Avici exploit: attacker with $190 wallet exploited signature verification bug to drain ~$670K from 1,100+ collateral accounts via 8,900 transactions.
Security & Exploits ·
A wallet with an initial balance of $190 in USDC exploited a signature verification flaw in Avici to drain approximately $670,000 from over 1,100 user collateral accounts. The attacker created the wallet and began the exploit within hours, executing nearly 8,900 transactions that siphoned funds from individual accounts rather than a shared treasury or upgrade mechanism.
The vulnerability lay in how Avici processed signature verification. The attacker submitted a signature bundle, then called AddCollateralAdmin to grant themselves admin privileges on target accounts. A second signature check within the process pointed backward to an earlier instruction, causing the Solana program to verify the attacker's own signature a second time instead of validating a legitimate admin key. This flaw allowed the unauthorized admin elevation across thousands of accounts.
The extraction of funds occurred unevenly across accounts, with a median withdrawal of $24 and the largest observed amount in a single account at $5,268. Approximately $576,000 exited the attacker's wallet between 18:19 and 18:34 UTC, though funding continued afterward. Whether the wallet received additional stolen proceeds or the full extent of the drain remains unconfirmed.