Solana-based crypto card platform Avici has lost over $1 million from its users’ collateral accounts. Estimated losses as of 18:58 UTC reached 10,005.03 SOL, or roughly $1.07 million, alongside $11,600 worth of assets in USDC and USDT. A total of 125 sender accounts were identified as victims, with losses ranging from $9 to over $26,000 per account.
Three Steps of Access Manipulation
The attacker did not break into the system through brute force, but rather manipulated legitimate authorization pathways. The attack unfolded in three recurring steps. First, the perpetrator called the SubmitSignatures instruction via Avici’s authorization program. Second, they executed AddCollateralAdmin to register an additional admin wallet to the victim’s profile. Once duplicate access was obtained, the third step was executed: WithdrawCollateralAsset, which transferred the entire collateral asset balance from the victim’s wallet directly into the hacker’s hands.
To facilitate the mass operation, the attacker’s wallet signed 14,672 consecutive transactions, though 2,344 of them ended in failure.
Three-Hour Delay and Company Response
The asset-draining campaign was prepared hours in advance. The attacker’s wallet received an initial funding of 1.79 SOL from another network via the deBridge service at 13:40 UTC. After securing the funds, the wallet address remained inactive for approximately three hours before the withdrawal execution began.
Avici only acknowledged the incident via an announcement on X around 1 hour and 53 minutes after the first transaction was detected. However, the company did not refer to the event as an exploit, nor did it confirm the total amount of stolen funds or the number of affected users.
What Remains Unknown
The exact cause of the incident remains unknown. It is not yet clear whether the entry point stemmed from a code vulnerability, leaked credentials, or another internal system failure. One thing is certain: the chain of events was purely related to Avici’s own collateral program, not a vulnerability in the Solana network.
Both manipulated Avici programs were designed to be upgradeable and shared a single upgrade authority - indicating their infrastructure did not use a multisig account.
Reported by crypto.news.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




