Press "Enter" to skip to content

A $1.1 million crypto card hack crashed a neobank’s token 49% $BTC

  • A security breach on neobank Avici’s crypto card platform led to the theft of approximately $1.1 million in digital assets.
  • The AVICI token plunged 49% from its 24-hour high, touching an all-time low before recovering part of the decline.
  • The exploit targeted the card infrastructure rather than the core banking ledger, according to the company’s initial incident report.
  • Trading volume spiked to multi-month highs as holders rushed to exit, with the token stabilizing roughly 30% below pre-incident levels.
  • Avici said it has paused card issuance and is working with blockchain forensics firms to trace the stolen funds.

Exploit Details and Immediate Market Reaction

A vulnerability in Avici’s crypto-linked debit card processing system allowed an attacker to drain roughly $1.1 million in stablecoins and ether from a pooled custody wallet on Wednesday, according to the neobank’s incident disclosure. The company said the breach did not affect customer fiat balances or the underlying bank accounts, but the market reaction was severe. Within hours of the announcement, the AVICI token—used for fee discounts and loyalty rewards on the platform—collapsed 49% from its intraday high of $0.082, sliding to a record low of $0.041 before buyers stepped in. The token pared some losses to trade near $0.057 by Thursday morning, still down about 30% from the pre-incident price. On-chain data showed that the attacker converted the stolen assets into ether and moved them through a series of mixers within 90 minutes of the exploit, complicating recovery efforts. Avici’s native token had been one of the better-performing neobank coins in the first half of 2026, supported by a partnership with a European payment processor that expanded its card program to 12 additional countries.

Broader Implications for Neobank Security

The incident highlights a growing risk in the fintech sector: as neobanks integrate crypto wallets with traditional card rails, the attack surface expands beyond conventional banking fraud. Unlike a typical card skimming or credential stuffing attack, this exploit appears to have targeted the smart contract that manages the card’s spending limits and transaction signing. Avici’s preliminary analysis suggests the attacker exploited a reentrancy flaw in the contract’s balance-checking function, allowing repeated withdrawals before the system updated the available balance. Security researchers not affiliated with Avici noted that the flaw was similar to a vulnerability patched in a major DeFi protocol in late 2025, raising questions about code reuse across projects. The neobank has not confirmed whether it audited the contract after that public disclosure. Avici said it has temporarily suspended new card issuance and is requiring two-factor authentication for all existing card-linked wallets while it deploys a fix. The company also stated that it is working with two blockchain forensics firms to trace the funds, though it acknowledged that recovery is unlikely given the mixer usage.

Token Price Outlook and Investor Sentiment

The AVICI token’s recovery will depend on whether Avici can restore confidence in its security posture and whether it decides to compensate affected users. The company has not announced a buyback or a compensation fund, but its treasury holds approximately $18 million in stablecoins, according to its last quarterly report. Analysts are split on the token’s near-term path: some see the current price as oversold given the relatively small absolute loss, while others warn that repeated security incidents could erode the platform’s user base. Trading data shows that the token’s 24-hour volume surged to $42 million, roughly 15 times its average daily turnover, indicating heavy speculative activity. The broader crypto market was flat on the day, suggesting the selloff was idiosyncratic to Avici rather than a sector-wide move. The neobank’s user base of about 400,000 customers has not yet reported any unauthorized transactions on their individual accounts, and Avici emphasized that its banking partners have confirmed no fiat-side exposure. Looking ahead, the key catalyst will be Avici’s full post-mortem report, expected within two weeks. The company has said it will disclose whether the exploit was isolated to the card contract or if other components of its custody infrastructure were compromised. For now, the token remains in a fragile state, with the record low serving as a psychological support level. If the investigation reveals additional vulnerabilities, further downside is possible; if the fix is clean and user funds are protected, the token could reclaim the $0.07 level in the coming weeks. Investors should monitor Avici’s official channels for updates, as the situation remains fluid and the recovery process is far from certain.

Comments are closed.

WP Twitter Auto Publish Powered By : XYZScripts.com