Avici's card-issuing partner Rain traced the theft to an outdated version of its Solana contract. The attacker registered himself as an administrator on 1,685 collateral accounts; every one of them will be refunded in full.
An attacker made himself an administrator on 1,685 Avici card accounts on 28 August and withdrew $500,859.22 of customer collateral.
Avici sells a Visa card backed by crypto its customers never hand over. You deposit into a collateral account, receive a credit limit against it, spend, and the collateral settles the bill afterwards. The company's App Store listing tells users they stay in control and that Avici never holds their funds. That promise held for the self-custodial wallet and failed completely for the card programs sitting next to it, a distinction most customers had no reason to know existed.
The withdrawals ran on three instructions. First SubmitSignatures, on Avici's authorisation program, in a transaction that also invoked Solana's Ed25519 signature verification program. Then AddCollateralAdmin, on the collateral program, registering a second administrator against somebody else's account. Then WithdrawCollateralAsset, which did what its name promises. One transaction reviewed by The Defiant moved 2,346.77 USDT out of a single user's balance. The wallet signed 14,672 transactions before analysts stopped counting; 2,344 of them failed.
The operation was quick. The wallet was funded through deBridge at 13:40 UTC with 1.79 SOL, sat idle for about three hours, then made its first call into Avici's programs at 16:49:48. The on-chain analyst STACC, who built a live tracker while withdrawals were still going out, counted 125 sending accounts, with individual transfers ranging from roughly 9 USDC to more than 26,000 USDT.
Rain, the card-issuing partner behind the Visa product, traced the flaw to an outdated version of its Solana card contract, one used by Avici and, in Avici's phrasing, a small number of other programs. Every deployment still running that version has since been upgraded. So this was not an exotic cryptographic break or some novel attack primitive. It was a stale signature and permission check left live at a company that issues payment cards, and a second company that built on top of it without checking which version it had. Ledger customers met a related failure this month, when the wallet maker's Ethereum app could display one transaction while signing another.
Avici's first public statement, posted an hour and 53 minutes after the initial transaction, acknowledged an issue affecting card balance withdrawals and said little else. The second, later the same day, was considerably more specific.
The size of the loss moved around for a day. Early estimates ran from $600,000 to well past $1 million, because the attacking wallet finished holding roughly 10,005 SOL, worth about $1.07 million at the time, plus some $11,600 in stablecoins. DefiLlama logs the incident at $500,859, matching Avici's own count of $500,859.22 across 1,685 users. Treating the wallet's whole balance as Avici's loss roughly doubles it, and several outlets did exactly that.
Both Avici programs were upgradeable and shared an upgrade authority, and that authority was a standard Solana account rather than a multisignature. Nothing so far ties it to the withdrawals. It is still a single key with the power to rewrite the programs holding customer collateral, sitting behind a product marketed on the idea that you do not have to trust anybody.
AVICI fell to a record low near $0.22, which cut the token's market capitalisation to about $2.84 million and left it more than 96% below the peak it set in November 2025. It has since recovered to around $0.31. The token was sold last October through a capped MetaDAO offering at $0.35, where 7,352 contributors pledged roughly $34.23 million; Avici returned about 89.8% of that under the cap and kept $3.5 million.
The following day the Ethereum lending protocol Ajna lost about $775,000 to what the monitoring firm Defimon Alerts described as liquidation accounting manipulation, $173,700 of it from the syrupUSDC pool alone. Defimon says it identified the prepared attack more than an hour before the first exploit transaction and warned the team in its Discord, and that Ajna failed to react. The protocol later told users to withdraw everything, repay loans and stop interacting with it. Its total value locked is now roughly $246,880, down 71.3% over thirty days. BounceBit shut its entire layer-1 down this month after an exploit it could not patch, and Term Finance lost $8.5 million to an attacker funded with two ETH out of Tornado Cash.
None of these were unaudited weekend projects. CoinGecko's security review counted more than 245 incidents between January 2025 and July 2026, worth $3.63 billion between them. Audited protocols accounted for 147 of those incidents and 88.44% of the money taken.