The $600K Lesson: Why Avici Neobank's User-Driven Custody Failed Under Phishing Pressure
PompWolf
The first rule of custody is that you cannot delegate vigilance. The second rule is that if your security model depends on every user being a security expert, you have already lost.
Avici neobank just became the latest case study in this axiom. Over $600,000 in user funds was drained from accounts. The available reporting frames it as a phishing attack — a social engineering vector that exploited a design philosophy rather than a cryptographic weakness. No smart contract vulnerability was deployed. No protocol-level exploit was executed. The breach happened at the level of human decision-making, which is precisely the attack surface that user-driven custody models expand.
I have spent the last nine years dissecting blockchain systems at the code level. I have audited governance contracts, reverse-engineered light client verification processes, and poked at Groth16 circuit logic. I have learned one thing that applies across every layer of this stack: when a system transfers security responsibility to the end user without giving them the tools to actually exercise that responsibility, the system is not decentralized — it is just unaccountable.
This is the deeper finding from the Avici incident. It is not the story of a single platform's failure. It is the story of a custody model that has been sold as a breakthrough but functions, in practice, as a redistribution of risk from the operator to the most vulnerable participant in the system: the average user.
Let me walk through the technical architecture that enabled this attack, why the $600,000 figure is more damning than it initially appears, and what this means for the broader neobank and custody landscape.