Morning Edition · Thursday, September 3, 2026Published at 1:55 AM EDT · New York
Avici lost about 500,800 dollars across 1,685 users and Tria more than 430,000 dollars across 636 users, with both firms pledging full reimbursement while the stolen funds moved through Tornado Cash.

An outdated version of a card contract from the crypto card infrastructure firm Rain let an attacker take administrative control of individual card-collateral accounts on Solana and withdraw their balances, taking about 1.1 million dollars from programs that relied on it. The root cause was access control in a deprecated contract that customers were still using, not a novel cryptographic break.
The neobank Avici said roughly 500,800 dollars was taken from 1,685 users, and Tria reported losses above 430,000 dollars across 636 users. Both said they would reimburse affected accounts in full. Rain said it identified the problem in the outdated contract version and upgraded the programs still running it, and reported no further unauthorised activity afterwards. The AVICI token fell as much as 49 percent. Blockchain data showed the attacker converted the stolen stablecoins into SOL, moved them across networks, and routed them through Tornado Cash.
Two smaller incidents also mattered this week. Researchers at DeFiHackLabs published a proof of concept for spot-price manipulation of a Hypervisor position on FloatProtocol using Uniswap V3, the standard pattern in which a protocol reads an instantaneous pool price instead of a time-weighted one. Separately, KiiChain said an attacker moved 148.3 million KII tokens out through the Hyperlane bridge to BNB Smart Chain across 18 transactions on 22 August, and has not published a dollar figure or an attribution. Rekt News is tracking that incident alongside Mantra, Term Labs and TAC.
What this means
The costly failure here was operational, not cryptographic. Rain released a fixed contract, but the money was lost because integrators were still using the old one, so the party exposed was the end user of a consumer card product who had no way to know which contract version held their collateral. Fintech firms that build on shared crypto infrastructure inherit the deprecation risk of every dependency, and audits scoped to the current version do not cover it. Reimbursement by Avici and Tria shifts the loss onto the companies' balance sheets, which is the practical reason consumer crypto products keep moving toward custodial models where a firm can absorb a failure.
What to watch
Part of a tracked trend
Bridge and Mint Exploits Sustain Heavy DeFi Losses
Over 3-6 months, recurring bridge proof-validation and unauthorized-mint exploits keep monthly DeFi losses elevated, including drains of deprecated contracts.
Start a discussion in Townsquare.
More from this edition
Observations to monitor, not financial advice.
Synthesized from: crypto.news · DeFiHackLabs · Rekt News
Comments
0No comments yet.