BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Markets

Avici attack drains over $1M from Solana users

An ongoing attack against Solana-based crypto card platform Avici has reportedly drained more than $1 million from user collateral accounts while sending its AVICI token to an all-time low. S

AnonymousCryptoCompass newsroom
August 28, 2026
6 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for markets coverage.

An ongoing attack against Solana-based crypto card platform Avici has reportedly drained more than $1 million from user collateral accounts while sending its AVICI token to an all-time low.

Summary
  • The suspected attacker held 10,005 SOL and about $11,600 in stablecoins at one checkpoint.
  • On-chain records showed repeated calls that added an administrator before collateral withdrawals.
  • Avici acknowledged a card balance withdrawal issue but did not confirm the reported loss.
  • AVICI fell 49.4% within 24 hours and touched a record low of $0.2175.

Avici attacker adds administrators before withdrawals

According to reports, the suspected attacker had collected 10,005.03 SOL, worth about $1.07 million at 18:58 UTC, along with approximately $11,600 in USDC and USDT. Its analysis was based on Solana transaction logs and RPC data gathered while the attack was still underway.

The wallet received its initial funding through deBridge at 13:40 UTC, when 1.79 SOL arrived from another network. After remaining inactive for about three hours, the address made its first call involving Avici’s programs at 16:49:48 UTC.

Transaction logs reviewed by the publication showed the same three-step process across affected accounts. First, the wallet called SubmitSignatures through Avici’s authorization program in a transaction that also used Solana’s Ed25519 signature verification program.

You might also like: CCC exploit drains $117K after attacker targets BSC liquidity pool

Next, the attacker called AddCollateralAdmin on Avici’s collateral program, registering an additional administrator for the user’s account. A final WithdrawCollateralAsset call then transferred the collateral to an account controlled by the attacker.

In one reviewed transaction, the withdrawal instruction moved 2,346.77 USDT from a user’s collateral account. The attacker also converted some of the collected stablecoins into SOL, including one swap that returned 209.76 SOL.

By the publication’s checkpoint, the wallet had signed 14,672 transactions, of which 2,344 had failed. Its SOL holdings increased by about 2,595 tokens, then worth approximately $277,000, during an 11-minute period.

Anonymous on-chain analyst STACC also created a live tracker for the affected transfers. According to figures cited from the tracker, 125 sending accounts had been identified, with individual transfers ranging from approximately 9 USDC to more than 26,000 USDT.

Neither Avici nor an independent security company has published a post-mortem identifying how the attacker obtained authorization. Although the transaction sequence shows how funds moved, it does not establish whether the incident resulted from a program flaw, compromised credentials, an exposed signing authority, or another failure.

Avici confirms card withdrawal issue

Avici acknowledged the incident in an X post published about one hour and 53 minutes after the first reported transaction involving its programs.

“We’re aware of an issue affecting card balance withdrawals and are closely monitoring the situation.”

The company added that it was working directly with relevant partners and would provide updates once more information became available. Avici did not call the incident an exploit, confirm how much had been taken or state how many customers were affected.

Several other questions also remain unanswered, including whether the activity has stopped, whether Avici has paused its programs, and whether affected users will receive compensation. The company has not disclosed whether any signing keys or administrative accounts were compromised.

Users had reported missing balances on social media before Avici released its statement. One user notably said their entire Avici balance had been drained while they waited for information from the project.

The incident concerns Avici’s card collateral and authorization programs rather than the Solana network itself. No available report has identified a vulnerability in Solana’s underlying blockchain.

Both Avici programs were upgradeable and shared the same upgrade authority, according to reports. The authority was reportedly a standard Solana account rather than a multisignature account, although no evidence has yet shown that the upgrade authority caused or enabled the withdrawals.

Operational controls have received increased attention as attacks move beyond flaws contained in smart contract code. In July, crypto.news reported security findings showing that compromised keys, signers and infrastructure accounted for 88.3% of roughly $764 million stolen during the second quarter of 2026. The Hacken report cited in the article found that only 4% of tracked projects combined audits, active bug bounties, and third-party monitoring.

Avici attack challenges its self-custody claims

Avici describes its product as a self-custodial wallet connected to a secured Visa credit card. Its Apple App Store listing states that users remain in control and that Avici never holds their funds.

Under the card model, customers deposit crypto into collateral accounts and receive a corresponding credit limit. Purchases reduce the available card balance, while the related collateral is later used for settlement.

The reported ability to add another administrator and remove unspent collateral raises questions about how Avici’s authorization controls enforce its advertised self-custody model. A technical finding will require Avici or an independent security company to explain why the attacker’s signature submissions were accepted.

Avici’s documentation identifies Rain as a partner involved in its card service. Rain supplies stablecoin payment infrastructure and works with licensed institutions to issue cards connected to Visa and Mastercard. Available transaction analysis points to Avici’s Solana programs, and neither Avici nor Rain has said that Rain’s or Visa’s systems were compromised.

The distinction is important for users because a self-custodial payment product is supposed to keep unspent assets under the wallet owner’s control. Tangem introduced a similar model in November 2025, with on-chain USDC spending through a virtual Visa card while users retained custody of their funds.

Payment infrastructure has also faced separate wallet-related incidents. In July, on-chain analysts identified suspicious outflows exceeding $9.7 million from wallets linked to stablecoin payment provider Triple-A across networks including Solana, Ethereum, TRON and TON. Triple-A had not confirmed whether customer assets were involved when the report was published.

AVICI falls 49% to an all-time low

AVICI dropped 49.4% over 24 hours to $0.2175 as reports of the withdrawals spread, according to CoinGecko data cited at the time. The selloff reduced the token’s market capitalization to approximately $2.84 million and pushed its price to a record low.

Trading volume reached about $656,543 during the same 24-hour period. Most AVICI trading occurred through MetaDAO’s futarchy automated market maker, while LBank, KCEX and MEXC accounted for the remaining reported activity.

CoinGecko lists AVICI’s record high at $7.56, reached on Nov. 26, 2025. The incident-day low left the token approximately 97% below that peak.

Avici Inc. is a US company that lists a San Francisco address on its website, while its privacy policy identifies it as a Delaware corporation. The platform also provides separate card terms for US customers, creating direct exposure for eligible American users of its wallet and secured card services.

The company raised $3.5 million through a capped MetaDAO token sale in October 2025. MetaDAO’s fundraising record shows that 7,352 contributors committed approximately $34.23 million, but Avici returned about 89.8% of the pledged USDC after applying the sale cap.

The offering priced AVICI at $0.35 and valued the project at approximately $4.52 million on a fully diluted basis. Avici issued 10 million tokens through the sale, representing about 77.5% of its 12.9 million-token supply.

Read more: Tokenized gold is becoming productive collateral in crypto lending, Arch says