Avici exploit: $190 initial funding yielded $670K in stolen assets through signature check vulnerability and coordinated multi-account drains.
Security & Exploits ·
An attacker exploited a signature verification flaw in Avici to drain user collateral accounts across the platform. The assault began with minimal capital—$190 in USDC bridged to Solana for gas fees—and escalated through 8,857 transactions to extract approximately $670,000 in stolen assets. According to the incident analysis, the wallet was created at 13:40 UTC and draining commenced roughly three hours later.
The exploit centered on a signature check vulnerability that allowed the attacker to gain unauthorized admin privileges. By submitting a signature bundle, calling AddCollateralAdmin, and then withdrawing, the attacker repeated this pattern across accounts. A critical flaw in the second signature verification caused the Solana program to validate the attacker's own signature against instruction 0, incorrectly granting admin status to a key that should never have been accepted. This gave the attacker administrative control over 1,100 or more collateral accounts.
The funds extracted came from individual user deposits rather than a centralized treasury or compromised upgrade key. Median individual account losses stood at $24, though the largest single account drained held $5,268. The bulk of stolen funds—roughly $576,000—left the attacker's wallet between 18:19 and 18:34 UTC, though additional inflows continued afterward. The precise attack window, transaction count, and user account scope remain under investigation.