An attacker siphoned more than $1 million from customer accounts on Avici, a Solana-based neobank that offers Visa cards backed by users’ crypto, according to onchain data reviewed by The Defiant. The incident was still unfolding at publication time, with the attacker’s wallet holding 10,005.03 SOL, worth about $1.07 million at 18:58 UTC, as well as roughly $11,600 in USDC and USDT.
Avici markets its product as self-custodial, with customer balances held in onchain accounts that users authorize through passkeys rather than seed phrases. Based on the transaction pattern described in the report, the attacker appears to have bypassed that authorization flow, added a new administrator to users’ collateral accounts, and then withdrawn funds.
How the drain unfolded
The wallet identified in the report was initially funded with 1.79 SOL bridged through deBridge at 13:40 UTC and then remained inactive for about three hours. Its first transaction against Avici’s contracts arrived at 16:49:48 UTC. From there, activity accelerated quickly: by 18:58 UTC, the wallet had signed 14,672 transactions, including 2,344 failed attempts.
The attacker’s SOL balance increased by around 2,595 SOL, or roughly $277,000, in the 11 minutes before 18:58 UTC alone. The wallet also periodically converted stolen stablecoins into SOL. In one cited trade, a swap added 209.76 SOL to the wallet’s holdings.
Transaction pattern points to admin registration abuse
According to transaction logs cited by The Defiant, the same sequence was repeated across victims in three steps. First, the attacker called SubmitSignatures on Avici’s authorization program in a transaction that also invoked Solana’s Ed25519 signature-verification precompile. Next came AddCollateralAdmin on Avici’s collateral program, followed by WithdrawCollateralAsset from that same program.
In one reviewed example, a single WithdrawCollateralAsset instruction moved 2,346.77 USDT from a user’s collateral account into the attacker’s token account. The report said both Avici programs are upgradeable and share the same upgrade authority, which is a standard Solana account rather than a multisig.
Avici acknowledged the incident nearly two hours later
Avici said in a post at 18:42 UTC that it was “working directly with all relevant partners to resolve it” and would provide updates when more information becomes available. That statement came one hour and 53 minutes after the first drain transaction, while users had already begun reporting missing balances publicly.
The company has not disclosed how the funds were taken, how many accounts were affected, or whether customers will be reimbursed. A live tracker created by pseudonymous onchain analyst STACC counted 125 distinct sending accounts within its monitored window, with inbound transfers ranging from about 9 USDC to more than 26,000 USDT.
Token price falls as broader questions remain
Amid the exploit, AVICI traded at $0.2175, down 49.4% over 24 hours, giving the token a market capitalization of $2.84 million on $656,543 in daily volume. The token reached a record low on Friday, far below its peak of $7.56 on Nov. 26, 2025. Trading is concentrated on MetaDAO’s futarchy automated market maker, which accounts for about 58% of volume, with the remainder spread across LBank, KCEX, and MEXC.
Avici raised funds through MetaDAO in October 2025, capping the sale at $3.5 million after attracting more than $34.2 million in commitments and refunding 89.8% of committed USDC. It set an initial token price of $0.35 on a fully diluted valuation of $4.515 million across a 12.9 million token supply. On Aug. 24, the company said it would be among the first neobanks to offer Coinbase’s tokenized stocks on Base.
What is confirmed next
For now, the confirmed next step is Avici’s stated effort to work with relevant partners and issue further updates. The key unanswered questions are how the authorization layer was bypassed, the full number of affected accounts, and whether users will be made whole.
The incident also lands during a period of rising wallet-level compromises across crypto. The Defiant noted that DeFi saw about 70 exploits and $746 million stolen in the second quarter of 2026, the highest-loss quarter on record.
Source: thedefiant.io