Rain contract exploit drains $1.1M from card users

fiverr
BTCC



An attacker exploited an outdated Rain card contract on Aug. 28, draining approximately $1.1 million from multiple stablecoin card programs operating on Solana, according to blockchain security company Blockaid.

Summary

  • An outdated Rain Solana contract allowed unauthorized withdrawals from card collateral accounts across multiple programs.
  • Blockaid estimated approximately $1.1 million was stolen, with proceeds later entering Tornado Cash on Ethereum.
  • Avici reported $500,859 drained from 1,685 users, while Tria identified $431,945 affecting 636 customers separately.
  • Rain said every program using the vulnerable contract version was upgraded following the August attack.
  • Self-custodial wallets remained unaffected because the attacker targeted separate contracts holding funded card balances instead.

Avici and Tria were among the affected crypto neobanks. The two companies disclosed combined losses of more than $932,800 across 2,321 users. Blockaid said other Rain-supported programs were also exposed, bringing the estimated loss to approximately $1.1 million.

itrust

The attacker did not access customers’ self-custodial wallets or private keys. Instead, the exploit targeted collateral contracts holding stablecoins that users had deposited to fund their card balances.

Rain said its monitoring systems discovered a vulnerability affecting a “small number of programs” using an outdated version of its Solana card contract. The company upgraded every program still running the affected version, according to its public statement.

The incident adds to wider concerns about contract and operational vulnerabilities. Crypto security failures caused approximately $1.1 billion in losses during the first half of 2026, according to research published by Blockaid.

Rain contract flaw exposed shared card infrastructure

Rain provides infrastructure that allows crypto companies to issue cards funded with stablecoins. When customers fund their cards, the deposited assets move into collateral accounts managed through onchain contracts.

These balances are separate from assets held inside customers’ personal wallets. Once funds enter a card collateral contract, their security depends on the infrastructure provider’s code and authorization controls.

Blockaid identified four deployments containing code with the same opcode hash as the vulnerable contract. The security company said the attacker drained at least two deployments. The other two reportedly carried the same vulnerability but had no confirmed losses.

Rain confirmed that an outdated contract caused the incident. However, it has not published a complete technical report identifying every affected deployment or explaining why some programs continued using the older version.

The situation resembles other incidents in which outdated or repeatedly vulnerable infrastructure remained active. In related coverage, attackers exploited the same Verus bridge contract twice within two months, raising similar questions about upgrades across shared deployments.

The Rain incident did not represent a compromise of Solana itself. The blockchain continued processing transactions normally while the attacker exploited application code deployed on the network.

Reused signature bypassed withdrawal controls

The outdated Rain contract required two independent authorizations before allowing certain account actions. It used Solana’s Ed25519 verification instructions to confirm the required signatures.

According to Blockaid’s analysis, the attacker manipulated the second verification instruction. Its signature, public key and message offsets pointed back to information contained in the first instruction.

The vulnerable contract therefore accepted one attacker-controlled signature as two independent approvals. This allowed the attacker to satisfy the authorization requirement without permission from the owners of the collateral accounts.

After bypassing the signature check, the attacker used an AddCollateralAdmin instruction to give itself administrative privileges over individual accounts. It then called WithdrawCollateralAsset to transfer USDC and USDT from those accounts.

Blockaid recorded 2,945 administrator additions and 5,288 withdrawal calls. The company identified 8,233 core exploit transactions over approximately two hours and 29 minutes.

The operation proceeded at an automated pace. Blockaid said the first two successful withdrawals occurred three seconds apart, indicating that the attacker had prepared a system for targeting multiple accounts.

Customers did not authorize the malicious transactions. The exploit occurred at the contract level, meaning protections against phishing or malicious wallet signatures would not have prevented these withdrawals.

A different application-level weakness recently exposed another protocol when faulty collateral controls enabled a $75 million DeFi exploit. In both cases, the underlying networks continued operating while application logic allowed unauthorized activity.

Attacker moved funds through deBridge

The withdrawn USDC and USDT accumulated in one Solana wallet identified as FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj.

The attacker exchanged the stablecoins for SOL through decentralized trading platforms. Blockaid then traced the proceeds from Solana to Ethereum through the deBridge cross-chain protocol.

Approximately 455.9 ETH entered Tornado Cash between 19:20 and 19:49 UTC, according to Blockaid. Tornado Cash pools deposits and permits withdrawals to addresses that are not publicly connected to the original sending wallets.

The mixer therefore made subsequent movements harder to trace through public blockchain records. Blockaid said the stolen funds had not been recovered after entering Tornado Cash.

The use of cross-chain infrastructure added another stage to the laundering route. Crypto bridges have also become direct targets, with a forged transfer exploit draining $11.5 million from the Verus Ethereum bridge earlier in 2026.

Blockaid connected two Ethereum addresses to the initial financing of the Rain attacker’s Solana activity. Neither Rain nor law enforcement authorities have publicly identified the people controlling those addresses.

The company’s statements about detecting the attack and tracing the funds represent its own findings. Blockaid provides security and monitoring services to crypto companies, including stablecoin card issuers.

Avici and Tria disclose customer losses

Avici reported that the attacker removed $500,859.22 from card balances belonging to 1,685 users. The company said it refunded all affected customers and provided 10% cashback following the incident.

Tria disclosed approximately $431,945 in losses across 636 customers. It said in an official update that each affected customer was being reimbursed.

The two disclosures account for $932,804.22 of the estimated losses. Blockaid also named Solayer Pay as an affected program, but no independently verified figure for its losses was available.

The difference between the disclosed Avici and Tria losses and Blockaid’s $1.1 million estimate appears to involve other Rain-supported programs. A complete breakdown has not been published.

Avici’s token fell 49% from its daily high after reports of the exploit emerged, according to market data. The token reached a reported low of $0.217 before partially recovering. Tria’s token also declined by more than 10% at one point.

Those price movements followed public reports of the attack, although broader market conditions may also have influenced trading.

Rain upgrades affected contract deployments

Rain said all card programs using the outdated contract had been upgraded. The company reported no additional unauthorized activity after completing the changes.

It also said affected users would be made whole. Rain has not disclosed whether it will reimburse card programs directly or whether individual providers will carry the costs.

Several questions remain unanswered. Rain has not released the vulnerable contract’s full version history, the date the flaw was introduced or the reason older deployments remained active.

The company also has not disclosed whether an audit identified the authorization flaw before the attack. No recovery of the funds deposited into Tornado Cash has been publicly reported.

The episode renews questions about whether periodic audits provide enough protection after contracts enter production. Recent industry research found that institutions increasingly want continuous monitoring alongside traditional security audits, particularly for contracts holding user assets.

A detailed technical report would allow outside researchers to confirm the vulnerability and determine whether similar code remains active elsewhere. Card providers may also review how they track contract versions and limit administrative permissions across shared infrastructure.

Users can retain control of their personal wallets while still facing risks after depositing funds into a card program. The security of those balances depends on the contracts holding the collateral, the provider maintaining them and the operators responding when vulnerabilities emerge.





Source link

Coinmama

Be the first to comment

Leave a Reply

Your email address will not be published.


*