News · August 29, 2026 · 4 min read
Avici Solana Neobank Hit by $600K Wallet Drain Incident: What It Means for Self-Custody Cardholders

Major Neobank exploited as hacker drains over $650,000 from Avici.
Avici is a Solana neobank offering self-custodial wallets and Visa cards for crypto spending. Today they were targeted with over $650K drained from user card collateral accounts.
The attacker's Solana wallet holds ~$660K USDC.
Avici's token has dropped over 45% as users and security teams respond.
When we load and test crypto cards at Cardify Crypto, self-custody products always catch my attention. They offer direct control over your assets right up until you swipe. But as the recent Avici incident shows, that direct line to your wallet cuts both ways.
Avici Statement: All affected card balances will be refunded in full
Earlier today, our card-issuing partner, Rain, identified a vulnerability in a version of a Solana card contract used by Avici and a small number of other programs. The contract has now been upgraded across all programs, and no further unauthorised activity has been observed.
Avici wallets and card balances are separate. Avici wallets are self-custodial and remain under users’ control.
When users top up their cards, funds move into a separate Solana contract that holds their card balance. Only this contract was affected.
Note: Funds held in Avici’s Solana and EVM wallets are safe and were not affected.
Our current reconciliation shows that 1,685 users were affected, representing $500,859.22 in card balances.
Every affected user will have their card balance refunded in full. We remain in close contact with our card-issuing and security partners and are monitoring the remediation closely.
Avici has also filed a report with the FBI’s Internet Crime Complaint Center. We are deeply sorry for the concern and inconvenience this has caused."
Avici has responded saying "All affected card balances will be refunded in full"
And that "Funds held in Avici's Solana and EVM wallets are safe and were not affected.
..............................................................................................................................
Rain's response: Earlier today, Rain’s monitoring systems discovered a vulnerability impacting a small number of programs using an outdated version of our Solana contracts. Other programs were not impacted. Rain immediately launched an investigation to determine the full scope of the situation.
Our team has successfully upgraded all programs that were using the outdated version of the Solana contracts, which has resolved the situation. Rain is continuing to monitor the issue, has engaged third-party forensics experts to investigate, and will work with law enforcement and relevant regulatory authorities.
All affected users will be made whole. We’ve already begun the remediation process and are focused on delivering a swift and responsible resolution.
...................................................................................................................................
This is the first of many hacks, scams, and exit scams to come from Crypto Neobanks, so becareful