Avici, a Solana-based neobank, announced it will refund all affected card balances in full following a breach on August 28 that exposed a flaw in its card contract. The company identified the vulnerability through its card-issuing partner Rain and said the flawed Solana contract was used by Avici and a small number of other programs before being upgraded.
The exploit affected 1,685 users and drained $500,859 in card balances. According to security database DefiLlama, the attacker exploited a withdrawal logic flaw by calling a series of functions—SubmitSignatures on Avici's authorization program, AddCollateralAdmin on its collateral program, and WithdrawCollateralAsset to extract funds. The attacking wallet accumulated approximately 10,005 SOL and around $11,600 in stablecoins.
The AVICI token declined roughly 39% within 24 hours of the incident, reaching an all-time low near $0.22 before recovering to around $0.31 by the time of reporting.
Ajna Targeted Days Later
On August 29, Ethereum lending protocol Ajna fell victim to a separate attack that drained approximately $775,000 through liquidation accounting manipulation. Security monitoring firm Defimon Alerts reported that the syrupUSDC pool alone accounted for $173,700 of the losses. Defimon stated it had flagged the prepared attack more than an hour before the first exploit transaction and warned the Ajna team via Discord, though Ajna failed to respond in time.
Ajna confirmed it was investigating unusual movements and instructed users to withdraw all funds, repay loans, and cease protocol interactions. The protocol's total value locked fell to approximately $246,880, down 71.3% over the prior 30 days.
Broader Security Landscape
The incidents reflect ongoing challenges in the sector. A CoinGecko report on crypto security documented over 245 incidents between January 2025 and July 2026, totaling $3.63 billion in losses. Of these, 147 affected audited protocols, accounting for 88.44% of stolen capital. Most attacks exploited infrastructure, third-party services, governance, or human error rather than bugs within audit scope.
On-chain insurance coverage available to absorb losses has declined, with active coverage falling from $163.2 million to $130.2 million. Five of nine on-chain insurance protocols went inactive or pivoted by August 2026.


