Skip to content

Solana Neobank Loses $500K in Outdated Contract Exploit

Avici will refund 1,685 users after a $500K exploit exposed dependency risk in Solana's card infrastructure. The attacker turned $190 into admin access across 1,100 accounts.

Abstract digital security breach showing vulnerability in financial infrastructure systems
Avici's $500K exploit exposed dependency risk in shared Solana card contracts used across multiple neobank platforms.

Table of Contents

The Attack Began with $190 in Gas

Solana-based neobank Avici will refund 1,685 users in full after an attacker exploited an outdated card contract supplied by its issuing partner Rain, draining $500,859.22 from customer card balances. The attacker's wallet was created on August 29 at 13:40 UTC and funded with $190 USDC bridged from Ethereum. Just enough for gas. The drain started three hours later at 16:49.

The attacker submitted a specially created signature bundle called AddCollateralAdmin, which incorrectly gave them admin access to more than 1,100 user collateral accounts. From there, the attacker could withdraw funds from those accounts one by one. AVICI token plummeted 49% from its daily peak, reaching an all-time low of $0.217.

Dependency Risk in Solana's Card Ecosystem

Rain identified the vulnerability in an outdated version of its Solana contracts used by Avici and a small number of other programs. Every deployment still running the affected version has since been upgraded, with no further unauthorized activity detected after the fix.

The incident highlights dependency risk in Solana's card ecosystem. Multiple platforms shared the same vulnerable infrastructure, creating concentrated attack surface. When one contract version fails, every platform relying on it becomes exposed simultaneously. This is not a theoretical risk. It materialized in less than four hours.

Infrastructure-Layer Exploits in 2026

The Avici exploit exemplifies a pattern emerging across 2026. Infrastructure-layer exploits are targeting permissions and governance mechanisms rather than cryptographic weaknesses. The attacker did not break encryption. The attacker submitted a signature bundle that the system accepted as legitimate admin input.

This is a different threat model than the DeFi exploits of 2020-2022, which primarily exploited economic logic in protocols. Now, the attack surface is in access controls, permission structures, and the handoff points between platforms and their infrastructure providers. When those handoffs rely on outdated contracts, the window opens.

What Full Refunds Mean for Users

Avici committed to refunding all 1,685 affected users in full. That commitment matters because it separates platforms willing to absorb loss from those that socialize it. In markets where users rely on crypto card infrastructure for daily spending, especially in high-inflation economies, the promise of reimbursement shapes trust.

The refund also signals that Avici views this as an infrastructure failure, not a user security failure. That framing matters. If users are blamed for interacting with a vulnerable contract they did not choose and could not audit, adoption stalls. If the platform absorbs the loss and upgrades the system, users return.

This is relevant in markets where card-linked stablecoin balances are used not for speculation but for remittances, bill payments, and salary conversion. A single exploit that drains grocery money is not an acceptable cost of adoption. The refund acknowledgment of that reality.

Shared Infrastructure, Concentrated Risk

Rain's contract was deployed across multiple platforms. That creates efficiency. It also creates systemic exposure. When one version of a widely used contract contains a vulnerability, every platform using it inherits the same risk at the same time. The fix must be coordinated. The communication must be fast. The window for exploitation is narrow but identical across all users.

This dynamic is familiar in traditional financial infrastructure. Payment processors, card networks, and clearinghouses all create shared dependencies. The difference in crypto is that the code is often visible, the upgrades are manual, and the coordination between platforms and infrastructure providers depends on relationships that are still being formalized.

The Takeaway

The Avici exploit reveals the cost of outdated dependencies in Solana's card infrastructure. The attack was simple: bridge $190 for gas, submit a malicious admin signature, drain 1,100 accounts. The response was fast: Rain identified the vulnerability, upgraded all deployments, and no further unauthorized activity was detected. Avici committed to full refunds.

What this signals is not a failure unique to Avici or Rain. It signals the maturation challenge facing crypto infrastructure in 2026. As platforms scale, they rely on shared contracts, shared issuers, and shared permissions systems. When those systems lag, the exposure spreads. The platforms that survive are the ones that audit dependencies, coordinate upgrades, and absorb user losses when infrastructure fails. The platforms that do not absorb those losses lose the users who need this infrastructure most.

Frequently Asked Questions

How did the Avici attacker gain admin access to user accounts?

The attacker submitted a specially created signature bundle called AddCollateralAdmin to an outdated Rain contract used by Avici. This signature incorrectly granted admin access to more than 1,100 user collateral accounts, allowing the attacker to withdraw funds systematically. The vulnerability existed in the permissions layer of the contract, not in cryptographic security.

Will Avici users get their funds back after the exploit?

Yes. Avici committed to refunding all 1,685 affected users in full after the $500,859.22 exploit. The platform is treating this as an infrastructure failure rather than a user security issue, absorbing the loss to maintain trust. This approach is critical in markets where users rely on crypto card infrastructure for daily spending and remittances.

What is dependency risk in Solana's card ecosystem?

Dependency risk occurs when multiple platforms share the same underlying infrastructure contracts. In this case, Rain provided card contracts used by Avici and other programs. When one outdated version contained a vulnerability, all platforms using it became exposed simultaneously. This creates concentrated attack surface and requires coordinated upgrades across all deployments to close the security gap.

How much did the attacker initially invest to exploit Avici?

The attacker created a new wallet and funded it with just $190 USDC bridged from Ethereum. This amount covered transaction fees on Solana while executing the exploit. Within hours, the attacker had drained $500,859.22 from user card balances by exploiting the outdated Rain contract's admin permission flaw.

What happened to AVICI token price after the exploit?

AVICI token plummeted 49% from its daily peak following the exploit announcement, reaching an all-time low of $0.217. The sharp decline reflects market concern about security vulnerabilities in the platform's infrastructure and potential user flight. The commitment to full refunds may stabilize confidence, but the price damage illustrates how infrastructure failures translate immediately to market valuation.

Comments

Latest