Avici Withdrawals Drain Up to $1.07 Million From Solana Card Collateral
On‑chain records show attacker-controlled transactions added administrators then moved user collateral, raising urgent questions about Avici’s authorization and signing controls.
Overview
- On Friday, Aug. 28, on-chain observers traced a repeated three-step sequence — SubmitSignatures, AddCollateralAdmin, then WithdrawCollateralAsset — that moved card collateral into attacker-controlled addresses.
- Estimates of funds taken differ by tracker and snapshot, ranging from about $604,800 in stablecoins to a checkpoint showing 10,005 SOL (roughly $1.07 million) plus small amounts of USDC and USDT.
- Avici posted on X that it was aware of a card-balance withdrawal issue and was working with partners, but it did not call the event a hack or provide a loss tally or affected-customer count.
- Available logs do not show how authorization was obtained and no company post-mortem or independent audit has been published, while reports note both Avici programs were upgradeable and shared a single non‑multisig upgrade authority.
- The withdrawals have wiped value from the AVICI token and left users reporting drained card balances, and the incident echoes a wider pattern where compromised keys and operational controls drive many crypto payment losses.