A coordinated attack on Solana-based crypto card platform Avici has siphoned more than $1 million from user collateral accounts and sent the AVICI token tumbling to record lows, on-chain analysts say. What happened - On-chain data shows a single attacker-controlled wallet amassed 10,005.03 SOL (about $1.07 million) plus roughly $11,600 in USDC and USDT as of 18:58 UTC. Analysis was compiled while the incident was still ongoing. - The malicious address received its first funding via deBridge at 13:40 UTC (1.79 SOL from another network). After roughly three hours of inactivity, it began interacting with Avici programs at 16:49:48 UTC. - Transaction traces reviewed by analysts reveal a repeatable three-step pattern across affected accounts: 1. A SubmitSignatures call through Avici’s authorization program — in a transaction that also used Solana’s Ed25519 signature verification program. 2. An AddCollateralAdmin call on Avici’s collateral program to register an additional administrator for the user’s collateral account. 3. A WithdrawCollateralAsset call that moved collateral into an attacker-controlled address. Concrete examples and scale - In one transaction, the attacker withdrew 2,346.77 USDT from a user collateral account. The attacker also swapped some stablecoins into SOL, including a swap that returned 209.76 SOL. - By the publication’s checkpoint, the attacker wallet had signed 14,672 transactions (2,344 failed). During an 11‑minute burst the wallet’s SOL balance rose by about 2,595 tokens, roughly $277,000 at the time. - Anonymous on-chain analyst STACC created a live tracker showing 125 sending accounts linked to the incident, with individual withdrawals ranging from about 9 USDC to more than 26,000 USDT. What Avici and others have said - Avici acknowledged the issue in an X post roughly 1 hour 53 minutes after the first transaction involving its programs: “We’re aware of an issue affecting card balance withdrawals and are closely monitoring the situation.” The company said it was working with partners and would provide updates, but did not call the incident an exploit, quantify loss, or say how many customers were affected. - No independent post-mortem has been published yet. The observed transaction sequence shows how funds moved but does not establish how the attacker obtained authorization — possibilities include a program vulnerability, compromised credentials or signing authority, or other operational failures. Technical and governance notes - Reports indicate the affected Avici card collateral and authorization programs were upgradeable and shared the same upgrade authority. That authority was reportedly a standard Solana account (not a multisig), though no evidence currently links the upgrade authority to the withdrawals. - The incident appears to involve Avici’s programs rather than a flaw in the Solana blockchain itself; no reports to date have identified a vulnerability in Solana’s underlying protocol. - The ability to add an admin and withdraw unspent collateral raises serious questions about how Avici’s authorization controls enforced the product’s advertised self-custody model. Avici presents its product as a self-custodial wallet paired with a secured Visa card, with collateral accounts determining credit limits and settlement. Broader context - Operational controls — compromised keys, signers and infrastructure — have accounted for a large share of recent crypto thefts. A Hacken report cited by industry outlets found such operational compromises made up 88.3% of roughly $764 million stolen in Q2 2026. - Payment partners named in Avici’s documentation include Rain, a stablecoin payment infrastructure provider that works with licensed institutions to issue Visa- and Mastercard-connected cards. Neither Avici nor Rain has said Rain’s systems were compromised; available analysis points to Avici’s Solana programs. User impact and market reaction - Users reported missing balances on social media before Avici’s statement; at least one user said their entire Avici balance was drained while awaiting a response from the project. - AVICI token plunged 49.4% in 24 hours to $0.2175 (CoinGecko figures cited at the time), cutting market capitalization to roughly $2.84 million and pushing the price to a record low. Trading volume for the 24‑hour window was about $656,543, with most AVICI trading on MetaDAO’s futarchy AMM and additional activity on LBank, KCEX and MEXC. The token remains about 97% below its Nov. 26, 2025 peak of $7.56. Company background - Avici Inc. is a U.S.-based company (San Francisco address listed; privacy policy identifies Delaware incorporation). It ran a capped MetaDAO token sale in October 2025 that raised $3.5 million after returning roughly 89.8% of pledges due to the cap. The sale priced AVICI at $0.35 and issued 10 million tokens (about 77.5% of a 12.9 million supply). Open questions - Has the attacker stopped? Has Avici paused its programs? Were signing keys or administrative accounts compromised? Will affected users be compensated? Independent security analysis and a post-mortem from Avici will be needed to determine root cause and scope. Takeaway The incident highlights persistent risks around operational security and custody models in crypto payment products: even projects that advertise self-custody can be vulnerable if authorization flows, key management, or administrative controls are weak. The industry will be watching for a full technical explanation from Avici or an independent auditor. Read more AI-generated news on: undefined/news