Avici Attacker Drains $670K Using $190 in Gas
An Avici security exploit has exposed over $1 million in user funds after an attacker spent just $190 on gas before draining more than $670,000.
The attack began when a wallet was created at 13:40 UTC yesterday and funded with $190 USDC bridged from Ethereum to cover transaction fees. The attacker then interacted with Avici's Solana card contracts at 16:49 UTC, starting the drain of individual user balances.
The first major batch of about $576,000 was moved between 18:19 and 18:34 UTC, followed by further withdrawals that pushed the total amount drained above $670,000 in over 8,857 transactions. The attack continued until Avici's team identified and fixed the contract issue.
The exploit targeted individual card-balance contracts due to an outdated signature and permission check in infrastructure provided by Rain, Avici's card-issuing partner. The attacker submitted a specially created signature bundle, called AddCollateralAdmin, which gave them admin access to more than 1,100 user collateral accounts.
Affected users have been refunded in full with an additional 10% cashback on the amount withdrawn. Avici confirmed that the exploit was limited to Solana card contracts holding balances added through its Top Up system and did not affect regular Solana or EVM wallets, as well as other related accounts.