain Infrastructure Hack Connection

The root cause traced back to Rain, not Avici's own code. Rain identified the vulnerability in an outdated version of its Solana contracts used by Avici and a small number of other programs. Every deployment still running the affected version has since been upgraded, with no further unauthorized activity detected after the fix. Because the same contract served multiple platforms, the damage spread beyond Avici. Tria, another crypto neobank, reported that 636 users were affected, resulting in losses totaling more than $430,000. Investigation details were still emerging at publication.

8. Avici's Reimbursement Plan: What Affected Users Need to Know

Avici moved fast on compensation. Avici announced that it restored affected balances fully and added 10% cashback to withdrawn amounts. The company confirmed the fix as well: refunds are processed in full, with an extra 10% cashback, the Solana contract has been updated, and no further related activity has been seen. Affected users were asked to check their restored balances directly, and the safest place to monitor updates remains Avici's official X account and support channels rather than third-party links.

9. Broader Implications for DeFi and Crypto Neobank Security

The Avici attack exposes how permission design, not exotic bugs, drives modern losses. As neobanks embed DeFi infrastructure, their attack surface grows. The fixes are well known: multi-sig admin controls, time-locks, independent audits, and insurance. Sobering context comes from the wider data: a report documented over 245 incidents between January 2025 and July 2026, totaling $3.63 billion in losses, and most attacks exploited infrastructure, third-party services, governance, or human error rather than bugs inside the audit's scope.

Where you hold and spend crypto matters. A self-custodial setup that keeps control in your hands changes your risk profile. Bleap is a fintech card company built around a self-custodial Mastercard, with 0% FX fees, up to 20% cashback, no monthly subscription, and fee-free crypto trading with no gas costs across supported networks including Solana and Arbitrum. It is a debit card you can use anywhere Mastercard is accepted, not a bank and not a place to lock funds behind admin keys you do not control.

Feature

Avici (pre-incident)

Bleap

Custody

Self-custodial wallets, custodied card balances

Self-custodial

FX fees

Card-dependent

0%

Cashback

Standard

Up to 20%

Crypto trading

Card spending focus

Fee-free, no gas costs

Monthly fee

Varies

€0

ATM withdrawals

Varies

Free, up to €400/month (increasing soon)

Card network

Visa

Mastercard debit

Want to buy and spend crypto with no fees? Bleap offers fee-free trading with no gas costs and a self-custodial Mastercard with 0% FX fees and up to 20% cashback. Get started with Bleap →

Frequently Asked Questions About the Avici Attack

What is the Avici exploit and how did it work?

The attacker used an "Add Admin, then withdraw" sequence. The attacker called SubmitSignatures on Avici's authorization program, followed by AddCollateralAdmin on its collateral program, then WithdrawCollateralAsset to pull funds out, exploiting an outdated Rain card contract.

How many users were affected by the Avici attack?

1,685 users were affected by the exploit, which represents $500,859.22 in card balances. The exposure was limited to card collateral accounts, not self-custodial wallets.

Were stolen funds recovered after being sent through Tornado Cash?

Recovery is extremely difficult. Following the theft, the stablecoins were converted to Solana, transferred across the bridge to Ethereum, and subsequently routed through the Tornado Cash mixing service, which breaks on-chain traceability.

Will Avici reimburse users affected by the hack?

Yes. The Avici team refunded affected users in full and added 10% cashback after identifying and fixing the contract issue.

Is there a connection between the Avici hack and the Rain Infrastructure breach?

Yes. Rain identified the vulnerability in an outdated version of its Solana contracts used by Avici and a small number of other programs, making Rain's infrastructure the shared root cause.

Why did the AVICI token crash after the attack?

Confidence collapsed. AVICI fell 49.4% in 24 hours to a record low of $0.2175, driven by fears over custodied funds and protocol security.

Conclusion: Lessons from the Avici Attack

The Avici attack cost users over $500,000 across 1,685 accounts, executed through an "Add Admin" exploit and laundered via Tornado Cash. The full reimbursement plus 10% cashback is a positive signal, but the incident exposes real gaps in crypto neobank contract design, especially around admin permissions and shared infrastructure. Expect stronger audit requirements and more user vigilance ahead. If you want full control of how you spend crypto, Bleap's self-custodial Mastercard puts your funds in your hands, with 0% FX fees, up to 20% cashback, and fee-free trading.

A smarter way to spend, send, earn and trade

Key Takeaways Section Image
  • debit-card

Related articles