Avici Attack Drains Over $1M From Solana Users
- An attacker drained over $1 million from Avici users by exploiting the platform's collateral authorization layer on the Solana blockchain.
- The incident involved registering new administrators on user accounts to bypass passkey security and withdraw funds.
- Avici's AVICI token plummeted by nearly 50%, hitting a record low amid revelations of weak upgrade authorities.
- The attack underscores the growing risk of operational control failures in self-custodial crypto neobanks.
An ongoing attack against the Solana-based crypto card platform Avici has reportedly drained more than $1 million from user collateral accounts, sending its governance token to an all-time low. On-chain records indicate the suspected attacker utilized a complex three-step process across affected accounts to bypass the platform's security measures. The incident has highlighted severe vulnerabilities in the platform's authorization logic and operational controls, casting doubt on the efficacy of its self-custody model.
The attacker, initially funded with 1.79 SOL via the deBridge network, executed a massive campaign of 14,672 transactions. By one checkpoint, the attacker's wallet held 10,005 SOL, worth approximately $1.07 million, alongside $11,600 in stablecoins. An anonymous on-chain analyst identified 125 sending accounts with individual transfers ranging from $9 USDCUSDC-- to over $26,000 USDT. Avici acknowledged a card balance withdrawal issue but did not confirm the specific loss amount or detail the security flaw, stating it was working with partners to resolve the situation.
How Did The Attacker Exploit Avici's Authorization Layer?
The attacker exploited Avici's self-custodial authorization layer, which relies on onchain accounts authorized through passkeys instead of traditional seed phrases. Transaction logs reveal a repeated three-step pattern per victim: calling SubmitSignatures through Avici's authorization program, invoking AddCollateralAdmin to register an additional administrator for the user's account, and finally executing WithdrawCollateralAsset to transfer funds to an attacker-controlled account.

This method allowed the attacker to bypass the platform's passkey security and assume administrative control over user collateral accounts. The attacker's wallet periodically swapped stolen stablecoins into SOL to obscure the trail of the funds. Both Avici programs involved were upgradeable and shared the same upgrade authority, a plain Solana account rather than a multisignature account. This setup raises significant questions about the administrative security and upgrade mechanisms employed by the neobank.
Why Does This Highlight Operational Control Risks?
This attack challenges Avici's self-custody claims, which state that users remain in control and Avici never holds their funds. The incident highlights a shift in attack vectors toward operational controls, where compromised keys, signers, and infrastructure accounted for 88.3% of roughly $764 million stolen in the second quarter of 2026. Only a small fraction of tracked projects combined audits, active bug bounties, and third-party monitoring, leaving many platforms vulnerable to such exploits.
The risk is compounded by the fact that Avici's user base is already accustomed to connecting wallets to web interfaces, a core behavior for the product. Scammers have also weaponized this muscle memory through phishing sites impersonating the neobank, further complicating the security landscape. Because Avici does not hold user funds, there is no fraud department to reverse malicious transactions, and the blockchain does not support chargebacks. The platform's model creates a specific risk profile where users must rely entirely on their own security and the integrity of the onchain authorization layer.
The AVICI token fell 49.4% within 24 hours, touching a record low of $0.2175, reflecting the market's reaction to the security breach. The decline exacerbates an existing downward trend, as the token had already shed more than half its value over several months. While some reports suggest the loss was around $600,000 linked to a specific Solana address, the total drained amount appears to exceed $1 million based on on-chain analysis. The incident underscores the growing trend of wallet-level compromises and infrastructure attacks in 2026, which have accounted for a significant portion of crypto losses.
Avici, a Solana-native neobank, aims to bridge decentralized finance and traditional retail banking by allowing users to deposit digital assets to receive a corresponding credit line for spending. The platform utilizes account abstraction for passkey security and futarchy governance through MetaDAO. However, this security incident demonstrates that even advanced onchain security measures can be undermined by flawed administrative controls. The lack of a multisignature upgrade authority and the ability for a single entity to add administrators poses a systemic risk to the platform's users.
Users reported missing balances on social media prior to the official statement, with some noting entire balances were drained while awaiting information. The company's silence on compensation and program status has contributed to market uncertainty, leaving investors and users to speculate on the extent of the damage. For Avici to recover, it must potentially return above the $0.40 level, though immediate trading conclusions remain pending. The incident serves as a stark reminder of the importance of robust operational security and transparent communication in the rapidly evolving crypto neobank sector.
Blending traditional trading wisdom with cutting-edge cryptocurrency insights.
Latest Articles
Stay ahead of the market.
Get curated U.S. market news, insights and key dates delivered to your inbox.



Comments
No comments yet