Avici hack on August 28 2026 drained $500,859 from 1,685 users through an outdated Rain Solana contract. Full refunds are promised. Here's what happened, how much was taken, and the current status.
On August 28 2026 Solana neobank Avici got hit. An attacker pulled $500,859.22 from the card balances of 1,685 users. On-chain numbers looked higher, closer to $1 million once you count other programs still running the same old contract. Avici and Rain both said they will refund every affected user in full. Self-custodial Solana and EVM wallets stayed safe the whole time.
What Happened in the Avici Hack
Avici is a self-custodial neobank that lets people spend crypto with Visa cards on Solana. When you top up a card the money goes into a separate Solana contract that holds the card balance. That contract was the problem, not the users' own wallets.
The vulnerability sat in Rain's system. Rain is the company that issues the cards. They still had an outdated version of their Solana contract running on a few programs, including Avici. The attacker found a flaw in the authorization logic. They submitted a crafted signature bundle, used AddCollateralAdmin to give themselves admin rights on user accounts, then called WithdrawCollateralAsset to drain the funds.
The attacker wallet FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj appeared around 13:40 UTC on August 28. It received about 1.79 SOL (roughly $190) bridged from Ethereum through deBridge, just enough to cover gas. The drain started at about 16:49 UTC. The wallet ran thousands of transactions, swapped the money into SOL then USDC, bridged it to Ethereum, and sent around 418 to 456 ETH into Tornado Cash.
Avici publicly noted a card balance withdrawal issue at 18:42 UTC, almost two hours after the first bad transactions. Rain upgraded the contracts on every affected program and the unauthorized activity stopped. Avici also reported the incident to the FBI Internet Crime Complaint Center.
How Much Was Stolen in the Avici Hack
Avici's own numbers show 1,685 users lost a total of $500,859.22 from their card balances. The same outdated Rain contract was used by a small number of other programs, which is why total on-chain movement looked bigger while the attack was live. Users' self-custodial wallets were never touched.
Will Avici Users Get Refunded
Yes. Both Avici and Rain stated that every affected card balance will be refunded in full. The vulnerable contract has been upgraded. No further unauthorized activity has been seen. Avici filed a report with the FBI and is working with its partners on the refunds.
Impact on the AVICI Token
The AVICI token dropped hard right after the news broke. Price fell between 28% and 40% in a short window before recovering a bit once the full refund promise came out.
Key Lessons From the Avici Solana Exploit
This was not a complex reentrancy or a treasury drain. It was an authorization and signature verification flaw in a contract that should have been updated earlier.
—Legacy code creates real risk. Having a newer safer version does not help if some programs are still running the old one.
—Card balance contracts are attractive targets because the money sitting in them is liquid and ready to spend.
—Keeping self-custodial wallets separate from card balances limited the damage. That design choice helped.
—Partner risk matters. The hole came from Rain's contract, not Avici's core code. Third-party dependencies need the same careful review as anything built in-house.
Final Take
Avici handled the communication better than many projects do after a hit. They were open, moved fast with partners, promised full refunds, and reported it to the authorities. Still, the incident shows that even self-custodial neo-banking products rest on smart contracts that have to stay current.
If you use crypto cards, only keep what you need for spending on the card balance and leave the rest in your own wallet.


