5 Hacks, 30 Days, Millions Lost, Why Neobanks and Crypto Platforms Keep Falling to the Same Basic Mistakes

BTCC
Binance


Your balance sitting in a neobank app feels like money in the bank. For five different groups of users over the past month, it turned out to be something closer to a bet on a smart contract nobody had stress-tested.

Here’s every confirmed incident, in order, with the source to verify each one yourself.

I went through this list expecting the usual scattershot of unrelated hacks. What actually stood out was how mundane most of the failures were, not sophisticated zero-days, but old code, stale approvals, and a single email that looked official enough to work. None of that makes the losses smaller. It just makes them harder to excuse.

Avici: $500,859 Drained From Solana Card Balances

On August 28, an attacker exploited an outdated version of a Solana card contract built by Rain, the infrastructure provider behind Avici’s card program. The attacker called a sequence of functions on Avici’s authorization and collateral programs, ultimately pulling funds out of card balances tied to 1,685 users.

okex

Avici confirmed the loss at $500,859.22 and pledged full reimbursement plus a 10% cashback on top, which is more than most platforms offer after an incident like this. The figure is independently logged in DefiLlama’s hacks database, which tracks the incident by date, amount, and technique.

5 Hacks, 30 Days, Millions Lost, Why Neobanks and Crypto Platforms Keep Falling to the Same Basic Mistakes

Tria: $431,945 Lost To The Same Contract Flaw

The same Rain contract vulnerability hit Tria on the same day, draining $431,945 from 636 customers’ card balances. What’s notable here is that this wasn’t a separate attack, it was the same exploiter, using the same flawed contract version, moving through multiple programs that had all built on top of Rain’s infrastructure without knowing they shared the same exposure.

Tria said ordinary wallets and EVM card balances were untouched, and reimbursed affected users. This incident is logged in the same DefiLlama hacks database alongside Avici’s, which makes the shared-infrastructure pattern easy to see in one place.

Ether.fi: 15.45 ETH Stolen From A Legacy Contract

Two weeks later, on September 11, a much smaller but structurally similar failure hit ether.fi. Security firm SlowMist flagged missing access control in the AtomicQueue contract’s solve() function, a legacy piece tied to an older Veda-built withdrawal queue. The attacker abused the flaw to force victim wallets into acting as “solvers,” then drained funds through pre-existing ERC-20 approvals those wallets had granted.

The total came to roughly 15.45 ETH, worth about $38,000 to $43,000 depending on the price snapshot used. Ether.fi’s CEO confirmed the issue publicly and pledged reimbursement for affected users. The incident is logged in DefiLlama’s hacks database under “ether.fi Liquid.”

5 Hacks, 30 Days, Millions Lost, Why Neobanks and Crypto Platforms Keep Falling to the Same Basic Mistakes

Revolut: A Data Breach That Didn’t Touch A Single Wallet

This one breaks the pattern, and that’s exactly why it belongs on the list. On September 12, Revolut confirmed to Reuters that it had disclosed sensitive customer data, birth dates, addresses, phone numbers, passport and driver’s license copies, and in some cases transaction histories, to an unauthorized third party who had submitted requests from what appeared to be a legitimate government agency email domain.

No code was exploited. No contract was drained. A human process accepted a convincing forgery, and customer identity documents went out the door as a result. I’d argue this incident is more unsettling than the smart contract exploits on this list, precisely because there was no bug to patch, just a process that trusted the wrong email.

Payy Network: $1.83 Million Gone From An Ethereum Rollup

The most recent incident on this list is also the largest. On September 24, an attacker exploited Payy Network’s Ethereum rollup contract, extracting the platform’s entire balance, roughly $1.83 million in USDC, through a malicious transaction that passed through the contract’s verifyRollup function. The stolen funds were swapped into 683.38 ETH and split across three addresses.

5 Hacks, 30 Days, Millions Lost, Why Neobanks and Crypto Platforms Keep Falling to the Same Basic Mistakes

Payy immediately suspended all deposits, withdrawals, transfers, and card transactions while working with law enforcement and incident response teams. The exploit transaction itself is verifiable directly on-chain in the confirmed block on Etherscan as the investigation continues.

Five Incidents, One Uncomfortable Pattern

Laid out together, these five incidents don’t share a single root cause, and I think that’s actually the more useful takeaway than if they did. Two came from the same third-party infrastructure flaw. One came from a legacy contract nobody had gotten around to deprecating. One came from a human process trusting a forged email. One came from a rollup contract’s own verification logic. Different failure modes, same outcome: money or data that users assumed was safely held turned out to depend on code, vendors, or internal processes that hadn’t been stress-tested against exactly this.

5 Hacks, 30 Days, Millions Lost, Why Neobanks and Crypto Platforms Keep Falling to the Same Basic Mistakes

None of these platforms were obscure or unaudited by reputation. Avici and Tria both had active card products with real user bases. Ether.fi is one of the larger names in liquid restaking. Revolut is a licensed, regulated bank with more than 80 million customers. Payy had already patched a critical flaw earlier this year and still got hit through a different part of its stack four months later. If there’s a lesson in the roll call, it’s that “regulated” and “well-known” aren’t the same thing as “immune,” and that the funds sitting in any card balance, restaking vault, or payment rollup carry the risk profile of the weakest contract or process behind them, not the reputation of the brand on the app icon.

Disclosure: This is not trading or investment advice. Always do your research before buying any cryptocurrency or investing in any services. Follow us on X @nulltxnews



Source link

Bybit

Be the first to comment

Leave a Reply

Your email address will not be published.


*