Solana Avici Faces $1M Crypto Drain as AVICI Hits Record Low

Solana Avici Faces $1M Crypto Drain as AVICI Hits Record Low

Key Insights

Avici is investigating a Solana-based security incident after reports linked more than $1 million. The withdrawals targeted user collateral accounts on August 28 and pushed AVICI to a record low.

Attack sequence exposes authorization questions

The suspected attacker funded a Solana wallet through deBridge at about 13:40 UTC. The wallet received 1.79 SOL before remaining inactive for roughly three hours.

At 16:49:48 UTC, the address began interacting with the platform’s programs. A pattern of transactions was observed on the impacted accounts.

The wallet initially attempted to use the SubmitSignatures in the authorization process. It then called AddCollateralAdmin on the collateral program. Finally, WithdrawCollateralAsset sent the collateral to an attacker’s address.

One transaction moved 2,346.77 USDT from a user account. The attacker also swapped stablecoins for SOL, including one transaction producing 209.76 SOL.

At one checkpoint, the wallet held 10,005.03 SOL worth about $1.07 million. It also held roughly $11,600 in USDC and USDT.

An on-chain tracker identified 125 sending accounts linked to the activity. Individual transfers reportedly ranged from about $9 to more than $26,000. Separate technical analysis estimated that more than 1,100 collateral accounts could have received unauthorized administrator changes.

However, the precise loss remains unsettled. Reports have cited figures from about $600,000 to above $1 million. The company has not independently confirmed either figure.

Avici response leaves critical questions open

Avici acknowledged an issue affecting card balance withdrawals about two hours after reported activity began. The company said it was monitoring events and working with partners.

It did not confirm an exploit, identify the attack method, disclose affected users, or announce compensation. It also did not state whether the activity had stopped.

Source: X

That restraint matters because transaction traces cannot establish the original security failure. They show how funds moved, but they cannot prove the initial access method.

Some technical reports point toward an authorization error. They allege that signature verification could accept the attacker’s signature twice. That behavior could allow administrator privileges before collateral withdrawals.

Other reports have attributed losses to phishing campaigns targeting users. The fraudulent sites reportedly lured connections with wallet through fake airdrops or offers on the platforms. Those claims conflict with the observed program-level withdrawal sequence.

No independent post-mortem has resolved that dispute. Therefore, the root cause remains unconfirmed pending technical evidence.

Self-custody model faces a sharper test

Avici is a self-custodial neo bank that offers a secured visa card. The customers put up their crypto assets as security and then can borrow money from them.

That architecture has put authorization at the product’s heart.That architecture puts authorization at the product’s centre. Adding administrative rights to an unauthorized party is a major problem with collateral control.

The card infrastructure also includes Rain, which offers stablecoin payment infrastructure. Solana is the direction of transaction points toward the platform. There is no report has brought up a compromise at Rain or Visa.

The incident is also not related to a Solana network failure. There is no evidence that Solana’s underlying blockchain has any vulnerability.

Token collapse raises business pressure

The attack reports quickly translated into market pressure. AVICI dropped 49.4% within 24 hours and reached $0.2175, according to figures cited from CoinGecko.

The token remained roughly 97% below its November 2025 record high of $7.56. Trading volume reached about $656,543 during the reported 24-hour period.

The selloff creates another risk. A damaged token can weaken confidence even after developers contain the underlying incident.

The company raised $3.5 million through a capped MetaDAO token sale in October 2025. The offering priced AVICI at $0.35 and issued 10 million tokens.

Meanwhile, broader security data shows the operational risk facing crypto platforms. A July Hacken report attributed 88.3% of roughly $764 million stolen during the second quarter to compromised keys, signers, and infrastructure.

That pattern reinforces the need for controls beyond smart contract audits.

Conclusion

The company now faces two parallel tasks. It must determine how withdrawals occurred while restoring confidence among users and token holders.

Current evidence supports unauthorized collateral withdrawals, but it does not settle the root cause. Until investigators establish that cause, exploit and phishing claims remain competing explanations.

For Avici, the central test extends beyond the reported loss. The incident will show whether its self-custody architecture can withstand authorization failures and security attacks.

Brenda Mary

Brenda Mary is a cryptocurrency journalist, SEO analyst, and editor with over 3 years of experience in blockchain, digital assets, and crypto market analysis. She has contributed to leading platforms including Crypto.news, Cryptopolitan, The Coin Republic, and Analytics Insight.
At CoinRaftar, she covers crypto news, market trends, and Web3 developments, simplifying complex topics into clear, reader-friendly insights.
Bachelor’s in International Business Management, University of Nairobi.
https://www.linkedin.com/in/brenda-mary-248b2422b/

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top