An attacker has drained more than $1 million from card collateral vaults at Avici, a Solana-based neobank, with the total climbing well past the $653,548 first confirmed when BeInCrypto’s Lockridge Okoth reported the breach on Aug. 28.
The AVICI token has fallen roughly 49% to an all-time low near $0.2175, as the company continues investigating an issue affecting card balance withdrawals.
Avici exploit targets customer collateral vaults
The Avici exploit centered on the collateral system supporting the company’s Visa credit card product. Avici allows users to lock USDC stablecoins into smart contracts, with the collateral serving as backing for card spending.
According to the information provided, Third National issues the card, while Avici operates the underlying system connected to customer collateral.
Avici’s documentation had outlined a self-custody model in which users were expected to retain control over withdrawals from their escrow contracts.
“Only user’s wallet can withdraw funds from escrow contract after deducting the spends,” — Avici documentation.
However, the Avici exploit demonstrated that the system contained additional pathways capable of affecting the funds held in those contracts.
A live tracker cited in the original report showed that $653,548 had been withdrawn as the incident unfolded. The attacker reportedly drained funds from individual customer escrow accounts rather than accessing a single central treasury.
The distinction is significant because each customer reportedly maintained a separate escrow contract. Instead of one large pool being emptied, the attack affected accounts individually, suggesting that the vulnerability could be replicated across multiple customer vaults.
How the Avici exploit may have unfolded
On-chain researchers investigating the Avici exploit said the attacker may have used a crafted signature bundle to gain administrative control over escrow accounts before withdrawing the funds.
According to those researchers, the attacker allegedly manipulated privileged permissions within the program, enabling access to customer collateral that was supposed to remain under user control.
However, Avici had not confirmed that method at the time of the report.
The incident highlights a critical distinction in blockchain-based financial systems: self-custody protections can define who is expected to control funds, but vulnerabilities in smart contract code or privileged administrative functions may still create alternative routes for unauthorized access.
The scale of the attack also appeared to remain under scrutiny as researchers monitored the situation. One on-chain observer, identified as inno, warned that the drain was still active and suggested the losses and number of affected users could be higher than the initial figures.
“Drain started 2 hours ago (5PM UTC) and is still ACTIVE!!” — inno (@inno_sol), on X.
The same post claimed that more than $1 million had been exploited and that over 9,000 users had been affected. Those figures, however, differed from the $653,548 recorded by the live tracker cited in the original report, underscoring that the full scale of the incident was still developing.
AVICI token falls sharply after security breach
The market reaction to theAvici exploit was immediate.
AVICI fell by approximately 40%, dropping to around $0.24 as investors reacted to the security breach and uncertainty surrounding customer funds. The decline erased roughly one-fifth of the token’s market value, according to the original report.
Crypto markets have historically reacted sharply to major security incidents, particularly when attacks raise questions about the safety of user assets or the integrity of a project’s underlying infrastructure.
In this case, the impact extended beyond a single treasury or corporate wallet. Because the Avici exploit reportedly affected individual customer escrow contracts, the incident created broader concerns about the security of the platform’s card collateral system.
The attack was therefore fundamentally different from a conventional treasury breach, where a hacker gains access to one large pool of funds. Instead, the reported structure of the incident suggested that multiple separate accounts could potentially be affected through the same vulnerability.
That uncertainty contributed to pressure on the AVICI token as market participants awaited further clarification from the company.
Avici says it is monitoring the withdrawal issue
Avici acknowledged that it was aware of problems involving card balance withdrawals but did not provide a detailed explanation of the cause or confirm the attack method described by on-chain researchers.
In a public update, the company said it was working with relevant partners to address the situation.
“We’re aware of an issue affecting card balance withdrawals and are closely monitoring the situation. We’re working directly with all relevant partners to resolve it and will share updates as soon as we have more information.” — Avici, in a statement on X.
At the time of the report, the company had not released a full post-mortem explaining the Avici exploit or disclosed whether the remaining vaults were still vulnerable.
It also remained unclear whether the incident could affect card settlement involving Third National, the institution identified as issuing Avici’s Visa credit card.
The Avici exploit has therefore left several important questions unanswered: how the attacker gained access, whether all affected vulnerabilities have been contained, how many users ultimately lost funds, and whether remaining customer collateral is secure.
For now, the incident serves as another reminder that blockchain-based financial products can combine the benefits of self-custody with risks embedded in the smart contracts and privileged systems supporting those services. As Avici continues working with its partners, users and investors will be watching closely for a detailed explanation of how the breach occurred and what measures will be taken to prevent another Avici exploit.