A fast-moving attack on Solana payment-card startup Avici has drained more than $1 million in user collateral and sent the AVICI token tumbling to an all-time low, on-chain analysis shows. What happened - On-chain investigators say a wallet accumulated 10,005.03 SOL (about $1.07 million at 18:58 UTC), plus roughly $11,600 in USDC/USDT, while interacting with Avici’s Solana programs during an ongoing exploit. - The wallet was initially funded via deBridge at 13:40 UTC with 1.79 SOL and made its first recorded Avici program call at 16:49:48 UTC. - Transaction logs show a repeated three-step pattern across affected accounts: (1) a SubmitSignatures call to Avici’s authorization program that also used Solana’s Ed25519 verification program, (2) an AddCollateralAdmin call on Avici’s collateral program that registered a new administrator for a user’s account, and (3) a WithdrawCollateralAsset call moving collateral to the attacker-controlled account. Key on-chain details - In one example, 2,346.77 USDT was moved out of a user collateral account. The attacker also swapped stablecoins into SOL in at least one transaction that returned 209.76 SOL. - By the publication’s checkpoint the attacker wallet had signed 14,672 transactions (2,344 failed). Over an 11-minute burst, its SOL balance jumped by ~2,595 SOL (about $277,000 at the time). - Anonymous on-chain analyst STACC ran a live tracker that had identified 125 sending accounts, with individual drained transfers ranging from about 9 USDC to more than 26,000 USDT. Avici’s response—and unanswered questions - Avici posted on X roughly 1 hour 53 minutes after the first program transaction: “We’re aware of an issue affecting card balance withdrawals and are closely monitoring the situation.” The company said it was working with partners and would provide updates, but did not label the event an “exploit,” disclose totals taken, or say how many customers were affected. - Critical questions remain unanswered: Has the activity stopped? Have Avici’s programs been paused? Will affected users be made whole? How was the attacker able to gain authorization—was it a program bug, leaked credentials, exposed signing keys, or another operational failure? Technical context and risks - Reports note the incident involves Avici’s card collateral and authorization programs, not a vulnerability in the Solana blockchain itself. Both of Avici’s programs were upgradeable and shared the same upgrade authority, which reportedly was a standard Solana account (not a multisig). There is no public evidence that the upgrade authority enabled or caused the withdrawals. - The attack raises questions about Avici’s “self-custodial” card model. Under that model customers deposit crypto to collateral accounts to receive a credit limit, and unspent collateral should remain under the user’s control. The attacker’s ability to add an administrator and withdraw unspent collateral suggests that Avici’s authorization and signing controls did not enforce the advertised custody guarantees—however, a definitive technical post-mortem from Avici or an independent security firm is needed to explain why the attacker’s signature submissions were accepted. Partners, broader ecosystem context - Avici’s documentation lists Rain as a payments partner; Rain provides stablecoin payment rails and works with licensed issuers for Visa/Mastercard products. Available transaction traces point to Avici’s Solana programs, and neither Avici nor Rain has said Rain’s systems or Visa were compromised. That distinction matters because a compromise of a third-party payment provider would have different implications than a failure inside Avici’s on-chain logic or key management. - The incident fits a wider trend: operational failures—compromised keys, signers, infrastructure—have accounted for the bulk of recent crypto losses. A Hacken report cited by other outlets found such issues were responsible for 88.3% of roughly $764 million stolen in Q2 2026, while only about 4% of tracked projects combined audits, active bug bounties and third-party monitoring. Market fallout - AVICI fell 49.4% in 24 hours to $0.2175 as reports of the withdrawals circulated (CoinGecko data cited at the time), cutting market cap to roughly $2.84 million and pushing the token to a record low. Trading volume over that period was about $656,543. Most AVICI trades flowed through MetaDAO’s futarchy AMM; LBank, KCEX and MEXC showed additional activity. - AVICI’s all-time high was $7.56 on Nov. 26, 2025; the incident-day low placed the token roughly 97% below that peak. Company background - Avici Inc. lists a San Francisco address and is identified as a Delaware corporation in its privacy policy. The company raised $3.5 million via a capped MetaDAO token sale in October 2025; it returned about 89.8% of pledged USDC after applying the cap. The sale priced AVICI at $0.35 and issued 10 million tokens—about 77.5% of the project’s 12.9 million-token supply. Similar incidents - The broader payments-and-wallet space has seen recent outflows and incidents: in July, on-chain analysts flagged suspicious outflows exceeding $9.7 million from wallets linked to stablecoin payment provider Triple-A across multiple networks. And in November 2025, Tangem launched a self-custodial Visa-linked model that—like Avici’s product—relies on on-chain spending while users ostensibly retain custody. What to watch next - A clear technical post-mortem would provide the most crucial answers: how the attacker’s authorizations were accepted, whether keys or authorities were compromised, whether Avici paused programs, and whether customer restitution will occur. Until Avici or an independent security firm publishes those findings, users and integrators should treat Avici-linked collateral as potentially at risk and monitor on-chain activity and official communications closely. Read more AI-generated news on: undefined/news
