خبری درباره‌ی Avici (AVICI)

Rain Card Exploit Drains $1.1 Million From Solana Users

Blockonomi ۱۳ روز پیش خلاصه‌ی فارسی · ۴۵۸ کلمه
Rain Card Exploit Drains $1.1 Million From Solana Users

TLDR An outdated Rain Solana contract allowed unauthorized withdrawals from card collateral accounts across multiple programs. Blockaid estimated about $1.1 million was stolen, with proceeds later entering Tornado Cash on Ethereum. Avici reported $500,859 drained from 1,685 users, while Tria identified $431,945 affecting 636 customers. Rain said every program using the vulnerable contract version has been upgraded since the attack. Self-custodial wallets were unaffected because the attacker targeted separate contracts holding funded card balances. An attacker exploited an outdated Rain card contract on Aug. 28, taking about $1.1 million from stablecoin card programs on Solana. Blockchain security firm Blockaid tracked the incident and published its findings. Rain provides infrastructure that lets crypto companies issue cards funded with stablecoins. Customer deposits move into collateral accounts controlled by onchain contracts. These collateral accounts are separate from a user’s personal wallet. Their safety depends on the code and controls set up by the infrastructure provider. Blockaid found four contract deployments sharing the same code as the flawed version. The attacker drained funds from at least two of them. Earlier today, Rain’s monitoring systems discovered a vulnerability impacting a small number of programs using an outdated version of our Solana contracts. Other programs were not impacted. Rain immediately launched an investigation to determine the full scope of the situation.… — Rain (@raincards) August 28, 2026 How the Exploit Worked The outdated contract required two separate approvals before certain actions could happen. It used Solana’s Ed25519 verification system to check signatures. Blockaid said the attacker reused one signature so it looked like two separate approvals. This let the attacker bypass the requirement without permission from account owners. An attacker exploited an outdated Rain contract, draining $1.1M in user card balances from @avici, @useTria, and other crypto neobanks. Blockaid's Onchain Monitoring gives stablecoin card issuers the capability to detect exploits across their fleet of contract deployments. Read… pic.twitter.com/vzMQfPkdtT — Blockaid (@blockaid_) September 2, 2026 After bypassing the check, the attacker gave itself admin access over individual accounts. It then withdrew USDC and USDT from those accounts. Blockaid recorded 2,945 admin additions and 5,288 withdrawal calls. In total, it counted 8,233 exploit transactions over about two hours and 29 minutes. The first two withdrawals happened three seconds apart. This pace suggests the attacker had built a system to target many accounts quickly. Where the Funds Went The stolen stablecoins were sent to one Solana wallet. The attacker then swapped them for SOL using decentralized exchanges. Blockaid traced the funds from Solana to Ethereum through the deBridge cross-chain protocol. About 455.9 ETH entered Tornado Cash between 19:20 and 19:49 UTC. Tornado Cash mixes deposits so withdrawals can’t easily be linked to the original wallet. Blockaid said the funds had not been recovered as of its report.

عنوان اصلی (انگلیسی): Rain Card Exploit Drains $1.1 Million From Solana Users

مشاهده‌ی خبر کامل در منبع ↗ بازگشت به Avici

این خلاصه به‌صورت خودکار از کوین‌مارکت‌کپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاع‌رسانی است و توصیه‌ی معاملاتی نیست.