A live exploit targeting Avici, a neobank built on the Solana blockchain, drained more than $1 million from user accounts in an active, ongoing attack — one of the starkest examples yet of what happens when crypto-native banking infrastructure fails in real time, with real customer money on the line.

The attacker's wallet accumulated 10,005 SOL at the time of reporting, and critically, the wallet was still receiving funds when the story broke. This was not a post-mortem. This was a heist in progress, playing out transparently on a public ledger while users remained largely unaware that their card balances were being siphoned.

What makes the incident particularly damaging — beyond the raw dollar figure — is the response timeline. Avici publicly acknowledged it was "aware of an issue affecting card balance withdrawals" nearly two hours after the first drain transaction had already been recorded on-chain. In cybersecurity terms, two hours is an eternity. In crypto, where transactions are irreversible and wallets are pseudonymous, it may as well be a lifetime. By the time the company issued even that tepid statement, the attacker had already constructed a substantial position, and the bleeding had not stopped.

This is the central contradiction of crypto neobanking: the transparency of blockchain infrastructure means that exploits are visible to anyone with a block explorer, yet the institutions built on top of that infrastructure can still fail to detect, acknowledge, or halt an attack for hours. The attacker exploited card balance withdrawals — a bridge between the crypto-native backend and a more traditional payment interface — suggesting the vulnerability may have lived precisely at the junction between the two systems. That seam, where decentralized rails meet conventional fintech UX, is where risk concentrates.

Solana's speed and low transaction cost, often cited as features that make it ideal for payments and neobanking applications, become liabilities in an exploit scenario. High throughput means an attacker can execute dozens or hundreds of drain transactions in the time it takes a human compliance team to notice an anomaly. The 10,005 SOL figure sitting in the attacker's wallet is a direct product of that throughput — accumulated not in days, but in hours, possibly less.

The broader context here matters enormously. The crypto industry has spent the last two years aggressively marketing the concept of on-chain banking: accounts, debit cards, yield-bearing balances, and global payments, all powered by blockchain rails and accessible through sleek mobile interfaces. Avici was operating squarely within that category. The pitch is compelling. The risk management infrastructure, as this incident demonstrates, has not always kept pace with the ambition. Incident response protocols, automated circuit breakers, anomaly detection systems — these are not optional features for a neobank. They are the product. And a two-hour detection gap on an active drain event is a fundamental operational failure, regardless of what the underlying technology stack looks like.

It would be premature to draw sweeping conclusions about Solana's security or the viability of crypto neobanking from a single incident. But the Avici attack fits a pattern: fast-moving exploits, slow institutional responses, and users left exposed during the gap. The vulnerability in this case targeted card balance withdrawals specifically, which points toward a systemic design or access control flaw rather than a broad network compromise. That distinction matters for attributing blame, but it does not change the outcome for the affected users who watched their balances disappear.

What regulators, developers, and prospective users should take from this episode is straightforward: the promise of crypto-native banking is real, but it requires the same — arguably greater — operational discipline as traditional finance. Real-time monitoring, automated fund freezes upon anomaly detection, and rapid public communication are table stakes, not differentiators. Any neobank operating on high-throughput chains like Solana, where an attacker can move thousands of SOL within minutes, must assume that the window between exploit initiation and catastrophic loss is measured in seconds, not hours. Building response infrastructure around that assumption is not a competitive advantage — it is the minimum viable product for handling other people's money.

Written by the editorial team — independent journalism powered by Bitcoin News.