Avici platform suffered a security attack and lost approximately US$670,000
Avici, a next-generation banking platform running in the Solana ecosystem, suffered a serious security incident. On-chain data showed that the attacker stole approximately $670,000 worth of assets from user accounts with only $190 in initial funds. After the incident, the AVICI token price fell by more than 45%.
According to SolanaFloor's preliminary report, more than $600,000 in funds were withdrawn from Avici users 'accounts without authorization. Avici previously stated that it detected an abnormality in the withdrawal of bank card balance on the platform and is investigating the matter with its partners. The platform later confirmed that the incident originated from a security breach.
On-chain analysis shows that the attack cost is relatively low. The wallet used in the attack was created at 5:40 p.m. today and was cross-linked from the Ethereum network to Solana, injecting USDC worth approximately $190. The funds are believed to be used mainly to cover transaction fees.
The attack reportedly began at approximately 16:49 UTC and lasted for thousands of transactions. Surveys showed that the attackers 'wallets processed more than 8,857 transactions.
The attacker controlled more than 1,100 accounts
According to technical analysis, the attack originated from an authorization flaw in the Avici smart contract. According to reports, the attacker called the AddCollateralAdmin function by sending a specific signature packet, thereby identifying himself as an administrator in the user's mortgage account.
Because the second signature verification was incorrectly routed to the first instruction, the Solana network again regarded the attacker's own signature as valid. This causes the program to add an administrator key to the system that should not normally be accepted.
Allegedly, using this vulnerability, the attacker gained management rights to more than 1,100 mortgage accounts and began withdrawing funds from those accounts.
Research showed that among the transactions examined, the median amount stolen per account was approximately US$24, while the maximum single loss in the sample was US$5,268.
Between 6:19 and 6:34 p.m., the first batch of large amounts of approximately US$576,000 was transferred from the attacker's wallet to other addresses, and new funds continued to flow into the attacker's address. It is estimated that the total damage subsequently reached approximately $670,000.
Preliminary investigation revealed that the attack did not stem from the disclosure of the Avici program upgrade key. It is reported that the program has not been modified or updated to a new version, and the upgrade key has not been used since March 2025.
Therefore, it is believed that the incident originated directly from an authorization error in the smart contract, rather than the theft of the deployment key or upgrade key.
On the other hand, claims emerged on social media that the attack cleared Avici's central funds. However, on-chain data does not support this statement. According to existing survey results, funds are withdrawn from individual user accounts rather than from a single fund bank account.
After the security incident, selling pressure on AVICI tokens intensified, and its price quickly fell by more than 45%.

This chart shows the decline in AVICI prices.
* This article does not constitute investment advice.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following