Breaking News: Altcoin Hacked, Significant Losses Reported!

cryptonews.ruPublished on 2026-08-28Last updated on 2026-08-28

Abstract

A next-generation banking platform, Avici, operating on the Solana ecosystem, suffered a major security breach. A hacker, using only $190 as seed capital, exploited an authorization vulnerability in Avici's smart contracts to steal approximately $670,000 in user assets. The attack, which began around 16:49 UTC, involved thousands of transactions. The vulnerability stemmed from a flaw where a signature verification error allowed the attacker to be incorrectly authorized as an admin for over 1,100 user collateral accounts. Funds were then withdrawn from these individual accounts, with a median loss of about $24 per account. Blockchain data indicates the stolen funds were not taken from a central treasury. Following the incident, the price of the AVICI token plummeted by over 45%. Initial investigations suggest the breach was due to the smart contract bug itself and not a compromise of the program's upgrade key.

Avici, a next-generation banking platform operating on the Solana ecosystem, has encountered a serious security incident. According to blockchain data, a malicious actor, using only $190 as initial capital, stole assets worth approximately $670,000 from user accounts. Following the incident, the price of the AVICI token dropped by over 45%.

Initial reports from SolanaFloor indicated that over $600,000 was withdrawn from Avici user accounts without authorization. Avici had earlier stated that it had detected an anomaly regarding card withdrawals from the platform and was investigating the matter with its partners. The platform later confirmed that the incident was due to a security breach.

Blockchain analysis revealed that the attack was executed with relatively low costs. The wallet used in the attack was created today at 17:40 and was funded with roughly $190 worth of USDC transferred from the Ethereum network to Solana. It is presumed this amount was primarily used to cover transaction fees.

Reports suggest the attack began around 16:49 UTC and continued across thousands of transactions. The investigation showed the attacker's wallet processed over 8,857 transactions.

Attacker Gains Control Over More Than 1,100 Accounts.

Technical analysis indicates the attack was triggered by an authorization vulnerability in Avici's smart contracts. It is reported that the attacker invoked the AddCollateralAdmin function by sending a specially crafted signature packet, thereby identifying themselves as an administrator on user collateral accounts.

Because the second signature verification was incorrectly directed to the first instruction, the Solana network repeatedly accepted the attacker's signature as valid. This allowed the program to add an administrative key to the system that it should not have accepted under normal circumstances.

It was stated that through this vulnerability, the attacker gained administrative privileges over more than 1,100 collateral accounts and then proceeded to withdraw funds from these accounts.

Research revealed that the median amount stolen from a single account in the examined transactions was approximately $24, while the largest single loss in the sample was $5,268.

Between 18:19 and 18:34, a large sum of funds, approximately $576,000, was reportedly transferred from the attacker's wallet to other addresses, after which new funds continued to flow into the attacker's address. The total loss is subsequently estimated to have reached roughly $670,000.

Preliminary investigation suggests the attack was not caused by a hack of Avici's program upgrade key. It was noted that the program has not been modified or upgraded to a new version, and the upgrade key has not been used since March 2025.

Therefore, it is believed the incident occurred directly due to an authorization error in the smart contract, rather than theft of a deployment or upgrade key.

On another note, claims have surfaced on social media suggesting the attack was related to draining Avici's central treasury. However, blockchain data does not support this claim. According to current data, funds were withdrawn from individual user accounts, not from a single treasury account.

Following the security incident, selling pressure on the AVICI token intensified, and its price rapidly fell by more than 45%.

The chart shows the decline in AVICI's price.

*This is not investment advice.

end-content

Trending Cryptos

Related Questions

QWhat was the key vulnerability exploited by the hacker in the Avici security incident?

AThe attack was caused by an authorization vulnerability in Avici's smart contracts. The hacker was able to call the 'AddCollateralAdmin' function and have a malicious signature incorrectly validated as legitimate by the Solana network, which granted them administrative privileges over user accounts.

QWhat was the estimated total financial loss due to the hack on Avici?

AThe attacker stole assets worth approximately $670,000 from user accounts on the Avici platform.

QHow did the initial deposit of $190 contribute to the attack?

AThe approximately $190 in USDC, transferred from Ethereum to Solana, served as the initial capital for the attacker's wallet and was primarily used to cover transaction fees necessary to carry out the thousands of transactions involved in the attack.

QWhat impact did the security incident have on the price of the AVICI token?

AFollowing the security incident, the price of the AVICI token fell by more than 45% due to increased selling pressure.

QDid the blockchain data confirm allegations that the hack targeted Avici's central treasury?

ANo, blockchain data does not support the allegation that the attack targeted Avici's central treasury. The funds were withdrawn from individual user accounts, not from a single treasury account.

Related Reads

Access to Active Sessions Instead of Databases: How the Shadow Market in Russia Has Changed

The Russian cybercriminal underground is shifting from selling massive, stolen corporate databases to trading active, short-term access to user accounts, according to a 2026 report. The value of information intercepted directly from infected devices by malware has risen nearly 13% in a year. Attackers now sell packets containing active session tokens (bypassing passwords and two-factor authentication), live email credentials, VPN and cloud storage logins, and corporate network access. A subscription for a steady stream of fresh data costs $250-$300 per month, far exceeding the value of outdated archives. While Russian regulators have successfully penalized companies for data leaks from centralized storage—with no repeat violations recorded after imposing turnover fines—this framework fails against the new threat model. Malware now steals data *after* it leaves the corporate perimeter and is on a user's personal device, a legal grey area. In 2026, 60% of studied web attacks aimed to steal keys for infiltrating corporate infrastructure. The situation mirrors global trends, akin to the Genesis Market shutdown in 2023, and highlights a structural risk: the demand for "fresh" data incentivizes botnet operators to maintain long-term control of infected devices for recurring revenue. This creates a persistent vulnerability layer between personal devices and corporate networks, currently outside the reach of existing regulatory protections.

cryptonews.ru1h ago

Access to Active Sessions Instead of Databases: How the Shadow Market in Russia Has Changed

cryptonews.ru1h ago

SlowMist Flags Fake Qwen 3.8 27B GitHub Repository Concealing StealC Information

SlowMist has identified a fake GitHub repository impersonating Alibaba's Qwen 3.8 27B AI model, which contains an information-stealing virus. The repository, created in August 2026, offered a download file of only 487 KB, far smaller than a legitimate 27-billion-parameter model (over 16 GB). The malicious ZIP file contained a Lua-based script disguised as a certificate, which deploys the StealC malware. Once executed, StealC harvests system data, takes screenshots, and steals browser credentials, cryptocurrency wallet information, and more, sending it to attacker-controlled servers. The malware also includes a backup system that can read new server addresses from the Polygon blockchain if the primary server is taken down. This incident is part of a broader campaign called FakeGit, active since March 2025, which has created thousands of malicious repositories. Approximately 800 of these specifically target AI tools using a method called AgentBaiting, sometimes tricking AI assistants into recommending them. Separate reports detail hundreds of other fake GitHub repositories spreading malware like BoryptGrab and campaigns like Megalodon that generate thousands of clones rapidly. Attackers copy legitimate projects, create convincing documentation, and even list them on public AI registries to appear trustworthy. The fake repositories exploit the high demand for open-source AI capabilities, putting users who run models locally at significant risk of data theft.

cryptonews.ru1h ago

SlowMist Flags Fake Qwen 3.8 27B GitHub Repository Concealing StealC Information

cryptonews.ru1h ago

Trading

Spot

Hot Articles

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of SOL (SOL) are presented below.

活动图片