Forget the $1.1 million figure for a moment. The number to sit with is $500,800 — the amount drained from 1,685 Avici users, all because a contract version nobody had gotten around to retiring was still live.
That is the only slice of the attack Avici has attached a number to. The remainder of the roughly $1.1 million traced onchain flowed elsewhere — into other programs running the same outdated Rain card contract — and neither firm will identify them.
The token took it worse than the balance sheet
AVICI slid from a 24-hour high of $0.43 to a record low of $0.217 — a fall of as much as 49% — before recovering to roughly $0.378 at the time of writing.
Avici bills itself as a self-custodial neobank, letting users spend crypto via a Visa-integrated credit card. Holding your own keys is the entire pitch. This breach is a fairly blunt test of how far that promise actually stretches.
Where the money actually sat
According to Avici, the breach was contained to a Solana contract that holds funds once customers top up their cards. Self-custodial wallets on Solana and Ethereum-compatible networks went untouched, and the company said every affected card balance would be refunded.
This is the custody handoff that never makes it onto the landing page. The money in your Avici wallet is yours to control. Load it for spending and it shifts into a third-party contract — and that is where your control stops.
Dig into Avici’s terms and Third National appears as the card issuer. The stablecoin card infrastructure sitting beneath it comes from Rain, a Visa principal member.
Avici wasn’t alone
Fellow crypto neobank Tria reported that 636 of its users were hit, with losses topping $430,000. It pledged to make users whole. Its own token dipped more than 10% at one stage.
Put Avici’s $500,800 alongside Tria’s $430,000 and the total still falls short of the $1.1 million traced onchain. That shortfall is the real story: other Rain-powered programs were caught in this too, and no one has named them or disclosed individual losses.
The attack itself was repetitive, not clever
Transaction records show the attacker resubmitting a signed authorization again and again, appointing itself administrator on individual card-collateral accounts, and then draining the balances.
What followed was the standard laundering routine: stolen stablecoins converted into solana (SOL), bridged over to Ethereum, then run through crypto mixer Tornado Cash.
Rain stated that its monitoring flagged the vulnerability in an outdated contract version used by Avici and a handful of other programs. It said it upgraded every program running that version and has seen no further unauthorized activity.
Why an old contract version is a scaling problem
Tracked crypto-card spending more than tripled in July to $1.04 billion, with stablecoins bankrolling 70% of more than 10 million transactions. Each of those top-ups is a handoff into somebody else’s contract.
The infrastructure layer gets shared. That works beautifully until a stale version is deployed across several programs simultaneously — and at that point, one bug belongs to everybody.
What Avici hasn’t answered yet
Avici says it has filed a report with the Federal Bureau of Investigation’s Internet Crime Complaint Center. What it hasn’t disclosed is when refunds land, or where the money behind them is coming from.
Those two questions carry more weight than the filing does. An IC3 report is paperwork; a funded refund plan with a date attached is a commitment.
Anyone currently carrying a balance on a crypto card should stop thinking of loaded funds as self-custodial money. Leave them in the wallet you actually control until the moment of purchase, and top up in small amounts. For the 1,685 Avici users who absorbed that lesson this week, the tuition ran to roughly $297 apiece.














STAY ALWAYS UP TO DATE