Crypto news report · source clearly identified

Avici platform suffers $1 M+ loss in Solana‑based attack, token crashes

An attacker exploited Avici’s Solana authorization contracts, draining over $1 million from user collateral accounts and pushing the AVICI token down 49% in 24 hours.

An attacker targeting the Solana‑based crypto card platform Avici has withdrawn more than $1 million from user collateral accounts. The exploit also caused the AVICI token to tumble to an all‑time low.

How the attack unfolded

On‑chain analysis shows the attacker followed a three‑step process for each affected account:

  • Submit a signature through Avici’s authorization program, using Solana’s Ed25519 verification.
  • Add a new administrator to the user’s collateral account via the AddCollateralAdmin call.
  • Execute a WithdrawCollateralAsset instruction that transferred the collateral to an address controlled by the attacker.

At one checkpoint the attacker’s wallet held 10,005 SOL (≈ $1.07 M) and about $11,600 in USDC/USDT. The wallet performed 14,672 transactions, of which 2,344 failed, and increased its SOL balance by roughly 2,595 tokens (≈ $277 k) within 11 minutes.

Impact on users and token price

Transfers affected at least 125 user accounts, with individual amounts ranging from roughly $9 USDC to over $26,000 USDT. Avici acknowledged a “card balance withdrawal issue” on X but did not confirm the total loss or the number of customers impacted. The AVICI token fell 49.4% in 24 hours, reaching $0.2175, a market cap of about $2.84 M and a 24‑hour volume of $656,543.

Open questions and security context

The incident highlights potential weaknesses in Avici’s authorization controls, which allowed an attacker to add an administrator and withdraw unspent collateral despite the platform’s self‑custody claims. It is unclear whether the breach resulted from a smart‑contract flaw, compromised signing keys, or another failure. Avici has not disclosed whether any signing keys or upgrade authorities were compromised, nor has an independent security audit been published.

Broader relevance

Avici’s programs are upgradeable and share a single upgrade authority, a standard Solana account rather than a multisig. While the Solana blockchain itself shows no known vulnerability, the attack underscores the growing prevalence of key‑compromise incidents, which accounted for 88.3% of crypto thefts in Q2 2026 according to industry reports.

Source & attribution

News Source

Publisher
crypto.news
Original date
August 28, 2026, 8:23 PM
Original headline
Avici attack drains over $1M from Solana users
View original report ↗