Avici Neobank Reimburses Users Amid $1M Security Breach
The Solana-based neobank Avici has confirmed that it will fully reimburse 1,685 users affected by a security breach tied to an outdated card smart contract. The breach occurred on August 28, 2026, and resulted in a loss of $500,859.22. According to the company's own figures, this is a significant portion of the total estimated loss, which ranges from $1 million to $1.1 million.
The exploit was made possible by an outdated version of the Solana smart contract used by Avici's card-issuing partner, Rain. The attacker was able to manipulate the contract's authorization logic and pull funds directly from the standalone contract that held card balances.
Avici has stated that users' self-custodied Solana and EVM wallets were not touched in the breach, and that the exposure was limited to funds parked specifically for card spending. This distinction is important, as it means that Avici treated this as a contained infrastructure failure rather than a platform-wide compromise.
The company has committed to automatically processing refunds for affected users over the coming weeks, with no claims process required. This swift response has been seen as a test case for how neobanks handle smart contract failures and whether goodwill compensation can substitute for deposit insurance carried by traditional banks.