Avici attack drains over $1M from Solana users
An ongoing attack against Solana-based crypto card platform Avici has reportedly drained more than $1 million from user collateral accounts while sending its AVICI token to an all-time low.
Summary
- The suspected attacker held 10,005 SOL and about $11,600 in stablecoins at one checkpoint.
- On-chain records showed repeated calls that added an administrator before collateral withdrawals.
- Avici acknowledged a card balance withdrawal issue but did not confirm the reported loss.
- AVICI fell 49.4% within 24 hours and touched a record low of $0.2175.
Avici attacker adds administrators before withdrawals
According to reports, the suspected attacker had collected 10,005.03 SOL, worth about $1.07 million at 18:58 UTC, along with approximately $11,600 in USDC and USDT. Its analysis was based on Solana transaction logs and RPC data gathered while the attack was still underway.
The wallet received its initial funding through deBridge at 13:40 UTC, when 1.79 SOL arrived from another network. After remaining inactive for about three hours, the address made its first call involving Avici's programs at 16:49:48 UTC.
Transaction logs reviewed by the publication showed the same three-step process across affected accounts. First, the wallet called SubmitSignatures through Avici's authorization program in a transaction that also used Solana's Ed25519 signature verification program.
You might also like: CCC exploit drains $117K after attacker targets BSC liquidity pool
Next, the attacker called AddCollateralAdmin on Avici's collateral program, registering an additional administrator for the user's account. A final WithdrawCollateralAsset call then transferred the collateral to an account controlled by the attacker.
In one reviewed transaction, the withdrawal instruction moved 2,346.77 USDT from a user's collateral account. The attacker also converted some of the collected stablecoins into SOL, including one swap that returned 209.76 SOL.
By the publication's checkpoint, the wallet had signed 14,672 transactions, of which 2,344 had failed. Its SOL holdings increased by about 2,595 tokens, then worth approximately $277,000, during an 11-minute period.
Anonymous on-chain analyst STACC also created a live tracker for the affected transfers. According to figures cited from the tracker, 125 sending accounts had been identified, with individual transfers ranging from approximately 9 USDC to more than 26,000 USDT.
Neither Avici nor an independent security company has published a post-mortem identifying how the attacker obtained authorization. Although the transaction sequence shows how funds moved, it does not establish whether the incident resulted from a program flaw, compromised credentials, an exposed signing authority, or another failure.
Avici confirms card withdrawal issue
Avici acknowledged the incident in an X post published about one hour and 53 minutes after the first reported transaction involving its programs.
"We're aware of an issue affecting card balance withdrawals and are closely monitoring the situation."
The company added that it was working directly with relevant partners and would provide updates once more information became available. Avici did not call the incident an exploit, confirm how much had been taken or state how many customers were affected.
Several other questions also remain unanswered, including whether the activity has stopped, whether Avici has paused its programs, and whether affected users will receive compensation. The company has not disclosed whether any signing keys or administrative accounts were compromised.
Users had reported missing balances on social media before Avici released its statement. One user notably said their entire Avici balance had been drained while they waited for information from the project.
The incident concerns Avici's card collateral and authorization programs rather than the Solana network itself. No available report has identified a vulnerability in Solana's underlying blockchain.
Both Avici programs were upgradeable and shared the same upgrade authority, according to reports. The authority was reportedly a standard Solana account rather than a multisignature account, although no evidence has yet shown that the upgrade authority caused or enabled the withdrawals.
Operational controls have received increased attention as attacks move beyond flaws contained in smart contract code. In July, crypto.news reported security findings showing that compromised keys, signers and infrastructure accounted for 88.3% of roughly $764 million stolen during the second quarter of 2026. The Hacken report cited in the article found that only 4% of tracked projects combined audits, active bug bounties, and third-party monitoring.
Avici attack challenges its self-custody claims
Avici describes its product as a self-custodial wallet connected to a secured Visa credit card. Its Apple App Store listing states that users remain in control and that Avici never holds their funds.
Under the card model, customers deposit crypto into collateral accounts and receive a corresponding credit limit. Purchases reduce the available card balance, while the related collateral is later used for settlement.
The reported ability to add another administrator and remove unspent collateral raises questions about how Avici's authorization controls enforce its advertised self-custody model. A technical finding will require Avici or an independent security company to explain why the attacker's signature submissions were accepted.
Avici's documentation identifies Rain as a partner involved in its card service. Rain supplies stablecoin payment infrastructure and works with licensed institutions to issue cards connected to Visa and Mastercard. Available transaction analysis points to Avici's Solana programs, and neither Avici nor Rain has said that Rain's or Visa's systems were compromised.
The distinction is important for users because a self-custodial payment product is supposed to keep unspent assets under the wallet owner's control. Tangem introduced a similar model in November 2025, with on-chain USDC spending through a virtual Visa card while users retained custody of their funds.
Payment infrastructure has also faced separate wallet-related incidents. In July, on-chain analysts identified suspicious outflows exceeding $9.7 million from wallets linked to stablecoin payment provider Triple-A across networks including Solana, Ethereum, TRON and TON. Triple-A had not confirmed whether customer assets were involved when the report was published.
-- Price
AVICI falls 49% to an all-time low
AVICI dropped 49.4% over 24 hours to $0.2175 as reports of the withdrawals spread, according to CoinGecko data cited at the time. The selloff reduced the token's market capitalization to approximately $2.84 million and pushed its price to a record low.
Trading volume reached about $656,543 during the same 24-hour period. Most AVICI trading occurred through MetaDAO's futarchy automated market maker, while LBank, KCEX and MEXC accounted for the remaining reported activity.
CoinGecko lists AVICI's record high at $7.56, reached on Nov. 26, 2025. The incident-day low left the token approximately 97% below that peak.
Avici Inc. is a US company that lists a San Francisco address on its website, while its privacy policy identifies it as a Delaware corporation. The platform also provides separate card terms for US customers, creating direct exposure for eligible American users of its wallet and secured card services.
The company raised $3.5 million through a capped MetaDAO token sale in October 2025. MetaDAO's fundraising record shows that 7,352 contributors committed approximately $34.23 million, but Avici returned about 89.8% of the pledged USDC after applying the sale cap.
The offering priced AVICI at $0.35 and valued the project at approximately $4.52 million on a fully diluted basis. Avici issued 10 million tokens through the sale, representing about 77.5% of its 12.9 million-token supply.
Read more: Tokenized gold is becoming productive collateral in crypto lending, Arch says
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Rain contract exploit drains $1.1M from card users

Utorg Launches iPhone App, Official Channel Statements Diverge

B.AI has reached a strategic cooperation with deBridge to jointly build cross-chain infrastructure for the AI agent era

Affected by the Coinbase Listing Roadmap, DBR experiences a short-term 15% price surge.

Insights from TOKEN2049: What Changes Are Happening in the Industry?

When Agents Learn to 'Collude': As AI Becomes Smarter, How to Define Safe Boundaries?

ESMA Gives EU Crypto Platforms Three Months to Drop Non-MiCA Stablecoins: What It Means for USDT Holders in Europe

What still works in crypto marketing in 2026 (and what doesn’t)

Trump's Tax Cuts and Strategic Reserve Release Fail to Curb Oil Prices; Energy Price Pressure Before Midterm Elections Ultimately Depends on Middle East Situation

Is AI Breaking the Mathematical Fortress? Is the 'Mathematical Apocalypse' of Cryptocurrency Just a False Alarm?

Sha Ai Lun Talks to Sun Yuchen: How Can Young People Seize Opportunities in the AI Era?

AI agents can pay for your shopping. Who gets your money back?

Kevin O'Leary's Latest Interview: The Next Stop for AI is Not Models, But Energy

Florida imposes new limits for using cryptocurrency ATMs ranging from $2,000 to $10,000

Bitcoin and Quantum Risk: This Study Shows Which Exchanges Are Most Exposed

Polkadot Launches Stablecoin 'dotUSD' Under DAO Governance with USDT Issuance and US Treasury Seed Funding

Debt in Pesos: Market Fears a New 'Wall' of Maturities Every Three Months

Strategy's $150 million-a-day STRC market has a hidden dependency on its own buybacks

Crypto, Starting to Doubt the Narrative

Did the US Government Sell Bitcoin? What the 12,267 BTC Transfer Shows and What On-Chain Data Cannot Prove
No sale has been confirmed. On October 8, 2026, US government-linked wallets moved 12,267 BTC, worth about $1.01 billion, out of a wallet holding funds seized in the 2016 Bitfinex hack, to new unlabeled addresses with no exchange deposit recorded. On-chain data shows movement, not intent, and no US agency has explained the transfers.

National Tax Agency Discusses Next-Generation System "KSK2" and Tax Investigations on Cryptocurrency Assets

Why Bitcoin Could Drop Below $80,000 After Another Failed Bounce

Circle Partners with Tereina to Integrate USDC and EURC into SAP Enterprise Payments

Hedge Funds Forced to Sell to Cut Losses, U.S. 10-Year Treasury Yield May Break 6%

Q3 2026 Earnings Preview: Why Strong Results May Not Lift Stocks & How to Predict Stock Moves with WEEX

Bitcoin Price Slips to a Three-Week Low Near $81,000: Can $80,000 Hold After Three Rejections at $87K?
The Bitcoin price briefly fell below $81,000 on October 9, 2026, its lowest level in nearly three weeks, after repeated failures near $87,000. A bond selloff, weaker tech stocks, spot ETF outflows and a long liquidation wave all added pressure. The $80,000 area is now the key support, while $83,000 is the first level bulls need to reclaim.

Who Will Share the Profits of Cross-Border Remittances in the Stablecoin Era?

Crypto firms turn to Anthropic AI to find security flaws

MedCred: a clandestine publication claims exposure of data from 274,534 users






