NewsCryptoAvici Hit by $1.02 Million Exploit as Stolen Funds Trail Through Tornado Cash

Avici Hit by $1.02 Million Exploit as Stolen Funds Trail Through Tornado Cash

Author: CoinTrust·

Key Takeaways

  • On-chain reports estimate the Avici exploit resulted in losses of approximately $1.02 million.
  • The attacker moved about 10,000 SOL to a secondary wallet, swapped it for roughly $1.02 million in USDC, bridged the funds cross-chain, and converted them into approximately 418 ETH.
  • The stolen proceeds were deposited into Tornado Cash, a mixing protocol that obscures links between deposited and withdrawn assets, making tracing more difficult.
  • Avici's card-issuing partner, Rain, identified a vulnerability in a version of a Solana card contract that was also used by a small number of other programs, and the contract has since been upgraded.
  • Avici stated that all affected card balances will be refunded in full.
Avici Hit by $1.02 Million Exploit as Stolen Funds Trail Through Tornado Cash

Avici has suffered a cryptocurrency exploit estimated at approximately $1.02 million, according to on-chain reports. The attacker moved the stolen funds through a multi-stage sequence of transactions, converting the assets from Solana (SOL) into USDC and then into Ethereum (ETH) before depositing the proceeds into Tornado Cash.

How the funds moved

The reported transaction trail began with the transfer of approximately 10,000 SOL — valued at roughly $1.02 million at the time of the incident — from Avici-related holdings to a secondary wallet controlled by the attacker. Rather than holding the stolen cryptocurrency in its original form, the attacker swapped the SOL for approximately $1.02 million in USDC.

The attacker then bridged the USDC proceeds across blockchain networks and exchanged them for approximately 418 ETH. This progression from SOL to a dollar-denominated stablecoin, followed by a cross-chain transfer and conversion into Ethereum, created several distinct stages between the initial theft and the funds' eventual destination.

The multi-stage approach can complicate investigations, because each conversion generates additional transactions across potentially different blockchain environments. Investigators typically rely on publicly visible transaction records to follow these movements and identify connections between wallets.

Onchain analytics account Onchain Lens reported the incident on X:

AVICI EXPLOITED FOR ~$1.02M @avici has been exploited, with losses totaling roughly $1.02M. The attacker moved 10K $SOL to another wallet and swapped it for ~$1.02M $USDC. The funds were then bridged and swapped into ~418 $ETH. Attacker:… pic.twitter.com/UfyxeynZEZ — Onchain Lens (@OnchainLens) August 29, 2026

Final destination: Tornado Cash

After obtaining the approximately 418 ETH, the attacker deposited the funds into Tornado Cash. The reported destination address begins with 0x2cE21E4921d3Eb116526c3651Dac0257657338D5.

Tornado Cash is a cryptocurrency mixing protocol designed to obscure connections between deposited and withdrawn digital assets. Its use in this transaction adds another layer of obfuscation to the movement of the funds following the initial exploit and could make subsequent tracing more challenging. The protocol has long been associated with laundering proceeds of crypto thefts: the U.S. Treasury's Office of Foreign Assets Control (OFAC) sanctioned Tornado Cash in August 2022, citing its use in laundering billions of dollars stolen by groups including the Lazarus Group, before those sanctions were lifted in March 2025 following a U.S. appeals court ruling. Its continued appearance in exploit fund trails remains a focal point for blockchain-analytics firms such as Chainalysis and TRM Labs, which track deposits to flagged mixers as part of post-hack investigations.

Avici's response

Avici first acknowledged the situation on X on August 28, 2026:

We're aware of an issue affecting card balance withdrawals and are closely monitoring the situation. We're working directly with all relevant partners to resolve it and will share updates as soon as we have more information. — Avici (@avici) August 28, 2026

The company later provided an update:

UPDATE: All affected card balances will be refunded in full. Earlier today, our card-issuing partner, Rain, identified a vulnerability in an version of a Solana card contract used by Avici and a small number of other programs. The contract has now been upgraded across all… — Avici (@avici) August 28, 2026

According to the statement, the vulnerability was identified by Avici's card-issuing partner, Rain, in a version of a Solana card contract used by Avici and a small number of other programs. Avici said the contract has since been upgraded and that all affected card balances will be refunded in full. The reference to a Solana-based card contract reflects a broader trend of crypto-linked spending products issuing balances on-chain while relying on third-party issuing partners for card rails — a layered architecture in which a flaw at the contract or partner level can affect multiple programs at once, as Avici noted that the vulnerable contract was also used by a small number of other programs.

Broader context

The incident highlights the continuing security risks faced by cryptocurrency projects and users holding assets across decentralized networks. Attackers can move stolen funds through different tokens and blockchain ecosystems relatively quickly, creating challenges for security teams and investigators attempting to respond to an exploit.

The reported $1.02 million loss demonstrates how a single compromise can produce a complex chain of transactions spanning wallet transfers, token swaps, cross-chain movement, and further conversion. Whether investigators can continue following the proceeds or identify additional wallets connected to the incident will depend on further movement of the cryptocurrency.

The Avici exploit adds to broader security concerns surrounding digital asset platforms, where rapid transfers and cross-chain swaps can complicate efforts to freeze, recover, or trace funds following a breach. It also underscores the importance of transaction monitoring and rapid detection when large cryptocurrency balances move unexpectedly. In this case, Avici committed to refunding affected balances in full, a response pattern seen in previous card-related crypto incidents where issuers or partners absorb losses to preserve user trust — though the outcome of any tracing or recovery effort against funds already routed through Tornado Cash remains an open question.