Breaking News: Altcoin Hacked, Significant Losses Reported!

cryptonews.ruPublished on 2026-08-28Last updated on 2026-08-28

Abstract

A next-generation banking platform, Avici, operating on the Solana ecosystem, suffered a major security breach. A hacker, using only $190 as seed capital, exploited an authorization vulnerability in Avici's smart contracts to steal approximately $670,000 in user assets. The attack, which began around 16:49 UTC, involved thousands of transactions. The vulnerability stemmed from a flaw where a signature verification error allowed the attacker to be incorrectly authorized as an admin for over 1,100 user collateral accounts. Funds were then withdrawn from these individual accounts, with a median loss of about $24 per account. Blockchain data indicates the stolen funds were not taken from a central treasury. Following the incident, the price of the AVICI token plummeted by over 45%. Initial investigations suggest the breach was due to the smart contract bug itself and not a compromise of the program's upgrade key.

Avici, a next-generation banking platform operating on the Solana ecosystem, has encountered a serious security incident. According to blockchain data, a malicious actor, using only $190 as initial capital, stole assets worth approximately $670,000 from user accounts. Following the incident, the price of the AVICI token dropped by over 45%.

Initial reports from SolanaFloor indicated that over $600,000 was withdrawn from Avici user accounts without authorization. Avici had earlier stated that it had detected an anomaly regarding card withdrawals from the platform and was investigating the matter with its partners. The platform later confirmed that the incident was due to a security breach.

Blockchain analysis revealed that the attack was executed with relatively low costs. The wallet used in the attack was created today at 17:40 and was funded with roughly $190 worth of USDC transferred from the Ethereum network to Solana. It is presumed this amount was primarily used to cover transaction fees.

Reports suggest the attack began around 16:49 UTC and continued across thousands of transactions. The investigation showed the attacker's wallet processed over 8,857 transactions.

Attacker Gains Control Over More Than 1,100 Accounts.

Technical analysis indicates the attack was triggered by an authorization vulnerability in Avici's smart contracts. It is reported that the attacker invoked the AddCollateralAdmin function by sending a specially crafted signature packet, thereby identifying themselves as an administrator on user collateral accounts.

Because the second signature verification was incorrectly directed to the first instruction, the Solana network repeatedly accepted the attacker's signature as valid. This allowed the program to add an administrative key to the system that it should not have accepted under normal circumstances.

It was stated that through this vulnerability, the attacker gained administrative privileges over more than 1,100 collateral accounts and then proceeded to withdraw funds from these accounts.

Research revealed that the median amount stolen from a single account in the examined transactions was approximately $24, while the largest single loss in the sample was $5,268.

Between 18:19 and 18:34, a large sum of funds, approximately $576,000, was reportedly transferred from the attacker's wallet to other addresses, after which new funds continued to flow into the attacker's address. The total loss is subsequently estimated to have reached roughly $670,000.

Preliminary investigation suggests the attack was not caused by a hack of Avici's program upgrade key. It was noted that the program has not been modified or upgraded to a new version, and the upgrade key has not been used since March 2025.

Therefore, it is believed the incident occurred directly due to an authorization error in the smart contract, rather than theft of a deployment or upgrade key.

On another note, claims have surfaced on social media suggesting the attack was related to draining Avici's central treasury. However, blockchain data does not support this claim. According to current data, funds were withdrawn from individual user accounts, not from a single treasury account.

Following the security incident, selling pressure on the AVICI token intensified, and its price rapidly fell by more than 45%.

The chart shows the decline in AVICI's price.

*This is not investment advice.

end-content

Trending Cryptos

Related Questions

QWhat was the key vulnerability exploited by the hacker in the Avici security incident?

AThe attack was caused by an authorization vulnerability in Avici's smart contracts. The hacker was able to call the 'AddCollateralAdmin' function and have a malicious signature incorrectly validated as legitimate by the Solana network, which granted them administrative privileges over user accounts.

QWhat was the estimated total financial loss due to the hack on Avici?

AThe attacker stole assets worth approximately $670,000 from user accounts on the Avici platform.

QHow did the initial deposit of $190 contribute to the attack?

AThe approximately $190 in USDC, transferred from Ethereum to Solana, served as the initial capital for the attacker's wallet and was primarily used to cover transaction fees necessary to carry out the thousands of transactions involved in the attack.

QWhat impact did the security incident have on the price of the AVICI token?

AFollowing the security incident, the price of the AVICI token fell by more than 45% due to increased selling pressure.

QDid the blockchain data confirm allegations that the hack targeted Avici's central treasury?

ANo, blockchain data does not support the allegation that the attack targeted Avici's central treasury. The funds were withdrawn from individual user accounts, not from a single treasury account.

Related Reads

How Can Bitcoin Resist Quantum Computers? A Comparative Analysis of Three Lattice-Based Signature Schemes

This report from Blockstream Research analyzes three lattice-based signature schemes as quantum-resistant candidates for Bitcoin, focusing on Dilithium, Falcon, and the now-withdrawn Hawk. Core evaluation criteria include on-chain costs (combined size of public key and signature), implementation complexity, deployment risks, and potential for integration with Bitcoin's existing infrastructure like BIP-32 hierarchical deterministic wallets. Key Findings: * **Dilithium** is praised for its design simplicity, using only integer operations, making secure implementation easier. However, it has the largest size (5,261 bytes for security level 3). * **Falcon** offers the most compact signatures and the fastest verification. Its main drawback—platform-dependent floating-point operations in signing—can be mitigated with a slower, deterministic integer-based implementation. The report recommends **Falcon-1024** (security level 5) for its safety margin. * **Hawk**, which aimed for a better balance, was withdrawn after a cryptographic attack revealed a structural flaw that halved its estimated security. The report concludes that Falcon-1024 is the most suitable lattice-based choice for Bitcoin, pending the finalization of its NIST FN-DSA standard. In the short term, it still recommends hash-based signatures (like SPHINCS+) as a lower-risk transitional solution, with future hybrid deployments as a possibility.

marsbit1h ago

How Can Bitcoin Resist Quantum Computers? A Comparative Analysis of Three Lattice-Based Signature Schemes

marsbit1h ago

Ripple (XRP) Company Announces Plans for Major Future Update

Ripple (XRP) has announced a four-phase plan to prepare the XRP Ledger (XRPL) for future security threats posed by quantum computers. The company's senior director of engineering stated the goal is to build necessary infrastructure before quantum computers become a direct threat, aiming to minimize impact on existing systems, user assets, and network operations. The plan begins with identifying potential quantum vulnerabilities within XRPL, followed by testing quantum-resistant cryptographic methods. The next phase involves parallel testing of existing security mechanisms and new quantum-resistant solutions to ensure reliability and prevent disruption for users and applications. The final phase would involve transitioning the XRPL to more comprehensive, quantum-resistant security standards if the technology matures. Ripple is also developing contingency plans for a faster-than-expected advancement of quantum computing, which could accelerate the transition timeline. A current XRPL feature allowing users to change the keys controlling their accounts without altering the accounts themselves is seen as a potential advantage in any future migration. However, Ripple cannot unilaterally change transaction validation rules or network-wide cryptographic standards; such updates require coordination and approval from independent validators via XRPL's governance process. While quantum computers are not yet capable of breaking the cryptography used by major blockchains like Bitcoin or XRPL, developers across the industry are already evaluating transition scenarios to quantum-resistant algorithms due to the long-term risks they pose to public-key cryptography.

cryptonews.ru2h ago

Ripple (XRP) Company Announces Plans for Major Future Update

cryptonews.ru2h ago

Trading

Spot

Hot Articles

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of SOL (SOL) are presented below.

活动图片