Home / News / Avici Breach Drains $500K From 1,685 Users While Self Custody Wallets Stay Safe
News 3 min read

Avici Breach Drains $500K From 1,685 Users While Self Custody Wallets Stay Safe

Avici breach illustration showing $500K drained from 1,685 users, with crypto coins spilling from the compromised platform while a self-custody wallet remains protected.
The Avici breach reportedly affected 1,685 users and resulted in roughly $500,000 being drained, while self-custody wallets remained unaffected.

Key Takeaways

  • A vulnerability in a Solana card contract used by Avici allowed an attacker to drain $500,859.22 from 1,685 users.
  • Avici said its self-custodial Solana and EVM wallets were not affected because card balances are held in a separate contract.
  • Avici has promised to reimburse every affected user in full, while the vulnerable contract has been upgraded and the incident reported to the FBI.

Solana-based crypto neobank Avici has confirmed that 1,685 customers lost a combined $500,859.22 after an attacker exploited a vulnerability in the infrastructure supporting its payment cards.

The incident did not compromise users’ main Avici wallets.

According to the company, the vulnerability was found in an older version of a Solana card contract operated by card-issuing partner Rain.

When Avici users top up their payment cards, those funds leave their self-custodial wallets and move into a separate smart contract that holds the card balance.

It was this contract, rather than Avici’s wallet infrastructure, that was attacked.

How the Avici Attack Drained User Card Balances

Onchain analysis indicates that the attacker exploited an authorization flaw, allowing an unauthorized administrator to be added to affected collateral accounts.

The attacker then repeatedly used withdrawal functions to move balances from those accounts.

One reconstruction found thousands of withdrawal calls during the attack. The attacker-controlled address also accumulated substantial assets across affected programs, although estimates of the total amount moved have varied because the vulnerable Rain contract was reportedly used by multiple services.

Avici’s own reconciliation currently shows customer losses of $500,859.22 across 1,685 users.

Rain has since upgraded the vulnerable contract across affected programs, and Avici said it has seen no further unauthorized activity following the fix.

Why Avici Self-Custody Wallets Were Not Drained

The incident shows an important difference between holding funds in a self-custodial wallet and moving them into a payment product.

Avici said users retain control of assets stored in their Solana and EVM wallets, and those balances were not exposed during the exploit.

The risk appeared only after customers transferred funds into the separate card contract used to support spending.

That separation limited the breach, but it also shows that a self-custodial crypto app can still introduce third-party smart-contract risk when users interact with cards, lending products or other external services.

Avici Promises Full Refunds

Avici has said every affected card balance will be reimbursed in full.

The company is working with Rain and security partners while monitoring the upgraded infrastructure. It has also filed a report with the FBI’s Internet Crime Complaint Center.

Early social-media warnings claimed entire Avici wallets were drained, but the company later clarified that this was inaccurate: the exploit was confined to card balances held in a separate Rain-powered contract.

For users, that distinction is significant. The breach did not break Avici’s self-custody model, but it exposed how funds can take on a different security profile the moment they leave a wallet and enter third-party payment infrastructure.

 

Was this Article helpful? Yes No
Thank you for your feedback. 0% 0%