Solana-based neobank Avici has stated it will fully reimburse all funds from affected cards following an August 28th hack that drained user accounts. A day later, a similar series of vulnerabilities hit the Ethereum lending protocol Ajna.
The refund promise came in an August 28th post on X, where Avici stated its card issuer partner Rain had identified tracan issue—an incorrect version of a Solana cardtraccontract.
"All funds on affected cards will be refunded in full"
Avici wrote that thetracwas used by the neobank "and a small number of other programs" before being widely upgraded.
The post stated that 1,685 users impacted by the vulnerability, representing $500,859.22 in card balances, will be fully reimbursed for the corresponding amounts.
How the attacker drained the cards
DefiLlama, pegs the Avici incident at $500,859, aligning with the company's update. It also classifies it as a withdrawal logic flaw in a Rust-based protocol. Initial reports had suggested figures from $600,000 to over $1 million.
Reportedly, the attacker invoked the SubmitSignatures function in Avici's authorization program, then the AddCollateralAdmin function in the collateral program, followed by the WithdrawCollateralAsset function to drain funds.
The attack resulted in the wallet receiving around 10,005 SOL, worth approximately $1.07 million at the time, and stablecoins worth about $11,600.
Following the hack, the AVICI token plunged roughly 39% over 24 hours, nearing $0.26 and hitting a new all-time low around $0.2189. Its value has thus fallen over 96% from its peak of $7.61 in November 2025.
At the time of writing, the token has recovered slightly and is trading around $0.3093, but, according to CoinMarketCap data, it remains significantly down.
Ajna becomes next in line
On August 29, DefiAlerts reported on X that Ajna lost about $775,000 due to what it described as manipulation of liquidation accounting on the Ethereum network, with only the syrupUSDC pool suffering a $173,700 loss.
Defimon stated it reported the impending attack over an hour before the first exploit transaction and warned the team on its Discord channel, but Ajna "did not respond."
Ajna confirmed it is investigating "unusual activity" and urged users to withdraw all funds, repay loans, and cease interacting with the protocol.
According to DefiLlama, Ajna's total value locked is now around $246,880, down 71.3% over the past 30 days.
A costly year for audited protocols
A CoinGecko report titled "The State of Crypto Security in 2026" documented over 245 incidentsdenta period from January 2025 through July 2026, with total losses amounting to $3.63 billion.
Of these, 147 attacks targeted audited protocols, accounting for 88.44% of all stolen capital, with most attacks exploiting infrastructure vulnerabilities, third-party services, governance systems, or human error rather than flaws within the scope of the audits.
Insurance coverage to cover such losses is also shrinking, as on-chain active insurance reportedly fell to 20.2% of the market, from $163.2 million to $130.2 million. Furthermore, five of the nine on-chain insurance protocols are reportedly set to become inactive or change their strategy by August 2026.
end-content






