Losses from a hack of Avici, a Solana-based neobank that issues crypto-linked payment cards, have climbed past $1 million as the company pledged to fully reimburse affected users, according to multiple independent reports published between August 28 and 30.
The incident first surfaced late on August 28, when BeInCrypto reported that the neobank had been hacked for roughly $650,000 and that its AVICI token had fallen about 40% following the disclosure. Startup Fortune reported that the attacker drained around $500,000 from card users overnight. By August 29, CoinDesk put the figure at approximately $1.1 million and reported that the neobank's token had crashed as much as 49% at one point, making clear the final tally was still moving.
What Is Known
- Target: Avici, a Solana-based neobank offering crypto payment cards to retail users.
- Victims: More than 1,600 users of the card product were affected, according to a report from Pluang on August 30.
- Losses: Estimates have risen from an initial $500,000-$650,000 to at least $1.1 million as on-chain analysis progressed. The final number has not been confirmed by the company.
- Response: Avici has pledged full repayment to all affected card users, Pluang reported.
- Laundering: Blockchain analytics platform CryptoRank reported on August 29 that stolen funds had been laundered through Tornado Cash, the sanctioned Ethereum mixing protocol.
The attacker has not been identified, and no attribution has been made public. The precise intrusion vector — whether a compromise of card infrastructure, hot wallets backing the card product, or a signing layer — has not been independently established. No post-mortem from Avici was available at the time of writing.
The Pattern: Custodial Rails Between Users and Their Funds
The incident fits a recurring 2026 pattern in which the losses occur not in a smart contract but in the custodial plumbing around it: card programs, hot wallets, bridges, and the operational keys that connect them. The year's largest incidents — from the Coldcard firmware exploitation to governance takeovers like Term Finance — have largely bypassed audited contract code and attacked the layers around it.
For users, crypto card products add a structural tension: the card network requires a spendable custodial balance, which means funds that could otherwise sit in self-custody are continuously exposed to the operator's operational security.
Avici's repayment pledge, if executed, would spare its users direct losses. But as this week's Ledger disclosure dispute also illustrates, the burden of verifying that operator security remains with the user. Neither the repayment timeline nor the total affected balance has been independently verified.