The Solana-based financial platform Avici recently disclosed a security breach involving its card contract, resulting in the unauthorized withdrawal of approximately $24,859.22. The incident, which targeted a specific vulnerability in the protocol’s banking infrastructure, affected 1,685 users but did not compromise self-custodial wallets. In a swift response to the exploit, the Avici team has committed to a full reimbursement for all impacted individuals while coordinating with federal law enforcement to investigate the origin of the attack.
Vulnerability in Solana Card Contracts
The security flaw was identified within a specific version of the Solana card contract, a component utilized not only by Avici but also by several other projects within the ecosystem. The vulnerability specifically targeted the independent contracts responsible for managing bank card balances. Technical teams have since executed mandatory contract upgrades across all affected platforms to patch the loophole.
It is important to note that the scope of the breach was limited to the platform's internal banking ledger. According to the official report, the following assets and systems remained secure:
- User-hosted Solana (SOL) wallets.
- EVM-compatible wallets connected to the service.
- Private keys and seed phrases of the platform’s user base.
- General protocol liquidity outside the specific card contract version.
Legal Response and Recovery Procedures
Following the detection of the unauthorized activity, Avici management initiated formal legal proceedings to track the movement of the stolen funds. The project has filed an official report with the FBI’s Internet Crime Complaint Center (IC3), providing digital forensics to assist in the recovery efforts. No further unauthorized transactions have been reported since the deployment of the security patches.
This incident only affected the independent Solana contracts used to store bank card balances, and user-hosted Solana and EVM wallets were not impacted.
The platform’s commitment to a 100% refund policy aims to maintain trust within the decentralized finance (DeFi) community. Users affected by the August 2026 event are expected to receive their funds back through the platform's insurance or reserve treasury, though a specific timeline for the distribution of these refunds is currently being finalized.
The Avici exploit highlights the ongoing security challenges faced by bridge-like financial services that attempt to integrate traditional banking features with blockchain technology. While the financial loss was relatively contained compared to larger DeFi hacks, the event serves as a reminder of the necessity for rigorous auditing of smart contracts that handle fiat-to-crypto balances. The proactive steps taken by the Avici team, including law enforcement cooperation and user compensation, reflect a growing trend toward professionalized incident response within the Solana ecosystem.
Frequently Asked Questions
Quick answers to the most common questions about this topic.