Avici attack drains over $1M from Solana users
An ongoing attack against Solana-based crypto card platform Avici has reportedly drained more than $1 million from user collateral accounts while sending its AVICI token to an all-time low.
Summary
- The suspected attacker held 10,005 SOL and about $11,600 in stablecoins at one checkpoint.
- On-chain records showed repeated calls that added an administrator before collateral withdrawals.
- Avici acknowledged a card balance withdrawal issue but did not confirm the reported loss.
- AVICI fell 49.4% within 24 hours and touched a record low of $0.2175.
Avici attacker adds administrators before withdrawals
According to reports, the suspected attacker had collected 10,005.03 SOL, worth about $1.07 million at 18:58 UTC, along with approximately $11,600 in USDC and USDT. Its analysis was based on Solana transaction logs and RPC data gathered while the attack was still underway.
The wallet received its initial funding through deBridge at 13:40 UTC, when 1.79 SOL arrived from another network. After remaining inactive for about three hours, the address made its first call involving Avici's programs at 16:49:48 UTC.
Transaction logs reviewed by the publication showed the same three-step process across affected accounts. First, the wallet called SubmitSignatures through Avici's authorization program in a transaction that also used Solana's Ed25519 signature verification program.
You might also like: CCC exploit drains $117K after attacker targets BSC liquidity pool
Next, the attacker called AddCollateralAdmin on Avici's collateral program, registering an additional administrator for the user's account. A final WithdrawCollateralAsset call then transferred the collateral to an account controlled by the attacker.
In one reviewed transaction, the withdrawal instruction moved 2,346.77 USDT from a user's collateral account. The attacker also converted some of the collected stablecoins into SOL, including one swap that returned 209.76 SOL.
By the publication's checkpoint, the wallet had signed 14,672 transactions, of which 2,344 had failed. Its SOL holdings increased by about 2,595 tokens, then worth approximately $277,000, during an 11-minute period.
Anonymous on-chain analyst STACC also created a live tracker for the affected transfers. According to figures cited from the tracker, 125 sending accounts had been identified, with individual transfers ranging from approximately 9 USDC to more than 26,000 USDT.
Neither Avici nor an independent security company has published a post-mortem identifying how the attacker obtained authorization. Although the transaction sequence shows how funds moved, it does not establish whether the incident resulted from a program flaw, compromised credentials, an exposed signing authority, or another failure.
Avici confirms card withdrawal issue
Avici acknowledged the incident in an X post published about one hour and 53 minutes after the first reported transaction involving its programs.
"We're aware of an issue affecting card balance withdrawals and are closely monitoring the situation."
The company added that it was working directly with relevant partners and would provide updates once more information became available. Avici did not call the incident an exploit, confirm how much had been taken or state how many customers were affected.
Several other questions also remain unanswered, including whether the activity has stopped, whether Avici has paused its programs, and whether affected users will receive compensation. The company has not disclosed whether any signing keys or administrative accounts were compromised.
Users had reported missing balances on social media before Avici released its statement. One user notably said their entire Avici balance had been drained while they waited for information from the project.
The incident concerns Avici's card collateral and authorization programs rather than the Solana network itself. No available report has identified a vulnerability in Solana's underlying blockchain.
Both Avici programs were upgradeable and shared the same upgrade authority, according to reports. The authority was reportedly a standard Solana account rather than a multisignature account, although no evidence has yet shown that the upgrade authority caused or enabled the withdrawals.
Operational controls have received increased attention as attacks move beyond flaws contained in smart contract code. In July, crypto.news reported security findings showing that compromised keys, signers and infrastructure accounted for 88.3% of roughly $764 million stolen during the second quarter of 2026. The Hacken report cited in the article found that only 4% of tracked projects combined audits, active bug bounties, and third-party monitoring.
Avici attack challenges its self-custody claims
Avici describes its product as a self-custodial wallet connected to a secured Visa credit card. Its Apple App Store listing states that users remain in control and that Avici never holds their funds.
Under the card model, customers deposit crypto into collateral accounts and receive a corresponding credit limit. Purchases reduce the available card balance, while the related collateral is later used for settlement.
The reported ability to add another administrator and remove unspent collateral raises questions about how Avici's authorization controls enforce its advertised self-custody model. A technical finding will require Avici or an independent security company to explain why the attacker's signature submissions were accepted.
Avici's documentation identifies Rain as a partner involved in its card service. Rain supplies stablecoin payment infrastructure and works with licensed institutions to issue cards connected to Visa and Mastercard. Available transaction analysis points to Avici's Solana programs, and neither Avici nor Rain has said that Rain's or Visa's systems were compromised.
The distinction is important for users because a self-custodial payment product is supposed to keep unspent assets under the wallet owner's control. Tangem introduced a similar model in November 2025, with on-chain USDC spending through a virtual Visa card while users retained custody of their funds.
Payment infrastructure has also faced separate wallet-related incidents. In July, on-chain analysts identified suspicious outflows exceeding $9.7 million from wallets linked to stablecoin payment provider Triple-A across networks including Solana, Ethereum, TRON and TON. Triple-A had not confirmed whether customer assets were involved when the report was published.
-- Price
AVICI falls 49% to an all-time low
AVICI dropped 49.4% over 24 hours to $0.2175 as reports of the withdrawals spread, according to CoinGecko data cited at the time. The selloff reduced the token's market capitalization to approximately $2.84 million and pushed its price to a record low.
Trading volume reached about $656,543 during the same 24-hour period. Most AVICI trading occurred through MetaDAO's futarchy automated market maker, while LBank, KCEX and MEXC accounted for the remaining reported activity.
CoinGecko lists AVICI's record high at $7.56, reached on Nov. 26, 2025. The incident-day low left the token approximately 97% below that peak.
Avici Inc. is a US company that lists a San Francisco address on its website, while its privacy policy identifies it as a Delaware corporation. The platform also provides separate card terms for US customers, creating direct exposure for eligible American users of its wallet and secured card services.
The company raised $3.5 million through a capped MetaDAO token sale in October 2025. MetaDAO's fundraising record shows that 7,352 contributors committed approximately $34.23 million, but Avici returned about 89.8% of the pledged USDC after applying the sale cap.
The offering priced AVICI at $0.35 and valued the project at approximately $4.52 million on a fully diluted basis. Avici issued 10 million tokens through the sale, representing about 77.5% of its 12.9 million-token supply.
Read more: Tokenized gold is becoming productive collateral in crypto lending, Arch says
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Utorg Launches iPhone App, Official Channel Statements Diverge

B.AI has reached a strategic cooperation with deBridge to jointly build cross-chain infrastructure for the AI agent era

Affected by the Coinbase Listing Roadmap, DBR experiences a short-term 15% price surge.

Insight: Flow Rollback Blockchain Decision Made Without Key Bridge Partner Communication, Potential Economic Loss Far Exceeds Vulnerability Itself

The Future of Cryptocurrency: Transforming from a Speculative Asset to the Internet’s Core Infrastructure
Key Takeaways The adoption of cryptocurrency is shifting towards integrating blockchain as a foundational, secure communication layer in…

Coinbase to List deBridge (DBR) for Spot Trading

Coinbase Listing Roadmap Update: deBridge (DBR)

The Persistence of Retail Demand: The Structural Challenge for the BCRA in the Face of Currency Coverage

ZONDACRYPTONawrocki Responds to Allegations: I Have Not Met Przemysław Kral

Major Altcoin Cleanup: 18 Cryptocurrencies Delisted from South Korean Exchanges

Bitcoin: 12 Years After His Death, Why Hal Finney Still Fascinates

Bitcoin Knots is trying to fork Bitcoin again after its last chain died in two blocks

BlackRock is Buying Ethereum in Bulk. Will ETH Outpace Bitcoin in the New Bull Market?

Ethereum: Gnosis Chain Abandons Its Status as an Independent Blockchain to Become a Rollup

Cryptocurrency Scammers and Wallet Graphs: How the Central Bank Tracks Shadow Chains

Court Orders Bithumb Client to Return $140,400 for Accidentally Sent Bitcoins

Barcelona Embraces AI: The AI Summit Concludes a Busy September

50% Tariff on Canada: What Changes with the 1930 Law

The SEC is reviewing automatic filing pathways after exotic crypto and event-linked ETF proposals flooded the market

Digital Trust: A Strategic Asset in the Financial System

Evernorth’s XRP strategy hinges on one number after Nasdaq vote

How Can Bitcoin Withstand Quantum Computers? A Comparison of Three Lattice-Based Signature Schemes

Ethena Perpetual Equity Contracts: Ethena Seeks New Yield for USDe in Perpetual Equity Contracts

Cyberattack in Manchester: 8.7 Million Travelers Compromised by Free Airport Wi-Fi

Cryptocurrency Platforms Lost $3.63 Billion Due to Cyberattacks

Google Creates WikiSkill for AI Agents to Remember Their Mistakes and Improve

UK police seize $1.4M tied to darknet market activity

Lambda Raises $1 Billion in Debt to Purchase Nvidia Chips

Chinese Automakers Bet on Humanoid Robots as a New Source of Profit

A Founder’s Reflection: Why Did Fomo Run Further Than Us from the Same Starting Point?
Utorg Launches iPhone App, Official Channel Statements Diverge
B.AI has reached a strategic cooperation with deBridge to jointly build cross-chain infrastructure for the AI agent era
Affected by the Coinbase Listing Roadmap, DBR experiences a short-term 15% price surge.
Insight: Flow Rollback Blockchain Decision Made Without Key Bridge Partner Communication, Potential Economic Loss Far Exceeds Vulnerability Itself
The Future of Cryptocurrency: Transforming from a Speculative Asset to the Internet’s Core Infrastructure
Key Takeaways The adoption of cryptocurrency is shifting towards integrating blockchain as a foundational, secure communication layer in…








