EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Rain contract vulnerability caused card users to lose US$1.1 million

2026-09-03 15:39:13
Bookmark

Attackers used outdated Rain contracts to steal approximately $1.1 million from Solana stablecoin card projects.

According to blockchain security company Blockaid, an attacker used an outdated Rain card contract to steal approximately $1.1 million from multiple stablecoin card projects running on Solana on August 28.

Summary

An outdated Rain Solana contract allows attackers to make unauthorized withdrawals from card-backed accounts across multiple items. Blockaid estimated that the stolen amount was approximately $1.1 million, and the proceeds were then entered into the Tornado Cash mixer on Ethereum. Avici reported losses of $500,859 to 1685 users, while Tria separately confirmed losses of $431,945 to 636 customers. Rain said that after the August attack, all programs using the affected contract version had been upgraded. Self-managed wallets were not affected because the attacker targeted a separate contract that held a charged card balance.

Avici and Tria are two of the affected crypto digital banks. The two companies disclosed that a total of 2321 users lost more than $932,800. Blockaid said other Rain-backed projects were also at risk, resulting in total losses estimated at approximately $1.1 million. Instead of accessing customers 'self-managed wallets or private keys, the attacker used mortgage contracts held in stablecoins-which users deposit and use to recharge their card balances. Rain said its monitoring system discovered a vulnerability that affected "a few" projects that use outdated versions of Solana card contracts. According to its public statement, the company has upgraded all projects that are still running affected versions.

An attacker used outdated Rain contracts to steal $1.1 million worth of user card balances from Avici, Tria and other encrypted digital banks. Blockaid's on-chain monitoring feature allows stablecoin card issuers to detect vulnerabilities in their contract deployment networks. The incident has heightened widespread concerns about contractual and operational loopholes. According to research released by Blockaid, cryptographic security failures caused approximately $1.1 billion in losses in the first half of 2026.

Rain contract vulnerability exposes risk of shared card infrastructure

Rain provides infrastructure that allows crypto companies to issue cards recharged with stablecoins. When customers recharge their cards, the deposited assets are transferred to a mortgage account managed through on-chain contracts. These balances are separated from the assets in the customer's personal wallet. Once funds enter the card mortgage contract, their security depends on the infrastructure provider's code and authorization controls. Blockaid identified four contract deployments whose code contained the same opcode hashes as the vulnerable contracts. Security companies said the attackers ran out of funds in at least two deployments. Two other deployments are said to have the same vulnerability, but no damage has been confirmed. Rain confirmed that outdated contracts caused the incident, but has not yet released a complete technical report to identify all affected deployments or explain why some projects are still using older versions.

This situation is similar to other incidents where outdated or repeatedly vulnerable infrastructure remains active. In related reports, attackers exploited the same Verus bridging contract twice in two months, raising similar questions about shared deployment escalation issues. The Rain incident does not mean Solana itself has been compromised. The blockchain continues to process transactions normally, while the attacker exploits application code deployed on the network.

Reused signatures bypass withdrawal controls

The outdated Rain contract requires two separate authorizations before allowing certain accounts to operate. It uses Solana's Ed25519 verification instructions to confirm the required signature. According to Blockaid's analysis, the attacker manipulated the second verification command. Its signature, public key, and message offset point to the information contained in the first instruction. As a result, contracts affected by the vulnerability treat a signature controlled by an attacker as two separate approvals. This allows attackers to meet authorization requirements without having to obtain permission from the mortgage account owner. After bypassing signature checking, the attacker used the "AddCollateralAdmin" command to grant himself administrative rights on various accounts, and then called "Withdraw CollateralAsset" to transfer USDC and USDT from these accounts. Blockaid recorded 2945 administrator add operations and 5288 withdrawal calls. The company identified 8233 core attack transactions in approximately 2 hours and 29 minutes. The entire operation is carried out at an automated speed. Blockaid said there were only three seconds between the first two successful withdrawals, indicating that the attacker was ready to target the system for multiple accounts. The customer did not authorize these malicious transactions. The vulnerability occurs at the contract level, which means that protections against phishing or malicious wallet signatures cannot prevent these withdrawals. Another similar application-layer weakness recently exposed a protocol to risk: flawed collateral controls led to a $75 million DeFi vulnerability attack. In both cases, the underlying network is operating normally, but the application logic allows unauthorized activity.

Attackers transfer funds through deBridge

The extracted USDC and USDT are aggregated into a Solana wallet with the address FVNFzqAny8spWdPmYw6RQ9TkYa 29ueFFiqCFD1gQnCEj. The attacker exchanged stablecoins for SOL through a decentralized trading platform. Blockaid then traced the transfer of funds from Solana to Ethereum through the deBridge cross-chain protocol. According to Blockaid, approximately 455.9 ETH entered Tornado Cash between 19:19 and 19:49 UTC. The mixers pool deposits and allow funds to be withdrawn to addresses that are not publicly associated with the original sending wallet, thus making subsequent fund transfers more difficult to track in public blockchain records. Blockaid said funds have not been recovered after entering Tornado Cash. The use of cross-chain infrastructure adds new links to the money laundering route. Cryptobridges have also become a direct target-in early 2026, a forged transfer vulnerability stole $11.5 million from the Verus Ethereum Bridge. Blockaid linked two Ethereum addresses to the initial funding of Rain attacker Solana's activities. Neither Rain nor law enforcement have publicly identified the persons controlling these addresses. The company's statements about detecting attacks and tracking funds are based on its own findings. Blockaid provides security and monitoring services to crypto companies, including stablecoin card issuers.

Avici and Tria disclose customer losses

Avici reported that attackers stole $500,859.22 from the card balances of 1685 users. The company said it had refunds to all affected customers and provided a 10% cash back after the incident. Tria disclosed that its 636 customers lost a total of approximately $431,945. The company said in an official update that each affected customer will be compensated. These two disclosures combined losses of US$932,804.22. Blockaid also mentioned Solayer Pay as an affected project, but has not yet obtained independent confirmation data on the amount of its losses. The difference between the losses disclosed by Avici and Tria and Blockaid's estimate of $1.1 million appears to involve other Rain-backed projects, but detailed and complete data has not been released. According to market data, Avici's tokens fell 49% from the day's high after the report of the vulnerability attack, falling to a low of $0.217, and then partially rebounded. Tria's tokens also fell by more than 10% at one point. These price movements occurred after public reports of the attack, but broader market conditions may also have affected trading.

Rain upgrades affected contract deployments

Rain said all card items that use outdated contracts have been upgraded. The company reported that no additional unauthorized activity was discovered after completing the changes. Rain also said it would allow affected users to receive full compensation, but did not disclose whether it would directly reimburse the card project or whether each service provider would bear the costs themselves. Several issues remain unresolved. Rain has not released the full version history of the vulnerable contract, the date the vulnerability was introduced, and why older version deployments are still active. The company also did not disclose whether an audit found the authorization flaw before the attack. There have been no public reports that funds deposited with Tornado Cash have been recovered. This incident has once again raised questions about whether regular audits are sufficient to provide adequate protection after contracts enter the production environment. Recent industry research has found that organizations increasingly want continuous monitoring in addition to traditional security audits, especially for contracts that hold user assets. A detailed technical report will allow external researchers to identify vulnerabilities and determine whether similar code is still running elsewhere. Card providers may also revisit how they track contract versions and limit administrative rights in shared infrastructure. Users can retain control of their personal wallets while still facing the risks of depositing funds into card projects. The security of these balances depends on the contracts that hold the collateral, the providers that maintain those contracts, and the speed with which operators respond when a breach occurs.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP