Avici, an innovative banking platform within the Solana ecosystem, recently encountered a significant security breach. Analysis of on-chain data reveals that a hacker, starting with just $190, managed to siphon off approximately $670,000 worth of assets from users’ accounts. As a consequence, the price of the AVICI token plummeted over 45%.
Preliminary reports from SolanaFloor indicate that more than $600,000 was withdrawn from Avici users without authorization. Previously, Avici had communicated an anomaly regarding the unauthorized withdrawal of bank card balances and stated that it was collaborating with partners to investigate the issue. Ultimately, the platform confirmed that this incident was due to a security vulnerability.
On-chain analysis pointed out that the attack was executed with minimal upfront investment. The wallet employed for the intrusion was created on the same day at 5:40 PM, funded with about $190 in USDC transferred from Ethereum to Solana, primarily intended to cover transaction costs.
The attack reportedly launched around 16:49 UTC and involved thousands of transactions. Investigations uncovered that the attacking wallet was responsible for over 8,857 transactions.
Admin Control Over 1,100 Accounts Acquired by Attacker
Technical assessments revealed that the attack exploited an authorization vulnerability within Avici’s smart contracts. The attacker was able to invoke the AddCollateralAdmin function by sending a specific signature packet, wrongfully identifying themselves as an administrator of users’ collateral accounts.
Due to a misrouted second signature verification, the Solana network incorrectly accepted the attacker’s own signature as legitimate a second time. This erroneous validation permitted the program to accept an admin key that should not have been authorized.
This vulnerability led to the attacker gaining control over more than 1,100 collateral accounts, enabling them to withdraw funds from these accounts.
Analysis showed that the average amount stolen per examined account was roughly $24, while the highest single loss recorded was $5,268.
During the timeframe of 6:19 PM to 6:34 PM, an initial transfer of about $576,000 was made from the attacker’s wallet to other addresses, after which additional funds continued to flow into the attacker’s accounts. The total estimated loss subsequently reached around $670,000.
Initial assessments suggest that the breach did not result from compromise of Avici’s program upgrade key. It was confirmed that the program was neither altered nor updated, and the upgrade key had been unused since March 2025.
Thus, it appears that the incident resulted directly from an authorization flaw in the smart contract, not from a stolen deploy or upgrade key.
Conversely, there have been claims circulating on social media suggesting that the attack emptied Avici’s central treasury; however, on-chain data refutes this assertion. Current evidence indicates that funds were deducted from individual user accounts rather than a central treasury account.
Following the security breach, the selling pressure on the AVICI token intensified, resulting in a rapid decline of over 45% in its value.
*This should not be considered as financial advice.
