đš Avici Neobank Breach: $1M+ Drained, AVICI Token Crashes 49%
Solana-based crypto neobank Avici has suffered a major security incident, with attackers draining over $1 million from user collateral accounts.
What happened:
The exploit targeted Aviciâs own smart contracts â attackers chained together SubmitSignatures, AddCollateralAdmin, and WithdrawCollateralAsset calls to add themselves as an admin and siphon user funds. Both affected programs were upgradeable and shared a single standard account for upgrade authority instead of a multisig â a key weakness now under scrutiny.
â ïž Important: This was NOT a Solana network issue. No evidence has emerged of any flaw in the Solana L1 itself. The vulnerability was isolated entirely to Aviciâs own application-layer contracts.
The fallout:
đ AVICI token plunged ~49% to a record low near $0.2175
đ Avici confirmed the breach nearly 2 hours after the first theft, after users had already flagged missing balances on social media
đ”ïž Attackerâs wallet holds 10,000+ SOL (~$1.07M) plus ~$11,600 in USDC/USDT, with funds already moving to other addresses
Bonus damage: A separate phishing wave impersonating Aviciâs site has reportedly drained an additional $600K+ from users who connected wallets to fake lookalike pages.
Why it matters:
Even apps built on fast, secure chains can carry serious risk at the application layer. This highlights the danger of upgradeable contracts without multisig protections â a pattern worth watching across the whole âneobankâ DeFi category. Avici has yet to confirm whether affected users will be reimbursed.
đ Stay safe: Donât connect your wallet to unofficial Avici links, and always verify URLs before any airdrop or âverificationâ prompt.
Not financial advice. DYOR.$SOL #Avici
#defi #CryptoNews #BinanceSquare #AltcoinNews
Solana-based crypto neobank Avici has suffered a major security incident, with attackers draining over $1 million from user collateral accounts.
What happened:
The exploit targeted Aviciâs own smart contracts â attackers chained together SubmitSignatures, AddCollateralAdmin, and WithdrawCollateralAsset calls to add themselves as an admin and siphon user funds. Both affected programs were upgradeable and shared a single standard account for upgrade authority instead of a multisig â a key weakness now under scrutiny.
â ïž Important: This was NOT a Solana network issue. No evidence has emerged of any flaw in the Solana L1 itself. The vulnerability was isolated entirely to Aviciâs own application-layer contracts.
The fallout:
đ AVICI token plunged ~49% to a record low near $0.2175
đ Avici confirmed the breach nearly 2 hours after the first theft, after users had already flagged missing balances on social media
đ”ïž Attackerâs wallet holds 10,000+ SOL (~$1.07M) plus ~$11,600 in USDC/USDT, with funds already moving to other addresses
Bonus damage: A separate phishing wave impersonating Aviciâs site has reportedly drained an additional $600K+ from users who connected wallets to fake lookalike pages.
Why it matters:
Even apps built on fast, secure chains can carry serious risk at the application layer. This highlights the danger of upgradeable contracts without multisig protections â a pattern worth watching across the whole âneobankâ DeFi category. Avici has yet to confirm whether affected users will be reimbursed.
đ Stay safe: Donât connect your wallet to unofficial Avici links, and always verify URLs before any airdrop or âverificationâ prompt.
Not financial advice. DYOR.$SOL #Avici
#defi #CryptoNews #BinanceSquare #AltcoinNews
