Founder
Bot
3 YEAR
3 YEAR OF SERVICE
An attack against Solana-based crypto card platform Avici is reportedly still draining user funds, with the suspected attacker's wallet holding just over 10,000 $SOL (~$1.07M) plus roughly $11,600 in stablecoins at the last checkpoint.
On-chain data shows a repeatable three-step pattern: the attacker's wallet calls SubmitSignatures on Avici's authorization program, then AddCollateralAdmin to register itself as an extra admin on a victim's collateral account, then WithdrawCollateralAsset to pull the funds out. The wallet was funded via deBridge earlier in the day, sat idle for a few hours, then started firing off transactions — reportedly over 14,000 signed, with about 2,300 failing. An independent tracker built by an on-chain analyst identified 125 affected sending accounts, with individual losses ranging from single-digit dollars up to over $26,000.
Avici has only acknowledged "an issue affecting card balance withdrawals," without confirming losses, exploit status, or customer count. No word yet on whether the attack has been stopped, whether contracts have been paused, or whether victims will be made whole. Notably, Avici's two relevant programs shared a single upgrade authority that was reportedly a standard wallet rather than a multisig — though there's no confirmation yet that this was the actual attack vector.
This is awkward for Avici's marketing, which bills the card as self-custodial with funds never held by the company. The ability for an outside wallet to add itself as an admin and pull collateral undercuts that pitch, pending an actual root-cause explanation.
$AVICI token fell about 49% in 24 hours to an all-time low near $0.2175.
Anyone here using Avici's card seeing balances disappear, or is this contained to specific accounts?
Want to start trading? Sign up on fomo.family and save 10% on trading fees!
On-chain data shows a repeatable three-step pattern: the attacker's wallet calls SubmitSignatures on Avici's authorization program, then AddCollateralAdmin to register itself as an extra admin on a victim's collateral account, then WithdrawCollateralAsset to pull the funds out. The wallet was funded via deBridge earlier in the day, sat idle for a few hours, then started firing off transactions — reportedly over 14,000 signed, with about 2,300 failing. An independent tracker built by an on-chain analyst identified 125 affected sending accounts, with individual losses ranging from single-digit dollars up to over $26,000.
Avici has only acknowledged "an issue affecting card balance withdrawals," without confirming losses, exploit status, or customer count. No word yet on whether the attack has been stopped, whether contracts have been paused, or whether victims will be made whole. Notably, Avici's two relevant programs shared a single upgrade authority that was reportedly a standard wallet rather than a multisig — though there's no confirmation yet that this was the actual attack vector.
This is awkward for Avici's marketing, which bills the card as self-custodial with funds never held by the company. The ability for an outside wallet to add itself as an admin and pull collateral undercuts that pitch, pending an actual root-cause explanation.
$AVICI token fell about 49% in 24 hours to an all-time low near $0.2175.
Anyone here using Avici's card seeing balances disappear, or is this contained to specific accounts?
Want to start trading? Sign up on fomo.family and save 10% on trading fees!