Security Incident

Avici Attack Drains Over $1 Million From Solana Users As Protocol Token Plummets

An ongoing attack targeting the Solana-based crypto card platform Avici has reportedly drained more than $1 million from user collateral accounts, while the associated AVICI token has fallen to a record low. This development is not officially confirmed.

Digital visualization of security analysis and blockchain transaction tracking for the reported Avici platform incident.
Image: crypto.news

Overview of the Reported Security Breach

Recent independent media reports indicate that an aggressive security incident has impacted the Solana-based crypto card platform Avici, resulting in significant financial losses for platform participants. On-chain monitoring data reviewed during the active phase of the breach showed that an unidentified malicious actor systematically targeted user collateral accounts, draining accumulated funds while sending the protocol's native token down significantly. According to comprehensive transaction log analysis published by crypto.news, the total value extracted during the initial waves of the incident surpassed one million dollars, encompassing substantial quantities of Solana native tokens alongside stablecoin holdings.

The unfolding situation has generated widespread concern throughout the decentralized finance ecosystem, particularly among users who relied on the platform for daily crypto-to-fiat payment functionalities. Independent on-chain investigators and security analysts quickly established live tracking dashboards to monitor the movement of stolen assets across various decentralized exchanges and mixing services. As these tracking metrics circulated across social media channels, market participants reacted swiftly, leading to an intense sell-off that drove the protocol's token valuation down to unprecedented depths. Observers continue to scrutinize blockchain ledgers to determine the full scope of the breach and identify all affected deposit addresses.

Technical Mechanics of the On-Chain Attack

Detailed transaction log reviews revealed a highly structured and repeatable three-step procedure executed against the targeted accounts by the malicious actor. Initially, the perpetrator's wallet interacted with Avici’s authorization program by invoking signature submission functions combined with standard signature verification mechanisms native to the Solana network. This preliminary phase effectively bypassed normal operational boundaries, setting the stage for subsequent administrative manipulation within the collateral management smart contracts.

Following the initial authorization call, the attacker proceeded to execute a specific administrative addition function on Avici’s collateral program, registering an unauthorized entity as an administrator for the victimized account. With administrative privileges successfully appended, the attacker immediately initiated collateral asset withdrawal instructions, systematically transferring deposited funds directly into contractor-controlled wallets. On-chain analysis demonstrated that this precise sequence of instructions was repeated thousands of times across numerous independent accounts, leaving a clear digital trail of exploitation that security researchers continue to dissect.

Platform Response and Official Statements

In the wake of mounting community panic and visible balance discrepancies reported across various social channels, Avici management issued a public acknowledgment addressing the operational anomaly. Approximately two hours after the first suspicious transactions appeared on-chain, the company confirmed via social media that it was actively monitoring an ongoing issue affecting card balance withdrawals. The enterprise emphasized that it was collaborating closely with industry partners and relevant technical contributors to diagnose the root cause behind the unexpected balance movements.

Despite acknowledging the existence of withdrawal difficulties, the platform's initial communications fell short of providing comprehensive clarity regarding the total scale of the security breach. The official statements refrained from characterizing the incident as an explicit exploit, nor did they disclose exact figures concerning the total monetary value taken or the precise number of affected customers. Furthermore, leadership has not yet clarified whether platform programs have been temporarily paused, whether the malicious activity has been entirely contained, or what specific compensation mechanisms might be established for victims.

Self-Custody Claims and Infrastructure Context

The unfolding security incident has cast significant doubt on Avici’s foundational marketing assertions regarding absolute self-custody and user asset sovereignty. Promotional literature and application store descriptions historically assured participants that they maintained complete control over their deposited collateral while utilizing the secured payment card features. However, the reported capability of an external actor to dynamically insert administrative keys and withdraw unspent collateral directly challenges the underlying architectural integrity of these purported self-custodial guarantees.

Industry observers note that this event occurs against a broader backdrop of escalating infrastructure and authorization-related attacks across the wider decentralized finance and payment sectors. Recent quarterly threat intelligence reports from specialized blockchain security firms indicate that compromised signing authorities and credential leaks now represent the vast majority of stolen funds globally. Payment products connecting blockchain collateral with traditional Visa and Mastercard rails increasingly find themselves in the crosshairs of sophisticated actors seeking to exploit gaps between on-chain contracts and off-chain administrative controls.

Comprehensive Assessment, Affected Entities, and Next Steps

In conclusion, independent reporting indicates that the Solana-based crypto card platform Avici has suffered an unauthorized collateral drainage attack resulting in reported losses exceeding one million dollars, while its native AVICI token plummeted to historic lows. This assessment is based on media reporting and has not been officially confirmed by the project team or first-party sources. The affected entity is Avici, and the primary user group impacted consists of platform account holders and card collateral depositors who experienced unexpected balance reductions. The reported incident highlights critical security gaps in authorization management and challenges the protocol's self-custody promises. What changes now is that users must exercise extreme caution, revoke associated smart contract permissions, and monitor official channels for verified updates. The next action for participants is to secure remaining funds in hardware wallets and refrain from depositing additional assets until comprehensive security audits and official post-mortems are published.

While on-chain transaction logs clearly demonstrate the procedural addition of administrators followed by collateral withdrawals, the exact vector—whether software flaw, credential compromise, or administrative key exposure—remains unconfirmed pending formal disclosures. Market participants must carefully separate verified blockchain data from speculative commentary while evaluating their risk exposure. Regulatory scrutiny and user distrust will likely persist as long as transparent answers are withheld by the project operators. Moving forward, stakeholders should prioritize risk mitigation strategies and maintain vigilance against similar authorization-based vulnerabilities across comparable payment platforms.

Cexvia conclusion

Assessment and Next Actions

An unauthorized withdrawal incident impacting Avici collateral accounts has resulted in reported losses exceeding $1 million across numerous user wallets. This assertion is not officially confirmed.

Risk meaning
The incident exposes severe vulnerabilities in authorization controls for card collateral platforms, challenging claims of absolute self-custody and user asset protection.
User action
Affected individuals should immediately monitor their wallet activity, revoke unnecessary protocol permissions, and avoid interacting with compromised smart contracts until further notice.
Avici