Solana-based Neobank Avici fully refunds 1685 users after being attacked
Solana-based virtual bank Avici will fully refund the funds of 1685 users. Previously, the attacker used an outdated smart contract vulnerability provided by its card issuing partner Rain to steal $500,859.22 from users 'card balances. Before the final reconciliation was released, early estimates on the chain showed that the attack amount exceeded $1 million because funds quickly accumulated in addresses controlled by the attackers. Avici's self-hosted Solana and EVM wallets were not affected, except for a separate Solana contract that holds the user's balance transferred to the card system.
Outdated Rain contracts allow unauthorized withdrawals
Rain discovered loopholes in older Solana contracts used by Avici and a few other projects. All programs that are still running the affected version have been upgraded and no unauthorized activity has been detected since the fix. The first malicious interaction occurred at 16:49:48 UTC and involved Avici related contracts. The attacker repeatedly called SubmitSignatures, followed by AddCollateralAdmin and WithdrawCollateralAsset, thereby adding administrative rights before removing assets in a single mortgage account. The attacker address ultimately signed 14,672 transactions, including 2,344 failed attempts. One transaction reviewed resulted in USDT being withdrawn from a mortgage account. The wallet received only 1.79 SOL through deBridge at the beginning of the attack, and then converted part of the extracted stablecoins into SOL during the continued theft process.
The failure originated in the card infrastructure, not the Solana network itself or Avici's self-managed wallet system. Users are at risk only after transferring assets from their wallets to separate contracts that maintain the balance of expendable cards.
Avici promises a full refund and contacts the FBI
According to Avici's refund commitment, all affected card balances will be restored. The company has filed reports with the FBI's Internet Crime Complaint Center and stayed in contact with Rain and security partners during the reconciliation process. Rain has brought in third-party legal investigators and plans to cooperate with law enforcement and relevant regulatory agencies. The remedies cover all programs that are still using the vulnerable version of the Solana contract, not just the deployment of Avici. The separation between current and old contracts is similar to the Raydium theft incident in June-there were logical holes in the then-obsolete Solana liquidity pools that could still be exploited even though they had disappeared from Raydium's current interface. Another Solana agreement, Allbridge Core, was suspended in July after a lightning attack that manipulated the accounts of the stablecoin pool and stole more than $1 million.
AVICI drops to record low in currency theft incident
AVICI tokens fell sharply as users began to share news of missing card balances and the attack continued. The token fell to an all-time low of about $0.219, about half of the day's intraday high of $0.446, before recovering. After announcing the refund, AVICI traded close to $0.27, but still fell about 38% within 24 hours, with a market value of approximately $3.4 million, and 24-hour trading volume of nearly $1.2 million.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
SOL