Avici, a next-generation banking platform operating on the Solana ecosystem, has encountered a serious security incident. According to blockchain data, a malicious actor, using only $190 as initial capital, stole assets worth approximately $670,000 from user accounts. Following the incident, the price of the AVICI token dropped by over 45%.
Initial reports from SolanaFloor indicated that over $600,000 was withdrawn from Avici user accounts without authorization. Avici had earlier stated that it had detected an anomaly regarding card withdrawals from the platform and was investigating the matter with its partners. The platform later confirmed that the incident was due to a security breach.
Blockchain analysis revealed that the attack was executed with relatively low costs. The wallet used in the attack was created today at 17:40 and was funded with roughly $190 worth of USDC transferred from the Ethereum network to Solana. It is presumed this amount was primarily used to cover transaction fees.
Reports suggest the attack began around 16:49 UTC and continued across thousands of transactions. The investigation showed the attacker's wallet processed over 8,857 transactions.
Attacker Gains Control Over More Than 1,100 Accounts.
Technical analysis indicates the attack was triggered by an authorization vulnerability in Avici's smart contracts. It is reported that the attacker invoked the AddCollateralAdmin function by sending a specially crafted signature packet, thereby identifying themselves as an administrator on user collateral accounts.
Because the second signature verification was incorrectly directed to the first instruction, the Solana network repeatedly accepted the attacker's signature as valid. This allowed the program to add an administrative key to the system that it should not have accepted under normal circumstances.
It was stated that through this vulnerability, the attacker gained administrative privileges over more than 1,100 collateral accounts and then proceeded to withdraw funds from these accounts.
Research revealed that the median amount stolen from a single account in the examined transactions was approximately $24, while the largest single loss in the sample was $5,268.
Between 18:19 and 18:34, a large sum of funds, approximately $576,000, was reportedly transferred from the attacker's wallet to other addresses, after which new funds continued to flow into the attacker's address. The total loss is subsequently estimated to have reached roughly $670,000.
Preliminary investigation suggests the attack was not caused by a hack of Avici's program upgrade key. It was noted that the program has not been modified or upgraded to a new version, and the upgrade key has not been used since March 2025.
Therefore, it is believed the incident occurred directly due to an authorization error in the smart contract, rather than theft of a deployment or upgrade key.
On another note, claims have surfaced on social media suggesting the attack was related to draining Avici's central treasury. However, blockchain data does not support this claim. According to current data, funds were withdrawn from individual user accounts, not from a single treasury account.
Following the security incident, selling pressure on the AVICI token intensified, and its price rapidly fell by more than 45%.

*This is not investment advice.
end-content







