Rain Card Exploit Drains $1.1 Million From Solana Users

1 hour ago 3

TLDR

  • An outdated Rain Solana contract allowed unauthorized withdrawals from card collateral accounts across multiple programs.
  • Blockaid estimated about $1.1 million was stolen, with proceeds later entering Tornado Cash on Ethereum.
  • Avici reported $500,859 drained from 1,685 users, while Tria identified $431,945 affecting 636 customers.
  • Rain said every program using the vulnerable contract version has been upgraded since the attack.
  • Self-custodial wallets were unaffected because the attacker targeted separate contracts holding funded card balances.

An attacker exploited an outdated Rain card contract on Aug. 28, taking about $1.1 million from stablecoin card programs on Solana. Blockchain security firm Blockaid tracked the incident and published its findings.

Rain provides infrastructure that lets crypto companies issue cards funded with stablecoins. Customer deposits move into collateral accounts controlled by onchain contracts.

These collateral accounts are separate from a user’s personal wallet. Their safety depends on the code and controls set up by the infrastructure provider.

Blockaid found four contract deployments sharing the same code as the flawed version. The attacker drained funds from at least two of them.

Earlier today, Rain’s monitoring systems discovered a vulnerability impacting a small number of programs using an outdated version of our Solana contracts. Other programs were not impacted. Rain immediately launched an investigation to determine the full scope of the situation.…

— Rain (@raincards) August 28, 2026

How the Exploit Worked

The outdated contract required two separate approvals before certain actions could happen. It used Solana’s Ed25519 verification system to check signatures.

Blockaid said the attacker reused one signature so it looked like two separate approvals. This let the attacker bypass the requirement without permission from account owners.

An attacker exploited an outdated Rain contract, draining $1.1M in user card balances from @avici, @useTria, and other crypto neobanks.

Blockaid's Onchain Monitoring gives stablecoin card issuers the capability to detect exploits across their fleet of contract deployments.

Read… pic.twitter.com/vzMQfPkdtT

— Blockaid (@blockaid_) September 2, 2026

After bypassing the check, the attacker gave itself admin access over individual accounts. It then withdrew USDC and USDT from those accounts.

Blockaid recorded 2,945 admin additions and 5,288 withdrawal calls. In total, it counted 8,233 exploit transactions over about two hours and 29 minutes.

The first two withdrawals happened three seconds apart. This pace suggests the attacker had built a system to target many accounts quickly.

Where the Funds Went

The stolen stablecoins were sent to one Solana wallet. The attacker then swapped them for SOL using decentralized exchanges.

Blockaid traced the funds from Solana to Ethereum through the deBridge cross-chain protocol. About 455.9 ETH entered Tornado Cash between 19:20 and 19:49 UTC.

Tornado Cash mixes deposits so withdrawals can’t easily be linked to the original wallet. Blockaid said the funds had not been recovered as of its report.

Two Ethereum addresses were linked to the early funding of the attacker’s Solana activity. Neither Rain nor law enforcement has named who controls those addresses.

Avici said the attacker took $500,859.22 from 1,685 users. The company refunded all affected customers and added 10% cashback.

Tria reported losses of about $431,945 across 636 customers. It said each customer would be reimbursed.

Blockaid also named Solayer Pay as an affected program, though no confirmed loss figure was available for it. The gap between disclosed losses and Blockaid’s $1.1 million estimate has not been fully explained.

Avici’s token dropped 49% from its daily high after news of the exploit spread. It reached a low of $0.217 before recovering some value. Tria’s token also fell more than 10% at one point.

Rain said every program running the outdated contract has been upgraded. The company reported no further unauthorized activity since making the changes.

Rain has not released a full technical report or explained why older contract versions remained in use. It also has not said whether an audit caught the flaw before the attack happened.

The post Rain Card Exploit Drains $1.1 Million From Solana Users appeared first on Blockonomi.

Read Entire Article