More than $600,000 has been stolen from cryptocurrency users through a phishing website that impersonated Avici, a Solana-based neobank. The fraudulent site tricked visitors into connecting their wallets, which allowed the attackers to drain funds. The incident highlights the growing threat of phishing attacks in the decentralized finance (DeFi) space, where users are often the first line of defense.
How the Scam Worked
According to a report by Crypto Briefing, the hackers created a fake Avici website that closely mimicked the legitimate platform. Users who visited the site were prompted to connect their crypto wallets, a common step in many DeFi applications. However, once connected, the malicious site executed transactions that transferred the victims’ funds to the attackers’ wallets. The exact method—whether through a malicious smart contract or a wallet-draining service—has not been fully disclosed, but such attacks typically exploit user permissions granted during the connection process.
The phishing site was likely promoted through social media, phishing emails, or malicious ads, though the specific distribution channels have not been confirmed. This incident is part of a broader trend of phishing attacks targeting DeFi users, which have resulted in hundreds of millions of dollars in losses over the past year.
Market Impact and Token Price Drop
Following the news, the AVICI token, which is associated with the Avici platform, experienced a sharp decline. According to CoinMarketCap, AVICI was trading at $0.2728 at the time of reporting, down 38.54% from its recent levels. This drop reflects the market’s reaction to the security breach and the potential loss of user trust in the platform.
While the token’s price decline is significant, it is not uncommon for tokens associated with hacked or compromised projects to suffer double-digit losses. The long-term impact on Avici’s reputation and user base remains to be seen, as the team works to address the situation and reassure users.
Why This Matters to Crypto Users
This incident serves as a critical reminder of the risks associated with connecting wallets to third-party websites. Even legitimate-looking platforms can be spoofed, and users must always verify the authenticity of a website before connecting their wallets. The DeFi ecosystem relies heavily on user vigilance, and phishing attacks remain one of the most effective methods for cybercriminals to steal funds.
For Avici users, the immediate steps are to revoke any permissions granted to suspicious sites and to monitor their wallets for unauthorized transactions. Tools like revoke.cash can help users manage and revoke token approvals.
Broader Context of Phishing in Crypto
This attack is not an isolated event. In 2025, phishing scams accounted for a significant portion of crypto-related crimes, with losses exceeding $1 billion. Scammers often use sophisticated techniques, including creating lookalike domains, using social engineering, and leveraging search engine ads to appear legitimate. The use of neobanks and DeFi platforms as bait is particularly effective because users are accustomed to connecting their wallets to such services.
Regulators and industry leaders have been urging users to adopt better security practices, such as using hardware wallets, double-checking URLs, and avoiding clicking on links from unsolicited messages. However, as this incident shows, even experienced users can fall victim to well-crafted phishing sites.
Conclusion
The $600,000 phishing attack on Avici underscores the persistent threat of cybercrime in the cryptocurrency space. While the immediate financial losses are significant, the broader impact on user trust and the reputation of DeFi platforms could be even more damaging. Users are advised to remain vigilant, verify website URLs, and exercise caution when connecting their wallets to any platform. As the investigation continues, more details may emerge about the attackers’ methods and the full scope of the breach.
FAQs
Q1: How can I protect myself from phishing sites like the one that attacked Avici?
Always double-check the URL of any website before connecting your wallet. Use bookmarks for frequently visited sites, enable two-factor authentication, and consider using a hardware wallet for large holdings. Additionally, use tools like revoke.cash to regularly review and revoke unnecessary token approvals.
Q2: What should I do if I think I’ve connected my wallet to a phishing site?
Immediately revoke any permissions you granted to the site using a tool like revoke.cash or through your wallet’s settings. Move your remaining funds to a new wallet that has never been connected to the suspicious site. Monitor your wallet for any unauthorized transactions and report the incident to the platform and local authorities.
Q3: Will the AVICI token recover from this price drop?
It’s uncertain. Token prices after a security breach depend on several factors, including the team’s response, the extent of the losses, and overall market sentiment. In some cases, tokens recover if the project addresses the issue transparently and implements stronger security measures. However, in other cases, the damage to trust can be long-lasting. Investors should conduct their own research and consider the risks before making any decisions.
Disclaimer: The information provided is not trading advice, Bitcoinworld.co.in holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

