An ongoing attack against Solana-based crypto card platform Avici has drained more than 1 million USD from user collateral accounts, sending the project’s AVICI token to a record low and reigniting questions about how securely “self-custody” products actually hold customer funds.
The incident, first detected on the evening of August 28, is still being tracked by on-chain analysts. At one checkpoint, the suspected attacker’s wallet held 10,005 SOL, worth roughly 1.07 million USD at the time, along with about 11,600 USD in USDC and USDT stablecoins. The AVICI token collapsed 49.4 percent within 24 hours, touching an all-time low near 0.22 USD, according to market data cited by crypto.news.
## How the attack unfolded
On-chain records reviewed by The Defiant paint a picture of a methodical, repetitive drain rather than a single dramatic transfer. The attacker’s wallet received its initial funding of 1.79 SOL through the deBridge cross-chain protocol at 13:40 UTC. After lying dormant for roughly three hours, the address sprang into action at 16:49 UTC, interacting with Avici’s on-chain programs for the first time.
The transaction logs showed the same three-step sequence repeated across affected accounts. First, the wallet called SubmitSignatures through Avici’s authorization program, using Solana’s built-in Ed25519 signature verification program in the same transaction. Next, the attacker invoked AddCollateralAdmin on Avici’s collateral program, registering an additional administrator on the victim’s account. Finally, a WithdrawCollateralAsset call moved the collateral to an account controlled by the attacker.
In one reviewed transaction, the withdrawal instruction swept 2,346.77 USDT out of a single user’s collateral account. The attacker also converted a portion of the collected stablecoins into SOL, with one swap returning 209.76 SOL. By the checkpoint, the wallet had signed a staggering 14,672 transactions, of which 2,344 had failed. During one 11-minute stretch, the attacker’s SOL balance grew by roughly 2,595 tokens, worth approximately 277,000 USD at the time.
Anonymous on-chain analyst STACC built a live tracker for the affected transfers. Figures cited from the tracker identified 125 sending accounts, with individual transfers ranging from around 9 USDC to more than 26,000 USDT.
## Avici confirms “card balance withdrawal issue”
Avici acknowledged the incident in a post on X published nearly two hours after the first reported transaction involving its programs. “We’re aware of an issue affecting card balance withdrawals and are closely monitoring the situation,” the company wrote, adding that it was working directly with relevant partners and would share updates as more information became available.
Notably, Avici did not call the incident an exploit, confirm the scale of the losses, or state how many customers were affected. Several questions remain unanswered: whether the activity has stopped, whether Avici has paused its programs, and whether affected users will be compensated. Users had already reported missing balances on social media before the company’s statement, with one user saying their entire Avici balance had been drained while they waited for information.
No post-mortem has yet been published by Avici or an independent security firm identifying exactly how the attacker obtained authorization. The transaction sequence shows how funds moved, but it does not establish whether the incident stemmed from a program flaw, compromised credentials, an exposed signing authority, or some other failure.
## Not a Solana problem
It is worth emphasizing what this incident is not: an attack on Solana itself. The exploit concerns Avici’s card collateral and authorization programs, not the underlying blockchain. No available report has identified a vulnerability in Solana’s network.
Still, the details around those programs raise eyebrows. Both Avici programs involved were upgradeable and, according to reports, shared the same upgrade authority, which was reportedly a standard Solana account rather than a multisignature account. There is no evidence yet that the upgrade authority caused or enabled the withdrawals, but the setup has drawn scrutiny at a time when operational controls are under increased attention across the industry.
The scale of that broader problem is hard to overstate. Security findings reported by crypto.news in July, based on a Hacken analysis, showed that compromised keys, signers and infrastructure accounted for 88.3 percent of roughly 764 million USD stolen during the second quarter of 2026. Only 4 percent of tracked projects combined audits, active bug bounties, and third-party monitoring.
## The self-custody question
The most uncomfortable aspect of the incident may be its collision with Avici’s own marketing. Avici describes its product as a self-custodial wallet connected to a secured Visa credit card, and its App Store listing states that users remain in control and that Avici never holds their funds. Under the card model, customers deposit crypto into collateral accounts and receive a corresponding credit limit, with purchases reducing the available balance and the collateral later used for settlement.
The reported ability of an attacker to add an administrator to a user’s account and then withdraw unspent collateral directly challenges those claims. Until Avici or an independent security firm explains why the attacker’s signature submissions were accepted, the gap between “self-custody” as advertised and self-custody as implemented will remain the central question hanging over the platform.
Avici’s documentation identifies Rain as a partner involved in its card service; Rain supplies stablecoin payment infrastructure and works with licensed institutions to issue cards connected to Visa and Mastercard. Available transaction analysis points to Avici’s own Solana programs as the point of failure.
For Solana’s booming consumer crypto ecosystem, the episode is a reminder that the weakest link is rarely the chain itself. It is the permissioning wrapped around it, and for the 125-plus accounts caught in this drain, that distinction is proving expensive.
Disclaimer: This article is for informational purposes only and does not constitute financial advice.
14,672 transactions and the team needed almost two hours to post about an issue. the attacker drained accounts one by one while nobody was watching the programs.
AVICI at 0.22 after a 49 percent dump lol. card users lost collateral and token holders ate half the market cap. self custody in name only.
0.22 is basically zero already. averaging into an active drain is not a strategy
2 hours to even post about it while 14k txs drained. a circuit breaker on the collateral admin would have capped this at pennies
a pause key on the collateral program would have stopped this at wallet one. card protocols shipping without one in 2026 is just negligence at this point
14,672 transactions and the response was a tweet two hours later. you run a card program holding real collateral and put zero monitors on your own programs
funded with 1.79 SOL through deBridge then sat dormant for 3 hours before touching the programs. person knew exactly what they were doing and picked their window.
The fact that AddCollateralAdmin could register a new admin on someone else account is the real story here. That is an authorization design failure, not a hack in the classic sense.
SubmitSignatures into an admin register on other peoples accounts is a day one audit fail. whoever wrote that authorization flow should be named
an admin role that can self register on someone else account is a design decision. audits check code paths, they rarely question architecture
audits grade the homework, they dont question the seating plan. an admin role that self registers should have died in design review, not in a postmortem
they marketed it as self-custody while running collateral accounts for a crypto card. thats just a bank with extra steps and zero insurance
^ exactly. and 10,005 SOL parked in one wallet the whole time. on-chain analysts literally watched it drain in real time
watched the wallet climb past 10k SOL on the tracker while the token bled 49 percent. everyone could see it, nobody could stop it. thats the part that stings
The 49 percent bleed with the tracker live is what gets me. Everyone watched it happen in real time and support was still copy pasting be patient.
the copy paste be patient messages while the tracker showed 10k SOL climbing is going to end up in the lawsuit filings. screenshotted everything
1.79 SOL funded through deBridge and everyone still pretends mixers are the problem lol
AVICI down 49.4 percent to an all time low near $0.22 and the attack was still ongoing when this went up. anyone who bought that dip mid-drain is gambling, not trading
an actual not-your-keys moment, card edition. shocking how many people read self-custody in the marketing copy and assumed cold wallets
1.79 SOL of gas money to drain seven figures of collateral. cheapest heist of the year and the self custody branding did all the work
and the fix will be some audit pdf nobody reads. the card app had custody the whole time, the phrase self custody was doing zero work
deleted the app the second i read the fine print on their recovery flow. card spend pulling from a custodial pot aint self custody, thats just a bank with extra steps
1.79 SOL in, dormant 3 hours, then a metronome of the same 3 calls on every account. that patience is the scariest part, this was rehearsed somewhere first
rehearsed is the word. three hours dormant reading the program logic probably, you dont script that repetition on a first try
10k SOL sitting in one wallet and the team tweeting be patient. every minute the tracker ticked up was money gone, the response was slower than the drain