BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Policy

Avici Hack Suspected: $600K Drained From Solana Neobank

Avici Hack Suspected: Solana Neobank Loses Over $600K Avici Hack Suspected reports surfaced after SolanaFloor flagged unusual activity on it , a Solana ecosystem-based neobank, with more than

AnonymousCryptoCompass newsroom
August 29, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for policy coverage.

Avici Hack Suspected: Solana Neobank Loses Over $600K

Avici Hack Suspected reports surfaced after SolanaFloor flagged unusual activity on it , a Solana ecosystem-based neobank, with more than $600,000 drained from user card balances.

SolanaFloor's report stated that it "has reportedly been hacked," triggering immediate concern across the crypto community. SolonaFloor Official Tweet

Avici quickly acknowledged the situation, confirming that its card balance withdrawal function was experiencing anomalies and that the team was working with partners to investigate.

Crypto commentary channel WuBlockchain also covered this news in a tweet, citing SolanaFloor's original report on the suspected Avici breach.WuBlockchain Official Tweet

As the incident progressed, on-chain data showed the drain accelerating, with more than $1 million passing through the attacker's wallet since 16:49 UTC. 

The platform's native token, $AVICI, fell nearly 49% to a record low as news of the exploit spread across the Solana ecosystem.

What Happened in the Avici Hack Suspected Incident?

Here is a quick timeline of how the situation unfolded:

  • SolanaFloor first reported the suspected breach, noting funds were being drained from user accounts.

  • They confirmed anomalies in its card balance withdrawal system shortly after.

  • Rain, Avici's card-issuing partner, identified the root cause as an outdated Solana contract.

  • Avici issued a full public update confirming the scope and refund plan.

How Did the Solana Card Hack Happen? On-Chain Breakdown

According toRain's official statement, the company's monitoring systems discovered a vulnerability impacting a small number of programs using an outdated version of its Solana contracts. Rain Official Tweet

Other programs were not affected. Rain stated it has since upgraded all impacted contracts, resolving the issue, and is now working with third-party forensics experts, law enforcement, and regulatory authorities to complete the investigation.

Per this analysis, the attacker exploited an authorisation flaw rather than a stolen deploy key. 

The method involved submitting a signature bundle, calling an admin function to gain elevated access, and then withdrawing funds, all without the program itself being upgraded or replaced. 

The analyst also clarified that this was not a treasury-level drain, since every dollar came out of individual user accounts rather than a central pool.

Avici Confirms Refunds After the Suspected Breach

InAvici's official update, the neobank clarified the scale of impact and its remediation plan:Avici Official Tweet

Detail

Figure

Users affected

1,685

Card balance amount impacted

$500,859.22

Wallet funds affected

None

Refund status

Full refund confirmed

Avici also confirmed it has filed a report with the FBI's Internet Crime Complaint Center (IC3) and apologized for the inconvenience caused to users.

Wallets vs Card Balances: What Was Actually Affected

A key clarification from Avici separates this incident from a full platform compromise:

  • Avici wallets are self-custodial, meaning users retain control, and were not affected.

  • Card top-ups move into a separate Solana contract holding card balances   only this contract was impacted.

  • Funds in Avici's Solana and EVM wallets remain safe and untouched.

This distinction matters for anyone following crypto news today, since it shows the exploit was isolated to a specific card-balance contract rather than the broader Solana ecosystem infrastructure or Avici's core wallet system.

The Bigger Picture

Incidents like this remain a recurring theme in crypto news, highlighting how even reputable Solana-based platforms can carry residual risk from third-party contract dependencies. 

Analysts note that swift disclosure, contract upgrades, and full refund commitments as seen here are becoming the expected standard for crypto neobanks responding to smart contract vulnerabilities.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. The details mentioned are based on official statements and on-chain data available at the time of writing and may be updated as the investigation progresses. Readers should conduct their own research before making any financial decisions related to Avici or the ecosystem.