Rain contract exploit drains $932,804 from 2,321 crypto card users

  • Rain's legacy Solana contract enabled unauthorized withdrawals from Avici and Tria card users.
  • Avici and Tria disclosed combined losses of $932,804.22 affecting 2,321 users.
  • South Korean users lack statutory depositor protection for these nonbank virtual-asset cards.

An outdated Solana smart contract used by crypto-card infrastructure provider Rain enabled unauthorized withdrawals exceeding $930,000 from at least 2,321 Avici and Tria users. Avici reported losses of $500,859.22 among 1,685 cardholders, while Tria said 636 users lost $431,945. The Aug. 29 incident did not compromise personal self-custodial wallets, but funds transferred into card-specific contracts were exposed. The attacker exploited signature and authorization flaws to obtain administrative access to collateral accounts. Rain upgraded programs using the affected contract version, while both platforms moved to reimburse customers; accounts differ over the precise timing and additional compensation. The incident has raised particular caution in South Korea, where the cards can be issued but affected domestic losses were not separately calculated and the products are not covered by the country's financial protections. CoinGecko said $3.633 billion was lost in 245 crypto-platform hacking and security incidents from January of the previous year through July, including at least $1 billion linked to smart-contract vulnerabilities. Global crypto-card payments reached 1.45 trillion won in August, more than triple the level a year earlier.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.