Avici Crypto Card Hack: What Happened
AVICI, the token behind crypto neobank Avici, crashed as much as 49% on Friday, August 28, sliding from an intraday high near $0.43 to a record low of $0.217 before clawing back to roughly $0.30-$0.38 by the weekend. The trigger was real: an attacker drained about $500,800 from the card top-up balances of 1,685 Avici users by exploiting a bug in an outdated version of a shared third-party contract that Avici's card program runs on, built by infrastructure provider Rain. This is the avici crypto card hack that's now rattling anyone who tops up a crypto debit card for daily spending — and the honest answer on safety is more nuanced than either "your funds are gone" or "nothing to worry about."
Why Did AVICI Crash 49%?
Start with what actually happened. The attacker didn't break into Avici's app or steal a password. They repeatedly replayed a previously signed authorization message against Rain's card-collateral smart contract — the vault that holds the crypto backing each user's card spending limit — and used it to add themselves as an admin on individual accounts. Once inside, they simply withdrew the balances. It's a vendor infrastructure flaw, not a hack of Avici's own systems, and not a DeFi exploit in the usual sense of a drained liquidity pool.
The reason this became a two-neobank story is that Rain doesn't just power Avici. It issues the same card-collateral plumbing for other crypto-card brands, and the identical flaw hit at least one of them: Tria, which lost roughly $430,000 across 636 accounts. Combined losses across both programs run close to $1.1 million.
For most tokens, a $500,800 loss wouldn't move the price 49% in a day. AVICI could, because it's a thin, illiquid microcap — roughly $4 million in market cap, about 13 million tokens in circulation, and daily trading volume that swings between $400,000 and $1.9 million. A real but contained security incident, landing on a token that small, produces an outsized swing almost mechanically. That's proportionate to the token's liquidity profile, not evidence the project is insolvent or that losses are still growing.
Is My Crypto Debit Card Safe?
Here's the part that matters most for anyone holding one of these cards. Self-custody wallets were never touched in this incident — the exploit only reached funds sitting inside Rain's card-collateral contract, the balance you've specifically loaded onto a card for spending. If you hold crypto in your own wallet and haven't topped up a Rain-powered card, this incident doesn't touch you directly.
If you do use a crypto debit card, though, the honest framing is that your top-up balance briefly carried real risk, and that risk was never specific to Avici as a brand. It was a vendor-concentration problem: any card program built on the same outdated Rain contract version was exposed, regardless of how trustworthy the neobank running it looked. That's the broader lesson for the sector — as more "crypto debit card" products lean on the same handful of infrastructure vendors, one vendor's bug becomes a shared risk across brands that otherwise look unrelated.
The response since has been about as fast as this kind of incident gets. Rain has patched every card program running the vulnerable contract version and reports no further unauthorized activity since the disclosure. Avici and Tria have both publicly pledged full refunds to affected users, and Avici says it has filed a report with the FBI's Internet Crime Complaint Center (IC3). None of that undoes the theft, but it does cap the realistic near-term downside case for anyone currently owed a refund.
What Happens Next?
The base case here is fairly straightforward: Rain's patch holds, no new unauthorized withdrawals surface, Avici and Tria process their pledged refunds over the coming days to weeks, and AVICI stabilizes off its record low as the acute panic selling fades. That doesn't mean a full round-trip back to pre-hack prices — AVICI was already trading roughly 94% below its all-time high before this happened, and a thin, declining microcap doesn't automatically recover just because the immediate crisis is contained.
Two things would break that base case in the bearish direction. First, the disclosed losses at Avici and Tria only add up to about $930,000 of the roughly $1.1 million total reportedly stolen — if that gap reflects other Rain-integrated platforms that haven't come forward yet, more disclosures could reignite the sell-off, especially in AVICI's thin order book. Second, if refunds slip in timing or funding, the "this is contained" narrative weakens fast. Reports indicate the stolen funds were routed through Tornado Cash, a mixing service that makes on-chain tracing difficult, so full recovery of the stolen crypto itself is unlikely regardless of how the refund process plays out.
On the upside, a fast, verifiable refund process across both affected platforms, combined with silence from any other Rain-integrated brand, would be the clearest signal that this was a one-off vendor failure rather than a symptom of something wider. For now, the practical takeaway for cardholders is simple: check whether your card provider runs on Rain's infrastructure, watch for their refund communications if you were affected, and treat your card top-up balance and your self-custody wallet as genuinely separate risk buckets — because in this incident, they were.
Sources
- https://www.coindesk.com/web3/2026/08/29/a-usd1-1-million-crypto-card-hack-crashed-a-neobank-s-token-49
- https://blockonomi.com/1-1m-crypto-card-exploit-crashes-avici-token-49-as-solana-contract-vulnerability-exposed
- https://ambcrypto.com/avici-says-everyones-card-balance-refunded-in-full-as-rain-fixes-crypto-card-vulnerability
- https://www.cryptopolitan.com/avici-pledges-full-refunds-ajna-next/
- https://beincrypto.com/avici-exploit-solana-card-vaults-drained/
- https://www.coingecko.com/en/coins/avici
- https://cryptoticker.io/en/ajna-defi-lending-exploit-immutable-contract/