Crypto news report · source clearly identified
Avici platform suffers $1 M+ loss in Solana‑based attack, token crashes
An attacker exploited Avici’s Solana authorization contracts, draining over $1 million from user collateral accounts and pushing the AVICI token down 49% in 24 hours.

An attacker targeting the Solana‑based crypto card platform Avici has withdrawn more than $1 million from user collateral accounts. The exploit also caused the AVICI token to tumble to an all‑time low.
How the attack unfolded
On‑chain analysis shows the attacker followed a three‑step process for each affected account:
- Submit a signature through Avici’s authorization program, using Solana’s Ed25519 verification.
- Add a new administrator to the user’s collateral account via the AddCollateralAdmin call.
- Execute a WithdrawCollateralAsset instruction that transferred the collateral to an address controlled by the attacker.
At one checkpoint the attacker’s wallet held 10,005 SOL (≈ $1.07 M) and about $11,600 in USDC/USDT. The wallet performed 14,672 transactions, of which 2,344 failed, and increased its SOL balance by roughly 2,595 tokens (≈ $277 k) within 11 minutes.
Impact on users and token price
Transfers affected at least 125 user accounts, with individual amounts ranging from roughly $9 USDC to over $26,000 USDT. Avici acknowledged a “card balance withdrawal issue” on X but did not confirm the total loss or the number of customers impacted. The AVICI token fell 49.4% in 24 hours, reaching $0.2175, a market cap of about $2.84 M and a 24‑hour volume of $656,543.
Open questions and security context
The incident highlights potential weaknesses in Avici’s authorization controls, which allowed an attacker to add an administrator and withdraw unspent collateral despite the platform’s self‑custody claims. It is unclear whether the breach resulted from a smart‑contract flaw, compromised signing keys, or another failure. Avici has not disclosed whether any signing keys or upgrade authorities were compromised, nor has an independent security audit been published.
Broader relevance
Avici’s programs are upgradeable and share a single upgrade authority, a standard Solana account rather than a multisig. While the Solana blockchain itself shows no known vulnerability, the attack underscores the growing prevalence of key‑compromise incidents, which accounted for 88.3% of crypto thefts in Q2 2026 according to industry reports.
Source & attribution
News Source
- Publisher
- crypto.news
- Original date
- August 28, 2026, 8:23 PM
- Original headline
- Avici attack drains over $1M from Solana users