Close Menu
xpertsstudio

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Ripple’s Schwartz Backs $42.4M Tether Freeze as XRP Highlights Stablecoin Divide

    September 3, 2026

    Breaking Down ‘Loop Engineering’ and New AI Jargon

    September 3, 2026

    Anthropic’s Claude Mythos AI Sparks Crypto Security Concerns

    September 3, 2026
    Facebook Instagram YouTube WhatsApp TikTok Telegram
    xpertsstudio
    Facebook Instagram YouTube WhatsApp TikTok Telegram
    • Home
    • DeFi News
    • Altcoin News
    • Bitcoin News
    • Ethereum News
    • Crypto Business
    • More
      • Blockchain & Web3
      • Crypto Regulation
      • Crypto Markets
    xpertsstudio
    Home»Crypto Business»Rain contract exploit drains $1.1M from card users
    September 3, 20260 Views

    Rain contract exploit drains $1.1M from card users

    EditorBy EditorSeptember 3, 2026No Comments6 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
    Follow Us
    Google News Flipboard
    Rain contract exploit drains $1.1M from card users
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Don't want to trade it yourself?

    Our desk runs DEX portfolios on profit share.

    35% Share
    $2.5K Minimum
    Learn more

    An attacker exploited an outdated Rain card contract on Aug. 28, draining approximately $1.1 million from multiple stablecoin card programs operating on Solana, according to blockchain security company Blockaid.

    Avici and Tria were among the affected crypto neobanks. The two companies disclosed combined losses of more than $932,800 across 2,321 users. Blockaid said other Rain-supported programs were also exposed, bringing the estimated loss to approximately $1.1 million.

    The attacker did not access customers’ self-custodial wallets or private keys. Instead, the exploit targeted collateral contracts holding stablecoins that users had deposited to fund their card balances.

    Rain said its monitoring systems discovered a vulnerability affecting a “small number of programs” using an outdated version of its Solana card contract. The company upgraded every program still running the affected version, according to its public statement.

    The incident adds to wider concerns about contract and operational vulnerabilities. Crypto security failures caused approximately $1.1 billion in losses during the first half of 2026, according to research

    Rain contract flaw exposed shared card infrastructure

    Rain provides infrastructure that allows crypto companies to issue cards funded with stablecoins. When customers fund their cards, the deposited assets move into collateral accounts managed through onchain contracts.

    These balances are separate from assets held inside customers’ personal wallets. Once funds enter a card collateral contract, their security depends on the infrastructure provider’s code and authorization controls.

    Blockaid identified four deployments containing code with the same opcode hash as the vulnerable contract. The security company said the attacker drained at least two deployments. The other two reportedly carried the same vulnerability but had no confirmed losses.

    Rain confirmed that an outdated contract caused the incident. However, it has not published a complete technical report identifying every affected deployment or explaining why some programs continued using the older version.

    The situation resembles other incidents in which outdated or repeatedly vulnerable infrastructure remained active. In related coverage, attackers exploited the same Verus bridge contract twice within two months, raising similar questions about upgrades across shared deployments.

    The Rain incident did not represent a compromise of Solana itself. The blockchain continued processing transactions normally while the attacker exploited application code deployed on the network.

    Reused signature bypassed withdrawal controls

    The outdated Rain contract required two independent authorizations before allowing certain account actions. It used Solana’s Ed25519 verification instructions to confirm the required signatures.

    According to Blockaid’s analysis, the attacker manipulated the second verification instruction. Its signature, public key and message offsets pointed back to information contained in the first instruction.

    The vulnerable contract therefore accepted one attacker-controlled signature as two independent approvals. This allowed the attacker to satisfy the authorization requirement without permission from the owners of the collateral accounts.

    After bypassing the signature check, the attacker used an AddCollateralAdmin instruction to give itself administrative privileges over individual accounts. It then called WithdrawCollateralAsset to transfer $USDC and $USDT from those accounts.

    Blockaid recorded 2,945 administrator additions and 5,288 withdrawal calls. The company identified 8,233 core exploit transactions over approximately two hours and 29 minutes.

    The operation proceeded at an automated pace. Blockaid said the first two successful withdrawals occurred three seconds apart, indicating that the attacker had prepared a system for targeting multiple accounts.

    Customers did not authorize the malicious transactions. The exploit occurred at the contract level, meaning protections against phishing or malicious wallet signatures would not have prevented these withdrawals.

    A different application-level weakness recently exposed another protocol when faulty collateral controls enabled a $75 million DeFi exploit. In both cases, the underlying networks continued operating while application logic allowed unauthorized activity.

    Attacker moved funds through deBridge

    The withdrawn $USDC and $USDT accumulated in one Solana wallet identified as FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj.

    The attacker exchanged the stablecoins for SOL through decentralized trading platforms. Blockaid then traced the proceeds from Solana to Ethereum through the deBridge cross-chain protocol.

    Approximately 455.9 ETH entered Tornado Cash between 19:20 and 19:49 UTC Tornado Cash pools deposits and permits withdrawals to addresses that are not publicly connected to the original sending wallets

    The mixer therefore made subsequent movements harder to trace through public blockchain records. Blockaid said the stolen funds had not been recovered after entering Tornado Cash.

    The use of cross-chain infrastructure added another stage to the laundering route. Crypto bridges have also become direct <a href="https://xpertsstudio.com/can-eth-hit-5000-as-apeing-targets-the-next-crypto-to-explode/” title=”Can ETH Hit $5,000 as Apeing Targets the Next Crypto to Explode?”>targets, with a forged transfer exploit draining $11.5 million from the Verus Ethereum bridge earlier in 2026.

    Blockaid connected two Ethereum addresses to the initial financing of the Rain attacker’s Solana activity. Neither Rain nor law enforcement authorities have publicly identified the people controlling those addresses.

    The company’s statements about detecting the attack and tracing the funds represent its own findings. Blockaid provides security and monitoring services to crypto companies, including stablecoin card issuers.

    Avici and Tria disclose customer losses

    Avici reported that the attacker removed $500,859.22 from card balances belonging to 1,685 users. The company said it refunded all affected customers and provided 10% cashback following the incident.

    Tria disclosed approximately $431,945 in losses across 636 customers. It said in an official update that each affected customer was being reimbursed.

    The two disclosures account for $932,804.22 of the estimated losses. Blockaid also named Solayer Pay as an affected program, but no independently verified figure for its losses was available.

    The difference between the disclosed Avici and Tria losses and Blockaid’s $1.1 million estimate appears to involve other Rain-supported programs. A complete breakdown has not been published.

    Avici’s token fell 49% from its daily high after reports of the exploit emerged, according to market data. The token reached a reported low of $0.217 before partially recovering. Tria’s token also declined by more than 10% at one point.

    Those price movements followed public reports of the attack, although broader market conditions may also have influenced trading.

    Rain upgrades affected contract deployments

    Rain said all card programs using the outdated contract had been upgraded. The company reported no additional unauthorized activity after completing the changes.

    It also said affected users would be made whole. Rain has not disclosed whether it will reimburse card programs directly or whether individual providers will carry the costs.

    Several questions remain unanswered. Rain has not released the vulnerable contract’s full version history, the date the flaw was introduced or the reason older deployments remained active.

    The company also has not disclosed whether an audit identified the authorization flaw before the attack. No recovery of the funds deposited into Tornado Cash has been publicly reported.

    The episode renews questions about whether periodic audits provide enough protection after contracts enter production. Recent industry research found that institutions increasingly want continuous monitoring alongside traditional security audits, particularly for contracts holding user assets.

    A detailed technical report would allow outside researchers to confirm the vulnerability and determine whether similar code remains active elsewhere. Card providers may also review how they track contract versions and limit administrative permissions across shared infrastructure.

    Users can retain control of their personal wallets while still facing risks after depositing funds into a card program. The security of those balances depends on the contracts holding the collateral, the provider maintaining them and the operators responding when vulnerabilities emerge.

    Source: cryptonews.net

    Partner offer

    Start trading on Bybit

    Deep derivatives liquidity, tight spreads, and a deposit bonus on your first funding.

    Claim bonus
    Contract Drains Exploit From RAIN
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    K
    Mentioned in this article

    KuCoin

    Spot, futures and trading bots in one account. Our link applies a fee discount at signup.

    Open account

    Related Posts

    Coinbase Appoints Former Morgan Stanley, Musk Executive Anthony Armstrong to Board

    September 3, 2026

    Crypto Overview Shows Institutions Are All In as Pepeto’s Early Entry Gains Momentum

    September 3, 2026

    Coinbase co-founder joins rush for Venezuelan oil assets under new US

    September 3, 2026
    Leave A Reply Cancel Reply

    Accepting new clients

    Portfolio Management

    Managed trading on centralised and decentralised markets, handled by our experienced trading desk.

    Professional crypto trading management
    Profit share 35%
    Min. capital $2,500
    Wallet Set up by us
    Execution Full service
    How the service works
    • New to on-chain trading? Our team runs it for you on a profit-sharing basis.
    • We create the wallet and place every trade — no DEX experience needed on your side.
    • The share is 35% of profit on each token traded.
    • Minimum starting capital is $2,500.
    Start DEX Management
    Profit share 00%
    Min. capital $0,000
    Custody Your account
    Execution Full service
    How the service works
    • Your funds remain in your own exchange account while our team manages the trading activity.
    • You maintain control of your account and funds throughout the management period.
    • We provide professional trading management based on the agreed strategy and terms.
    • Works with KuCoin, MEXC, Bybit and Phemex.
    • Receive a monthly report covering positions, trading activity and performance.
    CEX management terms, profit split and minimum capital are agreed in writing before onboarding.
    Apply for CEX Management

    Not financial advice. Crypto trading involves substantial risk and past results do not guarantee future returns. Capital can be lost in full. Full terms are agreed in writing before onboarding.

    Trusted Exchanges

    5

    Open an account through our partner links to claim fee discounts and sign-up bonuses.

    K KuCoin Spot & futures · trading fee discount M MEXC Widest altcoin listings · low maker fees B Blofin Copy trading · no-KYC onboarding Y Bybit Deep derivatives liquidity · deposit bonus P Phemex Contract trading · zero-fee spot plan

    Affiliate disclosure: We may earn a commission when you sign up through these links, at no extra cost to you. Trading carries risk — never invest more than you can afford to lose.

    Top Posts

    XRP Price to $0.18? Analysts Warn of Drop as Brad Garlinghouse Bets on Ripple’s Crypto Winter

    August 19, 20264 Views

    Crypto Weekly Winners and Losers: VET, RAIN, STABLE, ARB

    August 30, 20262 Views

    Term Finance Loses $8.5M In Ethereum Governance Attack

    August 23, 20262 Views
    0% Spot fees

    Phemex zero-fee spot plan

    Sign up with our referral code to activate the plan on a new account.

    CODE · E4G2K
    Redeem
    Most Popular

    XRP Price to $0.18? Analysts Warn of Drop as Brad Garlinghouse Bets on Ripple’s Crypto Winter

    August 19, 20264 Views

    Crypto Weekly Winners and Losers: VET, RAIN, STABLE, ARB

    August 30, 20262 Views

    Term Finance Loses $8.5M In Ethereum Governance Attack

    August 23, 20262 Views
    Our Picks

    Ripple’s Schwartz Backs $42.4M Tether Freeze as XRP Highlights Stablecoin Divide

    September 3, 2026

    Breaking Down ‘Loop Engineering’ and New AI Jargon

    September 3, 2026

    Anthropic’s Claude Mythos AI Sparks Crypto Security Concerns

    September 3, 2026

    Stay Ahead of Crypto

    Get the latest crypto, blockchain, and Web3 news delivered straight to your inbox.

    Facebook Instagram YouTube WhatsApp TikTok Telegram
    • About Us
    • Contact us
    • Disclaimer
    • Privacy Policy
    • Terms & Conditions
    © 2026 Xperts Studio. Develop by Pro

    Type above and press Enter to search. Press Esc to cancel.