A security exploit in Avici's Solana card contracts resulted in losses exceeding $1 million. An attacker funded a wallet with approximately $190 in USDC to cover transaction fees and subsequently drained over $670,000 across 8,857 transactions.
According to on-chain data, the attacker's wallet was created and funded before remaining inactive for roughly three hours. Withdrawals began at 16:49 UTC, with the first major batch of approximately $576,000 moved between 18:19 and 18:34 UTC. Individual withdrawal amounts varied, with a median of $24 and a largest recorded withdrawal of $5,268.
Vulnerability in Third-Party Infrastructure
The vulnerability did not compromise Avici's main treasury or upgrade keys. Instead, it targeted individual card-balance contracts through an outdated signature and permission check in infrastructure provided by Rain, Avici's card-issuing partner.
The attacker submitted a specially crafted signature bundle called AddCollateralAdmin, which incorrectly granted them admin access to more than 1,100 user collateral accounts. This access allowed systematic withdrawal of funds from affected accounts.
Response and Restoration
Avici identified and fixed the contract issue, updating the affected Solana contract and reporting no further related activity. The team has restored all withdrawn balances in full and provided an additional 10% cashback on the amounts that were withdrawn.
The exploit was limited to Solana card contracts holding balances added through Avici's Top Up system. Regular Solana and EVM wallets, EVM card balances, onramps, offramps, and swaps were not affected. Avici continues monitoring the updated contracts while users are being asked to verify their restored balances.


