Solana-Based Avici Suffers Smart Contract Exploit Draining Over $1 Million

1 hour ago 5 sources negative

Key takeaways:

  • Avici exploit exposes systemic risks in Solana's self-custody card model, eroding user trust.
  • 49% AVICI drop reflects market pricing in further vulnerabilities; watch for post-mortem.
  • Low attack cost ($190) highlights need for stricter audits across Solana DeFi protocols.

Solana-based crypto card platform Avici suffered a severe security breach on August 28, 2026, with on-chain data showing an attacker drained more than $1 million from user collateral accounts while using only about $190 in initial capital. The exploit sent the AVICI token down roughly 49% in 24 hours to a record low of $0.2175.

According to transaction logs and initial reports, the attacker began interacting with Avici’s programs at approximately 16:49 UTC. The wallet first called SubmitSignatures through Avici’s authorization program, then invoked AddCollateralAdmin on the collateral program to register an additional administrator, and finally used WithdrawCollateralAsset to move funds to an attacker-controlled account.

Technical analysis pointed to an authorization flaw in Avici’s smart contracts rather than a compromised upgrade key. Because a second signature verification was incorrectly routed to the first instruction, the network accepted the attacker’s own signature as valid a second time. This allowed the malicious actor to add administrator privileges over more than 1,100 collateral accounts and withdraw funds. Initial estimates placed the loss near $670,000, but subsequent tracking suggested the total exceeded $1 million. The attacker's wallet processed over 8,857 transactions in one analysis, while another checkpoint recorded 14,672 transactions, of which 2,344 failed. Median loss per examined account was about $24, with the largest sample loss at $5,268.

The suspected attacker accumulated around 10,005 SOL worth about $1.07 million at 18:58 UTC, plus approximately $11,600 in USDC and USDT. The wallet received initial funding through deBridge and remained inactive for about three hours before the first Avici-related transaction.

Avici acknowledged the issue in an X post about one hour and 53 minutes after the first reported transaction, saying: “We’re aware of an issue affecting card balance withdrawals and are closely monitoring the situation.” The company said it was working with partners and would provide updates. However, Avici did not initially confirm the total loss, number of affected users, or whether compensation would be offered.

Avici markets itself as a self-custodial wallet connected to a secured Visa card, claiming it never holds user funds. The ability to add an administrator and withdraw collateral has raised questions about whether the platform’s authorization controls actually enforce its advertised self-custody model. Reports note the affected programs were upgradeable and shared a standard upgrade authority, but no evidence showed the upgrade authority caused the withdrawals. Neither Avici nor independent security researchers have published a post-mortem confirming how the attacker obtained authorization.

The token selloff reduced AVICI’s market capitalization to approximately $2.84 million, with 24-hour trading volume around $656,543. AVICI traded at $0.35 in its October 2025 token sale and reached a record high of $7.56 on Nov. 26, 2025, leaving the token about 97% below that peak at the incident-day low.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.