A smart contract exploit that briefly looked like it could sink a promising Solana neobank is now producing a different kind of headline. Avici has confirmed full refunds for all 1,685 users whose card balances were affected by the August 28 breach, and the market responded immediately: the BANKJ token jumped more than 50% on the news.
That recovery, while sharp, arrives against a backdrop of serious damage. The exploit cost affected users somewhere between $650,000 and $1 million, depending on which accounting method you use, and briefly wiped between 32% and 49% off the AVICI governance token’s value.
What actually happened on August 28
Avici is built as a self-custodial neobank on Solana. The core product pairs a Visa Signature card with smart wallets that hold user funds until the moment a card transaction settles at point of sale.
The exploit broke that model in a targeted way. Attackers found vulnerabilities in three smart contract operations: SubmitSignatures, AddCollateralAdmin, and WithdrawCollateralAsset. By chaining those operations together, they were able to claim unauthorized admin rights over roughly 1,100 collateral accounts and then drain them through a series of small withdrawals.
The root cause was an architectural shortcut: Avici’s smart contracts used a single non-multisig upgrade authority, meaning one compromised key was all an attacker needed to escalate privileges across the system.
The company acknowledged problems with card balance withdrawals shortly after the breach, confirming it was working with partners to contain the situation. What followed was weeks of uncertainty for users and a collapse in token value that brought AVICI’s market cap down to a range of roughly $2.8 million to $4 million at its lowest point.
The refund commitment and why it matters
Full restitution for 1,685 users is not a trivial undertaking for a project whose market cap recently sat in the low single-digit millions. The announcement signals that Avici either had reserves set aside, secured external support, or both, though the company has not publicly detailed the mechanics of how refunds will be funded or processed.
Context: Avici’s governance token and the pre-exploit trajectory
Avici launched its AVICI governance token in October 2025 through MetaDAO. The raise was oversubscribed, and the project retained approximately $3.5 million while refunding the majority of commitments that came in above its target. That detail matters now because it suggests the project entered the exploit with meaningful treasury resources, which may be part of what makes a full refund commitment credible.
What this means for Solana DeFi and crypto card products
The Avici incident highlights a risk not unique to Avici: any project running upgradeable contracts with a single key controlling upgrades carries a version of the same vulnerability. That includes a meaningful portion of the Solana DeFi ecosystem.
For crypto card products specifically, the stakes are higher than for a typical DeFi protocol. A breach that touches Visa-linked card balances is not just a smart contract failure. It is a failure in a context where users had every reason to expect bank-like reliability.


