Avici, a Solana-based neobank issuing crypto-backed Visa cards, suffered an exploit resulting in the theft of over $1 million from user collateral accounts. The platform acknowledged the breach nearly two hours after the first funds were drained.
The attacker's wallet currently holds 10,005.03 SOL, valued at approximately $1.07 million, alongside $11,600 distributed across USDC and USDT, according to on-chain data.
The attack sequence began with an invocation of Avici's authorization program's `SubmitSignatures` function, which bypassed the platform's security protocols for transaction approval. The attackers then called the collateral program's `AddCollateralAdmin` function, granting themselves administrative control over user collateral and enabling withdrawal of funds via `WithdrawCollateralAsset`.
The vulnerability stems from Avici's program architecture: both the authorization and collateral programs are upgradable but share a single standard Solana account for upgrade permissions, lacking any multi-signature requirement. This setup allowed a single account to authorize critical changes across both programs.
On-chain analyst STACC developed a tracker identifying 125 distinct sender accounts from which funds were illicitly transferred. Individual thefts ranged from approximately $9 in USDC to over $26,000 in USDT, indicating broad impact across account sizes.
The AVICI token fell 49.4 percent within 24 hours to $0.2175, marking a record low and reducing market capitalization to approximately $2.84 million.
Avici raised $34.2 million in commitments through a MetaDAO offering in October 2025, though the team later refunded 89.8 percent of committed USDC. The platform markets its crypto card product as self-custodial, with user balances held in on-chain accounts authorized through passkeys rather than seed phrases.

