Rain contract exploit drains $1.1M from card users

An attacker exploited an outdated Rain card contract on Aug. 28, draining approximately $1.1 million from multiple stablecoin card programs operating on Solana, according to blockchain security company Blockaid. Summary An outdated Rain Solana contract allowed unauthorized withdrawals from card collateral accounts across multiple programs. Blockaid estimated approximately $1.1 million was stolen, with proceeds later entering Tornado Cash on Ethereum. Avici reported $500,859 drained from 1,685 users, while Tria identified $431,945 affecting 636 customers separately. Rain said every program using the vulnerable contract version was upgraded following the August attack. Self-custodial wallets remained unaffected because the attacker targeted separate contracts holding funded card balances instead. Avici and Tria were among the affected crypto neobanks. The two companies disclosed combined losses of more than $932,800 across 2,321 users. Blockaid said other Rain-supported programs were also exposed, bringing the estimated loss to approximately $1.1 million. The attacker did not access customers’ self-custodial wallets or private keys. Instead, the exploit targeted collateral contracts holding stablecoins that users had deposited to fund their card balances. Rain said its monitoring systems discovered a vulnerability affecting a “small number of programs” using an outdated version of its Solana card contract. The company upgraded every program still running the affected version, according to its public statement. An attacker exploited an outdated Rain contract, draining $1.1M in user card balances from @avici, @useTria, and other crypto neobanks. Blockaid's Onchain Monitoring gives stablecoin card issuers the capability to detect exploits across their fleet of contract deployments. Read… pic.twitter.com/vzMQfPkdtT — Blockaid (@blockaid_) September 2, 2026 The incident adds to wider concerns about contract and operational vulnerabilities. Crypto security failures caused approximately $1.1 billion in losses during the first half of 2026, according to research published by Blockaid. You might also like: Blockaid uncovers $18M exploit that forces Ostium trading halt Rain contract flaw exposed shared card infrastructure Rain provides infrastructure that allows crypto companies to issue cards funded with stablecoins. When customers fund their cards, the deposited assets move into collateral accounts managed through onchain contracts. These balances are separate from assets held inside customers’ personal wallets. Once funds enter a card collateral contract, their security depends on the infrastructure provider’s code and authorization controls. Blockaid identified four deployments containing code with the same opcode hash as the vulnerable contract. The security company said the attacker drained at least two deployments. The other two reportedly carried the same vulnerability but had no confirmed losses. Rain confirmed that an outdated contract caused the incident. However, it has not published a complete technical report identifying every affected deployment or explaining why some programs continued using the older version. The situation resembles other incidents in which outdated or repeatedly vulnerable infrastructure remained active.
عنوان اصلی (انگلیسی): Rain contract exploit drains $1.1M from card users
مشاهدهی خبر کامل در منبع ↗ بازگشت به Aviciاین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.