Attacker Drains More Than $1 Million from Avici Users in Live Attack on Solana Neobank

DN19 Newsroom
28 Aug 2026 16:21
Coins 0 6
4 minutes reading

An attacker is draining customer funds from Avici, a Solana neobank that issues Visa cards backed by users’ cryptocurrency. More than $1 million had been stolen by press time.

Avici markets its cards as self-custodial, with user balances held in onchain accounts authorized through passkeys rather than seed phrases. The attacker breached that authorization layer by calling an instruction that registers a new administrator on a user’s collateral account, then withdrawing the account’s balance.

According to Solana RPC data queried by The Defiant, the attacker’s wallet, FVNFzq[…]QnCEj, held 10,005.03 $SOL worth approximately $1.07 million at 18:58 UTC, along with roughly $11,600 in $USDC and $USDT. Its $SOL balance had increased by about 2,595 tokens, or approximately $277,000, during the preceding 11 minutes.

Avici said in a post at 18:42 UTC that it is “working directly with all relevant partners to resolve it and will share updates as soon as we have more information.” The company has not disclosed how the funds were taken, how many accounts were affected or whether users will be reimbursed.

Attacker Added as Administrator Before Withdrawing Funds

The wallet received 1.79 $SOL bridged through deBridge at 13:40 UTC and remained inactive for three hours. Its first call against Avici’s contracts was recorded at 16:49:48 UTC. Since then, it has signed 14,672 transactions, including 2,344 failed transactions.

Transaction logs show a repeated three-instruction pattern for each victim. The wallet first calls SubmitSignatures on Avici’s authorization program in a transaction that also invokes Solana’s Ed25519 signature-verification precompile. It then calls AddCollateralAdmin on Avici’s collateral program, followed by WithdrawCollateralAsset on the same program.

In one transaction reviewed by The Defiant, a single WithdrawCollateralAsset call transferred 2,346.77 $USDT from a user’s collateral account to the attacker’s token account. The wallet periodically converts the stolen stablecoins into $SOL; one swap added 209.76 $SOL.

Both Avici programs are upgradeable and use the same upgrade authority, which is a standard Solana account rather than a multisig.

Avici Acknowledged the Attack Nearly Two Hours After the First Drain

Avici acknowledged the incident one hour and 53 minutes after the first draining transaction. Users had already posted about missing balances before the company’s statement appeared.

“i just got drained of all my balance from my @avici acc,” one user wrote at 18:44 UTC. “waiting to hear from the project.”

A live tracker created by pseudonymous onchain analyst STACC counted 125 distinct sending accounts during its tracking window. Inbound transfers ranged from approximately 9 $USDC to more than 26,000 $USDT.

AVICI Token Price Falls Nearly 50%

AVICI traded at $0.2175, down 49.4% over 24 hours, with a market capitalization of $2.84 million and 24-hour trading volume of $656,543, according to CoinGecko. The token set a record low on Friday after reaching $7.56 on Nov. 26, 2025.

Most AVICI trading takes place on MetaDAO’s futarchy automated market maker, which accounts for approximately 58% of volume. The remaining activity is split among LBank, KCEX and MEXC.

Avici Refunded Nearly 90% of ICO Commitments

Avici raised funds through MetaDAO in October 2025 in one of the token launches that helped revive the initial coin offering model on Solana. The team capped the sale at $3.5 million despite $34,206,976 in commitments, refunding 89.8% of committed $USDC and setting an initial price of $0.35.

The offering assigned the project a fully diluted valuation of $4,515,000 across a 12.9 million-token supply. AVICI now trades at approximately 62% of its ICO price.

The company is registered as Avici Inc. in San Francisco. On Aug. 24, it said it would be among the first neobanks to offer Coinbase’s tokenized stocks on Base.

Wallet-level compromises have represented a growing share of cryptocurrency losses in 2026, including Trust Wallet’s $7 million browser extension hack and thefts involving Coldcard hardware wallets. Decentralized finance recorded approximately 70 exploits and $746 million in stolen funds during the second quarter, making it the most heavily exploited quarter on record.

No Comments

Leave a Reply

Your email address will not be published. Required fields are marked *