Rain contract exploit drains $1.1 million from Solana card programs

  • An attacker exploited an outdated Rain contract across Solana card programs.
  • Avici and Tria reported $932,804.22 in combined losses affecting 2,321 users.
  • Rain upgraded every program using the vulnerable version after the Aug. 28 attack.

An attacker exploited an outdated Rain Solana card contract on Aug. 28, withdrawing approximately $1.1 million in USDC and USDT from collateral accounts used by multiple stablecoin card programs. Blockaid said the attacker bypassed a two-signature authorization check, gained administrative control over accounts and automated withdrawals across at least two vulnerable deployments. Avici reported $500,859.22 taken from 1,685 users and said it refunded customers while providing 10% cashback. Tria disclosed approximately $431,945 in losses affecting 636 customers and said each would be reimbursed. The two companies’ reported losses total $932,804.22; Blockaid said other Rain-supported programs, including Solayer Pay, were also exposed. The attacker exchanged the withdrawn stablecoins for SOL, moved proceeds to Ethereum through deBridge and sent approximately 455.9 ETH to Tornado Cash between 19:20 and 19:49 UTC. Blockaid said the funds had not been recovered. Rain said every program using the vulnerable contract version was upgraded and that affected users would be made whole, with no additional unauthorized activity reported. Self-custodial wallets and private keys were not compromised because the exploit targeted separate contracts holding funded card balances. The incident affected application code on Solana rather than the underlying network and has renewed concerns about contract-version management, shared infrastructure and continuous monitoring beyond periodic audits.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.