Avici Neobank Exploit Drains Over $1M From Solana Card Vaults as AVICI Token Drops 44%
At least $1 million left Avici user accounts after an attacker bypassed the Solana-based neobank's card vault system. The attacker's wallet accumulated 10,005 SOL. AVICI token dropped 44% following the exploit announcement.
Avici Neobank Exploit Drains Over $1M From Solana Card Vaults as AVICI Token Drops 44%
At least $1 million left Avici user accounts on Friday after an attacker bypassed the Solana-based neobank's card vault system, targeting balances the company had publicly claimed were accessible only to their rightful owners.
The attacker's wallet accumulated 10,005 SOL during the exploit. Estimates of the total damage diverge: one source pegs the haul above $1 million, while another puts the figure at $652,000, a gap that likely reflects the drain still being active at the time of initial reporting. Either number is a material loss for a consumer-facing crypto banking product whose entire value proposition rests on custody security.
Avici's public acknowledgment came roughly two hours after the first drain transaction hit the chain. The company said it was "aware of an issue affecting card balance withdrawals," careful language that understated what on-chain data already showed. Two hours is a long time when an attacker is actively emptying accounts. Whether the delay reflects a deliberate verification process or an operational blind spot, the optics are damaging for a platform competing on trustworthiness with both legacy banks and crypto-native alternatives.
The exploit's mechanism cuts at Avici's core marketing claim. Card vault withdrawals were presented as user-gated, meaning only the account holder could initiate them. That access control failed. The attacker found a path that the protocol's own design was supposed to make impossible. Until Avici publishes a post-mortem detailing exactly how that access control was bypassed, users have no basis to assess whether the vulnerability has been fully closed or whether remaining funds are still at risk.
AVICI, the project's native token, dropped 44% in the 24 hours following the exploit announcement. Token crashes of this magnitude after a security breach are common and often partially reverse once a recovery plan emerges, but the speed and scale of this selloff signals that market participants view the reputational damage as severe. A neobank that cannot protect card balances has a fundamental credibility problem that a patch alone cannot fix.
The Solana chain has hosted a string of high-profile exploits across its project base, from the Wormhole bridge loss of $325 million in February 2022 to various DeFi protocol failures in the years since. None of those incidents compromised Solana's base layer, and this one almost certainly did not either. The Avici vulnerability appears application-specific, a failure of the neobank's own smart contract logic or backend access controls rather than anything at the protocol level. That distinction matters for Solana's reputation, even if it offers cold comfort to Avici's users.
Fintech projects sitting at the intersection of crypto rails and consumer banking carry a particular security burden. They attract users who expect bank-grade protections while operating with startup-grade infrastructure. That mismatch has produced breaches across the sector, on Solana and elsewhere. Avici is the latest, and most acute, example of what happens when that gap is exposed.
The attacker's funds remain in the identified wallet as of this writing. No recovery mechanism, white-hat negotiation, or law enforcement action has been announced. Avici has not disclosed whether affected users will be made whole, and the company has not published a timeline for restoring full service. Those answers will determine whether this is a survivable incident or a terminal one.






