Analysts track ongoing exploit draining Avici user accounts as its token drops over 43%
On-chain researchers say an attacker gained admin rights over more than 1,100 collateral accounts on Avici, the Solana neobank, draining card balances through thousands of small transactions. The BANK token fell more than 43% to around $0.23.
An active exploit targeting Avici (@avici), a Solana-based neobank, is draining user card balances as on-chain researchers race to quantify the damage. One analyst put the running total at $670,000 and climbing, with the platform's native token falling more than 43% in the hours after the incident surfaced.
How the attack unfolded
According to on-chain researchers tracking the incident, an attacker obtained admin-level access to more than 1,100 collateral accounts on the platform. Rather than executing one large withdrawal, the attacker dispersed the activity across thousands of small transactions, a pattern commonly used to slow detection and complicate recovery efforts.
Avici operates as a fully on-chain neobank built on Solana. Its secured credit card model ties a user's spending limit directly to posted collateral, meaning the collateral accounts targeted in this exploit represent real user funds backing live card balances. The platform also offers virtual USD and EUR bank accounts and supports deposits from Solana, EVM-compatible networks, Bitcoin, and standard bank transfers.
Avici said it is aware of an issue affecting card balance withdrawals and is working with partners to resolve it. The project has not yet published a full post-mortem or confirmed the total amount lost.
Token falls sharply as confidence wavers
The solana:BANKJmvhT8tiJRsBSS1n2HryMBPvT5Ze4HU95DUAmeta token dropped more than 43% to around $0.23 in the wake of the news. The sell-off reflects the scale of concern among holders, given that Avici's model is built around the idea of self-custodial, user-owned banking infrastructure on Solana.
The incident arrives against a difficult backdrop for Solana-based projects. Earlier this year, Drift Protocol lost approximately $286 million in a sophisticated admin takeover attack that blockchain analytics firm Elliptic linked to techniques consistent with North Korean state-affiliated hacking groups. While the Avici exploit appears smaller in scale, the method of targeting admin-level access over collateral accounts raises similar questions about governance and account security across Solana-native platforms.
This story is developing. Further details on the exploit vector and total losses are expected as on-chain analysts and the Avici team continue their investigation.
Sources:
Elliptic: Drift Protocol exploited for $286 million in suspected DPRK-linked attack
CoinMarketCap: What Is Avici (AVICI) And How Does It Work?
CryptoCards: Avici product overview
Latest News
Read More...
Author
Crypto RichRich has been researching cryptocurrency and blockchain technology for eight years and has served as a senior analyst at BSCN since its founding in 2020. He focuses on fundamental analysis of early-stage crypto projects and tokens and has published in-depth research reports on over 200 emerging protocols. Rich also writes about broader technology and scientific trends and maintains active involvement in the crypto community through X/Twitter Spaces, and leading industry events.













