Avici Refunds Users After Solana Smart Contract Exploit
Avici, a Solana-based neobank, has confirmed that all 1,685 users affected by a recent smart contract exploit will receive full refunds for their losses. The breach on August 28 saw attackers drain user funds from around 1,100 collateral accounts, with the total loss estimated to be between $650,000 and $1 million.
The exploit targeted three smart contract operations: SubmitSignatures, AddCollateralAdmin, and WithdrawCollateralAsset. By chaining these operations together, attackers gained unauthorized admin rights and were able to drain user funds through a series of small withdrawals.
Avici's smart contracts used a single non-multisig upgrade authority, which made it vulnerable to attacks. The company acknowledged the issue shortly after the breach and confirmed that it was working with partners to contain the situation.
The full refund commitment is significant, considering Avici's market cap recently sat in the low single-digit millions. This suggests that the project either had reserves set aside or secured external support to cover the losses.