started · updated
Avici neobank suffers smart contract exploit on Solana
Avici, a Solana-based neobanking platform, has suffered a significant smart contract exploit resulting in losses estimated between $600,000 and $1.02 million. The vulnerability allowed an attacker to bypass authorization protocols by calling the ‘AddCollateralAdmin’ function, effectively granting themselves administrative rights over user collateral accounts to facilitate unauthorized withdrawals.
On-chain analysis indicates the attacker converted stolen SOL into USDC and subsequently into Ethereum, moving funds through various networks and ultimately toward Tornado Cash to obscure the trail. Following the incident, the native AVICI token experienced a sharp decline, dropping between 39% and 49% in value.
Avici confirmed an issue affecting card balance withdrawals and stated that the affected contract has since been upgraded. The company reported that 1,685 users were directly impacted, representing approximately $500,859 in card balances. Avici has committed to refunding all affected users in full and has filed a report with the FBI’s Internet Crime Complaint Center.