🚹 Avici Neobank Breach: $1M+ Drained, AVICI Token Crashes 49%

Solana-based crypto neobank Avici has suffered a major security incident, with attackers draining over $1 million from user collateral accounts.

What happened:
The exploit targeted Avici’s own smart contracts — attackers chained together SubmitSignatures, AddCollateralAdmin, and WithdrawCollateralAsset calls to add themselves as an admin and siphon user funds. Both affected programs were upgradeable and shared a single standard account for upgrade authority instead of a multisig — a key weakness now under scrutiny.

⚠ Important: This was NOT a Solana network issue. No evidence has emerged of any flaw in the Solana L1 itself. The vulnerability was isolated entirely to Avici’s own application-layer contracts.

The fallout:
📉 AVICI token plunged ~49% to a record low near $0.2175
🕐 Avici confirmed the breach nearly 2 hours after the first theft, after users had already flagged missing balances on social media
đŸ•”ïž Attacker’s wallet holds 10,000+ SOL (~$1.07M) plus ~$11,600 in USDC/USDT, with funds already moving to other addresses

Bonus damage: A separate phishing wave impersonating Avici’s site has reportedly drained an additional $600K+ from users who connected wallets to fake lookalike pages.

Why it matters:
Even apps built on fast, secure chains can carry serious risk at the application layer. This highlights the danger of upgradeable contracts without multisig protections — a pattern worth watching across the whole “neobank” DeFi category. Avici has yet to confirm whether affected users will be reimbursed.

🔒 Stay safe: Don’t connect your wallet to unofficial Avici links, and always verify URLs before any airdrop or “verification” prompt.

Not financial advice. DYOR.$SOL #Avici

#defi #CryptoNews #BinanceSquare #AltcoinNews