Avici exploit attacker used $190 in bridged USDC to siphon about $670K, with 8,857 transactions since 16:49 UTC

AI Market Summary
Avici confirmed an ongoing authorization-bypass exploit where an attacker used a signature-bundle flaw to grant themselves admin rights via AddCollateralAdmin and withdraw from over 1,100 user collateral accounts. Roughly $670K has been siphoned across 8,857 transactions, with funds coming from individual users rather than a treasury. The incident highlights smart-contract security and composability risks on Solana and may pressure risk appetite for Solana DeFi exposures.
Impact level
● Medium
Affected assets
SOL/USDT-4.65%
AI Insight · SOL/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Avici confirmed it was hit by an authorization-bypass exploit, with the attacker stealing about $670K. On-chain data show the attacker created a wallet at 13:40 UTC and bridged in $190 of USDC from Ethereum to cover gas. Draining began at 16:49 UTC and has continued, with 8,857 transactions executed by submitting a signature bundle, calling AddCollateralAdmin to gain admin privileges, and then withdrawing. The data indicate a verification flaw in which the second signature check pointed back to instruction 0, and the protocol’s upgrade key has not been used since March 2025.