Avici Promises Full Refunds After $500,859 Solana Card Exploit; Ajna Becomes Next Victim
Key Takeaways
- •Avici pledged to refund all 1,685 affected card balances totaling $500,859.22 in full after the August 28 exploit.
- •The Avici attacker escalated privileges by calling SubmitSignatures, AddCollateralAdmin, and WithdrawCollateralAsset rather than breaking cryptography.
- •Ethereum lending protocol Ajna lost roughly $775,000 on August 29, with Defimon saying it warned the team over an hour before the attack but Ajna failed to react.
- •A CoinGecko report documented more than 245 incidents totaling $3.63 billion in losses from January 2025 to July 2026, with audited protocols accounting for 88.44% of stolen capital.
- •Active on-chain insurance fell from $163.2 million to $130.2 million, and five of nine insurance protocols went inactive or pivoted by August 2026.

Avici, a Solana-based neobank, has pledged to refund every affected card balance in full after an August 28 breach drained user funds. A day later, the same wave of exploits hit the Ethereum lending protocol Ajna. The back-to-back incidents extend a rough stretch for decentralized finance, in which even audited protocols have repeatedly lost user funds to flaws outside the scope of their audits.
"All affected card balances will be refunded in full"
The refund commitment came in an August 28 post on X, in which Avici said its card-issuing partner, Rain, had traced the incident to a flawed version of a Solana card contract. Avici stated that the contract had been used by the neobank "and a small number of other programs" before being upgraded across the board — a detail that suggests the underlying vulnerability was not unique to Avici's deployment, since the flawed contract version was shared across multiple programs before the patch.
The company confirmed that 1,685 users affected by the exploit, representing $500,859.22 in card balances, will have their balances refunded in full.
How the attacker emptied the card program
DefiLlama's hack database logs the Avici incident at $500,859, matching the figure in the firm's update, and classifies it as a withdrawal logic flaw in a Rust-based protocol. Initial reports had estimated losses between $600,000 and more than $1 million.
According to reports, the attacker called a function named SubmitSignatures on Avici's authorization program, then AddCollateralAdmin on its collateral program, and finally WithdrawCollateralAsset to pull funds out. The chain of calls indicates the attacker escalated privileges within the programs rather than breaking cryptographic protections, a pattern consistent with the logic-flaw classification.
The attacking wallet ultimately held roughly 10,005 SOL, worth about $1.07 million at the time, along with approximately $11,600 in stablecoins.
Following the exploit, the AVICI token dropped about 39% in 24 hours to near $0.26, touching a new all-time low of around $0.2189. That left the token down more than 96% from its peak of $7.61, reached in November 2025. At the time of writing, the token has recovered slightly and trades around $0.3093, though it remains down more than 27.8% over the past 24 hours, per CoinMarketCap data.
Ajna becomes the next victim
On August 29, on-chain monitoring firm Defimon Alerts reported on X that Ajna lost roughly $775,000 to what it described as liquidation accounting manipulation on Ethereum, with the syrupUSDC pool alone accounting for $173,700.
Defimon said it had flagged the prepared attack more than an hour before the first exploit transaction and warned the team on its Discord, but Ajna "failed to react." The episode is the latest example of on-chain monitoring tools detecting attack preparation in real time while protocol teams struggle to respond within the available window.
Ajna confirmed it was investigating "unusual movements" and urged users to withdraw all funds, repay loans, and stop interacting with the protocol.
DefiLlama data shows Ajna's total value locked at about $246,880, down 71.3% over the prior 30 days.
A costly stretch for audited protocols
A CoinGecko report titled "2026's State of Crypto Security" documented more than 245 incidents between January 2025 and July 2026, totaling $3.63 billion in losses. Of those, 147 hit audited protocols, accounting for 88.44% of all stolen capital. Most attacks exploited infrastructure, third-party services, governance, or human error rather than bugs within the audits' scope — a pattern that both the Avici incident, traced to a partner-issued card contract, and the Ajna incident, allegedly preceded by an ignored alert, fit into.
Insurance coverage capable of absorbing such losses is also shrinking. Active on-chain insurance reportedly fell to 20.2% of the market, declining from $163.2 million to $130.2 million. Additionally, five of nine on-chain insurance protocols reportedly went inactive or pivoted by August 2026. That leaves refunds like Avici's — funded by the protocol itself rather than insurance — likely to remain the primary recourse for affected users, and whether the pledged repayments are completed in full is the key open question for the 1,685 impacted cardholders.