Solana The ecological card project Avici recently encountered an exploit of a contract vulnerability. On-chain data shows that the attacker first transferred approximately $190 to a new wallet USDC to cover transaction fees, and then carried out operations on the Solana card contract of Avici, transferring a total of over $670,000. As more accounts were compromised, the platform's related losses temporarily exceeded $1 million.
The attack involved nearly 9,000 transactions.
After completing the initial capital injection, the attacking wallet remained silent for about 3 hours, and then at 16:49 UTC, it began to interact with the Solana contract of Avici. The first large-scale transfer of funds occurred between 18:19 and 18:34 UTC, amounting to approximately 576,000 US dollars.
Thereafter, the attack continued to expand, with a total of 8,857 transactions occurring. On-chain data also shows that the attackers withdrew balances from each account individually, rather than transferring all the funds at once.
The vulnerability targets the card balance contract.
According to Avici, this incident did not affect the main vault, nor was it related to the theft of upgrade keys. The problem stemmed from the permission verification of a single user's card balance contract.
The report mentioned that the vulnerability is related to the infrastructure provided by Rain, a partner of Avici in card issuance, which involves an outdated set of signature and permission checking logic. Attackers constructed a signature package named AddCollateralAdmin and mistakenly obtained administrative privileges for over 1,100 user-backed accounts, subsequently withdrawing funds from each one.
In the disclosed samples, the median amount extracted per transaction was approximately $24, with the largest transaction amounting to $5,268.
The team stated that the issue has been fixed and a refund has been provided additionally.
Avici indicates that all affected balances have been fully restored, and an additional 10% rebate is provided on top of the amount transferred out. The team stated that this vulnerability only affected the Solana card contract balances that were topped up through the Top Up system.
Avici also indicates that the balances in regular Solana wallets, EVM wallets, and EVM cards, as well as the functions for depositing, withdrawing, and exchanging, have not been affected. The team is still continuously monitoring the updated contracts and asks users to verify their restored balances.










