Solana Neobank Avici’s Token Plunges 49% After Card-Contract Exploit Drains Customer Balances

A Solana-based neobank that lets users spend crypto through a physical debit card became the latest reminder that “banking-style” crypto products carry the same smart-contract risk as everything else on-chain. Here’s how the Avici incident unfolded, based on the platform’s own disclosures and its card-issuing partner’s statements.
August 28: withdrawals start behaving strangely
Avici, which offers spendable card balances backed by users’ crypto holdings, confirmed “an issue affecting card balance withdrawals” on August 28. An attacker had found a way to drain customer card balances by chaining together three calls across Avici’s smart contracts: first invoking a function called SubmitSignatures on the platform’s authorization program, then calling AddCollateralAdmin on its collateral program, and finally executing WithdrawCollateralAsset to pull the funds out. The attacker’s wallet was tracked holding roughly 10,000 SOL — worth just over $1 million at the time — along with a small amount of stablecoins, and early estimates of the total damage ranged as high as $1.1 million as the situation was still being pieced together in real time.
Same day: AVICI token craters
News of the exploit hit the platform’s native AVICI token immediately. The token plunged as much as 49% from its prior 24-hour high, touching a fresh record low near $0.2175 before recovering some ground. The sharp drawdown reflected how quickly confidence evaporates for a project whose entire pitch rests on the safety of its card-and-collateral infrastructure.
The root cause: a flawed contract from a card partner
Avici doesn’t issue its own cards directly — it relies on Rain, a crypto card-issuing platform, for the underlying infrastructure. Rain traced the problem to an outdated version of a Solana card contract that Avici and a small number of other programs were still running. Once the flawed contract was identified, Rain and Avici moved to upgrade it across all affected integrations, cutting off the attack path.
Resolution: full refunds for 1,685 users
Avici announced it would make customers whole, confirming that 1,685 users would be refunded in full after the reconciled damage came in at $500,859.22 drained from card balances — lower than some of the earlier headline estimates, though initial figures reported by outside observers ranged as high as $1.1 million while the incident was ongoing. The company said refunds would include an extra 10% in cashback as compensation, and that it would continue monitoring the upgraded contract for further irregularities.
Why it matters beyond one neobank
The Avici episode is a useful case study in how “crypto debit card” products actually work under the hood: user funds sit as on-chain collateral, and a bug in the authorization or collateral-management logic can let an attacker mint themselves permission to withdraw someone else’s balance. Because Rain’s contract was shared across multiple platforms, the same flaw could have affected other card issuers running the same outdated code — a reminder that in composable crypto infrastructure, a vulnerability in one vendor’s contract can ripple across every product built on top of it.
This article is for informational purposes only and does not constitute financial advice. Crypto-linked card products carry smart-contract and custodial risk; always research a platform’s security track record before depositing funds.
Curious how crypto custody and smart-contract risk actually work? Browse more guides on Coin680’s Bitcoin Academy.
