• Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Onchain Lending

Pencil Finance completes first fully onchain student loan cycle, financing 6,600 students in Southeast Asia

09/04/2026
Secret Network exploit

Outdated Rain contract exposes Avici and Tria to $1.1 million Solana card exploit

09/04/2026
Tether ipo fundraising

Tether sold USDT directly to firms later tied to North Korean hackers and the Sinaloa Cartel

09/04/2026
  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Onchain Lending

Pencil Finance completes first fully onchain student loan cycle, financing 6,600 students in Southeast Asia

09/04/2026
Secret Network exploit

Outdated Rain contract exposes Avici and Tria to $1.1 million Solana card exploit

09/04/2026
Tether ipo fundraising

Tether sold USDT directly to firms later tied to North Korean hackers and the Sinaloa Cartel

09/04/2026
Friday, September 4, 2026
  • Login
The Bit Gazette
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion
No Result
View All Result
The Bit Gazette
No Result
View All Result
Home Crypto News

Outdated Rain contract exposes Avici and Tria to $1.1 million Solana card exploit

The Rain contract exploit targeted outdated Solana card infrastructure, affecting thousands of users across multiple stablecoin programs while leaving self-custodial wallets untouched.

by Muhammad Abubakar
1 hour ago
in Crypto News
Reading Time: 5 mins read
0
Secret Network exploit

Secret Network exploit

Share on FacebookShare on Twitter

An attacker used an outdated Rain card contract on Solana on Aug. 28 to withdraw approximately $1.1 million in stablecoins from collateral accounts linked to several crypto card programs, according to blockchain security firm Blockaid.

The Rain contract exploit affected at least Avici and Tria, which together reported more than $932,800 in losses across 2,321 customers, while the attacker later moved part of the proceeds across chains and into Tornado Cash.

The incident did not compromise Solana itself or customers’ personal wallets. Instead, the Rain contract exploit targeted onchain contracts holding stablecoins deposited by users to fund their crypto card balances.

Rain provides infrastructure that enables crypto companies to issue cards funded by digital assets. According to the company, its monitoring systems identified a vulnerability involving a “small number of programs” that were still using an outdated version of its Solana card contract.

Rain subsequently upgraded every program using the affected contract version.

Rain contract exploit exposed shared Solana card infrastructure

The Rain contract exploit highlighted the security risks associated with shared blockchain infrastructure used by multiple crypto card providers.

When customers deposit stablecoins to fund a card, those assets are transferred into collateral accounts controlled through onchain contracts. Although the funds are associated with the customer’s card balance, they are no longer held in the customer’s self-custodial wallet.

Blockaid identified four deployments containing code with the same opcode hash as the vulnerable Rain contract. The security company said the attacker successfully drained at least two of those deployments, while the other two contained the same vulnerability but had no confirmed losses.

“The attacker exploited a vulnerability in an outdated Rain Solana contract,” Blockaid said in its analysis.

The distinction between the affected collateral contracts and personal wallets is significant. Customers’ private keys were not compromised, and the attacker did not gain access to their self-custodial assets.

Rain confirmed that an outdated contract was responsible for the incident but has not publicly released a complete technical report detailing every affected deployment or explaining why older versions remained operational.

The Rain contract exploit also did not constitute a breach of the Solana blockchain. The network continued processing transactions normally while the attacker exploited weaknesses in application-level contract code.

Rain contract exploit bypassed signature protections

The technical weakness at the center of the Rain contract exploit involved the contract’s signature-verification mechanism.

The outdated contract required two independent authorizations for certain account actions. It relied on Solana’s Ed25519 verification instructions to validate the signatures.

According to Blockaid, the attacker manipulated the second verification instruction so that its signature, public key and message offsets referenced information contained in the first instruction.

As a result, the contract treated a single attacker-controlled signature as if it represented two separate approvals.

That allowed the attacker to bypass the authorization requirement and gain administrative control over affected collateral accounts.

After defeating the signature check, the attacker used an AddCollateralAdmin instruction to assign itself administrative privileges. It then called WithdrawCollateralAsset to transfer USDC and USDT from the accounts.

Blockaid recorded 2,945 administrator additions and 5,288 withdrawal calls. The company identified 8,233 core exploit transactions carried out over roughly two hours and 29 minutes.

The speed of the operation indicated a high level of automation. Blockaid said the first two successful withdrawals were separated by only three seconds, suggesting that the attacker had prepared a system capable of rapidly targeting multiple accounts.

Customers did not authorize the malicious withdrawals.

“Rain is a critical piece of infrastructure for stablecoin-powered card programs, so vulnerabilities in shared deployments can have consequences across multiple applications,” Blockaid said in its analysis.

The Rain contract exploit demonstrates how users can remain exposed even when they maintain control of their personal wallets. Once funds are deposited into a card program, their security also depends on the smart contracts and infrastructure managing those balances.

Rain contract exploit sent proceeds through deBridge and Tornado Cash

After withdrawing the stablecoins, the attacker consolidated the funds in a Solana wallet identified by Blockaid as FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj.

The attacker then exchanged the stolen USDC and USDT for SOL through decentralized trading platforms before transferring proceeds from Solana to Ethereum through the deBridge cross-chain protocol.

Blockaid traced approximately 455.9 ETH into Tornado Cash between 19:20 and 19:49 UTC.

Tornado Cash pools deposits and allows withdrawals to addresses that are not publicly connected to the original sending wallets. That process can make subsequent blockchain movements more difficult to trace.

Blockaid said the stolen funds had not been recovered after entering the mixing service.

The Rain contract exploit therefore involved more than an unauthorized withdrawal. The movement of funds across blockchain networks added another layer to the investigation and complicated efforts to follow the proceeds.

Blockaid also identified two Ethereum addresses that had funded the attacker’s initial Solana activity. Neither Rain nor law enforcement authorities have publicly identified the individuals controlling those addresses.

The security company’s findings on the attack and subsequent fund movements represent its own analysis.

Rain contract exploit leaves Avici and Tria customers facing losses

The financial impact of the Rain contract exploit became clearer after affected crypto neobanks disclosed customer losses.

Avici said the attacker removed $500,859.22 from card balances belonging to 1,685 users. The company said it refunded all affected customers and offered 10% cashback following the incident.

Tria separately reported approximately $431,945 in losses affecting 636 customers. In an official update, the company said affected customers were being reimbursed.

Together, the disclosed losses from Avici and Tria totaled $932,804.22. Blockaid’s broader estimate of approximately $1.1 million indicates that other Rain-supported programs were also affected.

Blockaid identified Solayer Pay as another affected program, although no independently verified loss figure was available in the information disclosed.

The Rain contract exploit also affected market sentiment around the companies involved. Avici’s token fell 49% from its daily high after reports of the attack emerged, reaching a reported low of $0.217 before recovering part of the decline. Tria’s token also fell more than 10% at one point.

Those market movements occurred after the exploit became public, although broader market conditions could also have contributed to the price declines.

Rain said all card programs still using the vulnerable contract version had been upgraded and reported no additional unauthorized activity after the changes.

The company also said affected users would be made whole, although it has not publicly clarified whether Rain itself will reimburse card programs directly or whether individual providers will bear the costs.

Several questions remain about the incident, including when the vulnerable code was introduced, why outdated deployments remained active and whether the authorization weakness had previously been identified through an audit.

The Rain contract exploit comes amid broader concerns about blockchain security. Blockaid estimated that crypto security incidents caused approximately $1.1 billion in losses during the first half of 2026.

The incident also raises questions about whether periodic smart-contract audits are sufficient for infrastructure responsible for holding customer funds. Continuous monitoring, contract-version management and tighter administrative controls could become increasingly important as stablecoin-funded card services expand.

A detailed technical report from Rain would allow independent researchers and affected providers to assess the full scope of the vulnerability and determine whether similar code remains deployed elsewhere.

For users, the incident underscores an important distinction: maintaining self-custody protects personal wallets from certain forms of compromise, but it does not necessarily protect assets once they are deposited into third-party infrastructure.

In the case of the Rain contract exploit, the vulnerable contracts, not customers’ private keys, became the point of failure.

Tags: AviciBlockaidblockchaincardanocryptocrypto cardsCryptocurrencycybersecuritydeBridgedefiexploitfintechhackingRainsecuritysmart contractsSolanastablecoinstornado cashTriausdcusdtvulnerabilitieswalletsweb3
Share197Tweet123
Muhammad Abubakar

Muhammad Abubakar

  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Onchain Lending

Pencil Finance completes first fully onchain student loan cycle, financing 6,600 students in Southeast Asia

09/04/2026
Secret Network exploit

Outdated Rain contract exposes Avici and Tria to $1.1 million Solana card exploit

09/04/2026
Tether ipo fundraising

Tether sold USDT directly to firms later tied to North Korean hackers and the Sinaloa Cartel

09/04/2026
The Bit Gazette

Copyright © 2025 - The Bit Gazette.

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion

Copyright © 2025 - The Bit Gazette.