An attacker drained over $653,000 from card collateral vaults at Avici, a Solana neobank that issues a Visa credit card backed by USDC. The exploit compromised the platform's stated security model, under which only users' wallets should be able to withdraw funds from escrow contracts.
The AVICI token fell to $0.24, representing a decline of approximately 40%. The drained amount equals close to a fifth of the token's total market value.
How the Exploit Worked
Avici's documentation stated that only a user's wallet could withdraw funds from escrow contracts after deducting spending. However, on-chain researchers identified a discrepancy between the documented access controls and the actual smart contract code.
According to researchers, the attacker submitted a crafted signature bundle that granted administrative access to escrow accounts, enabling the unauthorized withdrawal. Avici has not confirmed this method. The company's card is issued by Third National, not Avici itself.
Each customer maintains a separate escrow contract, meaning the attacker drained funds account by account rather than from a single central vault.
Company Response
Avici stated on August 28 that it was aware of an issue affecting card balance withdrawals and was working with relevant partners to resolve it. The company has not provided details about whether remaining vaults remain functional or whether card settlement with Third National has been affected. No detailed post-mortem has been released.


