Avici confirmed full refunds for all 1,685 users hit by the August 28 exploit, and BANKJ rose more than 50 percent on the news. The recovery arrives after weeks of uncertainty that briefly wiped between 32 percent and 49 percent off the AVICI governance token's value.
The company said it would make whole every affected user, though it has not detailed how the refunds will be funded or processed. On-chain data from Solscan shows an address linked to the exploit held roughly $604,800 before disbursing the funds across multiple wallets.
Attackers chained vulnerabilities in three smart contract operations — SubmitSignatures, AddCollateralAdmin, and WithdrawCollateralAsset — to claim unauthorized admin rights over roughly 1,100 collateral accounts and drain them through a series of small withdrawals. The exploit cost affected users between $650,000 and $1 million, depending on accounting method.
The root cause was an architectural shortcut: Avici's smart contracts used a single non-multisig upgrade authority, meaning one compromised key was enough to escalate privileges across the system. That design flaw is shared by a meaningful portion of the Solana DeFi ecosystem, raising questions about the security of crypto card products that promise bank-like reliability.
Avici is built as a self-custodial neobank on Solana, pairing a Visa Signature card with smart wallets that hold user funds until a card transaction settles at point of sale. Third National issues the card, not Avici. The company acknowledged problems with card balance withdrawals shortly after the breach, confirming it was working with partners to contain the situation.
AVICI launched its governance token in October 2025 through MetaDAO. The raise was oversubscribed, and the project retained approximately $3.5 million while refunding commitments above its target. That treasury cushion may be part of what makes the full refund commitment credible.
Full restitution for 1,685 users is not trivial for a project whose market cap recently sat in the low single-digit millions. The refund announcement suggests Avici either had reserves set aside, secured external support, or both.
For crypto card products, the stakes are higher than for a typical DeFi protocol. A breach that touches Visa-linked card balances is not just a smart contract failure — it is a failure in a context where users had every reason to expect bank-like reliability. The Avici incident highlights a risk that extends beyond any single project: any protocol running upgradeable contracts with a single key controlling upgrades carries a version of the same vulnerability.
This article is for informational purposes only and does not constitute investment advice.