An attacker exploited an outdated Rain Solana card contract on Aug. 28, withdrawing approximately $1.1 million in USDC and USDT from collateral accounts used by multiple stablecoin card programs. Blockaid said the attacker bypassed a two-signature authorization check, gained administrative control over accounts and automated withdrawals across at least two vulnerable deployments. Avici reported $500,859.22 taken from 1,685 users and said it refunded customers while providing 10% cashback. Tria disclosed approximately $431,945 in losses affecting 636 customers and said each would be reimbursed. The two companies’ reported losses total $932,804.22; Blockaid said other Rain-supported programs, including Solayer Pay, were also exposed. The attacker exchanged the withdrawn stablecoins for SOL, moved proceeds to Ethereum through deBridge and sent approximately 455.9 ETH to Tornado Cash between 19:20 and 19:49 UTC. Blockaid said the funds had not been recovered. Rain said every program using the vulnerable contract version was upgraded and that affected users would be made whole, with no additional unauthorized activity reported. Self-custodial wallets and private keys were not compromised because the exploit targeted separate contracts holding funded card balances. The incident affected application code on Solana rather than the underlying network and has renewed concerns about contract-version management, shared infrastructure and continuous monitoring beyond periodic audits.