Avici Attack Drains Over $1M From Solana (SOL) Card Users
An ongoing attack on Solana-based card platform Avici drained over $1M from collateral accounts; AVICI fell 49.4% to a record low as phishing scams added…
AI SummaryAI
- Avici attack drained over $1 million from Solana user collateral accounts.
- Attacker wallet held 10,005 SOL plus about $11,600 in USDC and USDT.
- On-chain records show AddCollateralAdmin calls preceded collateral withdrawals.
- AVICI fell 49.4% in 24 hours to a record low of $0.2175.
Over $1M Swept From Collateral Accounts
An active attack on Avici, a Solana-based crypto card platform, has drained more than $1 million from user collateral accounts, per on-chain transaction data reviewed while the incident was still underway. The suspected attacker's wallet received its first funding through cross-chain bridge deBridge at 13:40 UTC, when 1.79 SOL arrived from another network, then sat dormant for roughly three hours before its first call touching Avici's programs at 16:49:48 UTC. From there, on-chain records show a repeated three-step sequence across affected accounts: a SubmitSignatures call through Avici's authorization program alongside Solana's Ed25519 signature verification program, then an AddCollateralAdmin call registering an extra administrator on the user's collateral account, and finally a WithdrawCollateralAsset call that swept collateral to an attacker-controlled address.
One reviewed withdrawal moved 2,346.77 USDT from a single user's account, and the attacker converted portions of the collected stablecoins into SOL along the way, including one swap that returned 209.76 SOL. By an 18:58 UTC checkpoint the wallet held 10,005.03 SOL, worth about $1.07 million, alongside roughly $11,600 in USDC and USDT; its holdings had grown by approximately 2,595 SOL, around $277,000, in a single 11-minute stretch, and the address had signed 14,672 transactions, of which 2,344 failed. A live tracker built by anonymous on-chain analyst STACC identified 125 sending accounts, with individual transfers ranging from about 9 USDC to more than 26,000 USDT.
Avici acknowledged the situation in a post on X about one hour and 53 minutes after the first reported transaction, writing, “We're aware of an issue affecting card balance withdrawals and are closely monitoring the situation,” and adding that it was working directly with relevant partners. The company did not call the event an exploit, confirm the loss amount, or say how many customers were affected. Notably, both affected programs were upgradeable and shared one upgrade authority — a standard account rather than a multisignature setup — though no evidence yet shows that authority enabled the withdrawals. The incident concerns Avici's card collateral and authorization programs only; no report has identified a flaw in the Solana layer-1 network itself.
Phishing Sites Add a Second Front
A parallel scheme has compounded the damage: fraudulent websites impersonating Avici have extracted more than $600,000 from users, according to Coinreaders. The phishing pages persuaded victims to connect their crypto wallets to impostor versions of the neobank's site, handing attackers the access needed to drain balances. Avici markets itself as a self-custodial wallet linked to a secured Visa credit card, and its Apple App Store listing states that users always retain control and that the company never holds their funds — a claim the reported ability to add an administrator and withdraw collateral directly now puts in doubt.
The AVICI token has borne the brunt of the fallout. Earlier in the session it traded down 38.54% at $0.2728; the latest readings show a 49.4% drop over 24 hours to $0.2175, an all-time low leaving the token roughly 97% below its record high of $7.56 set on Nov. 26, 2025. Market capitalization compressed to about $2.84 million on roughly $656,543 of 24-hour volume, most of it routed through MetaDAO's futarchy automated market maker — a dApp that also hosted the project's original fundraise — with LBank, KCEX and MEXC carrying the remainder.
Avici Inc. lists a San Francisco address on its website and is registered as a Delaware corporation, creating direct exposure for eligible US card users. The project raised $3.5 million through a capped MetaDAO token sale in October 2025: 7,352 contributors pledged about $34.23 million, of which roughly 89.8% was returned once the cap applied, with AVICI priced at $0.35 in an offering valuing the project near $4.52 million fully diluted. Its card rails rely on partner Rain, which supplies stablecoin payment infrastructure for Visa and Mastercard-linked issuance; neither Avici nor Rain has said any partner system was compromised.
Authorization Controls Under Scrutiny
Together, the collateral drain and the phishing campaign trace one arc: payment-style applications in the Solana ecosystem are being hit at the authorization layer, not at consensus. The load-bearing primary record is Avici's own X statement, which confirms only a card-balance withdrawal issue and offers no post-mortem; no independent security firm has established whether a program flaw, compromised credentials or an exposed signing key let the attacker's submissions through. Industry data points the same way — a Hacken report found compromised keys, signers and infrastructure behind 88.3% of roughly $764 million stolen in Q2 2026. SOL itself slipped 4.6% over the past 24 hours, and upgrade-authority governance on the network — recently in focus when Kraken's last-minute vote switch pushed the disinflation proposal past 67% — now faces a harder test.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


