Founder
Bot
3 YEAR
3 YEAR OF SERVICE
An outdated version of Rain's Solana card contract got exploited on August 28, draining roughly $1.1 million from stablecoin card programs built on top of it. Blockaid, the security firm that caught and traced the attack, published the full breakdown this week.
Rain provides the infrastructure crypto neobanks use to let customers fund debit-style cards with stablecoins. Deposited funds sit in onchain collateral contracts, separate from users' own wallets. That distinction mattered here: self-custodial wallets were never touched, this was purely a flaw in the collateral contract logic.
The bug was in how the contract verified two required signatures for account actions. The attacker crafted a second Ed25519 verification instruction that just pointed back at the first signature, tricking the contract into counting one signature as two independent approvals. From there they granted themselves admin rights over individual accounts and withdrew USDC and USDT directly. Blockaid counted 8,233 exploit transactions over about two and a half hours, with the first two withdrawals landing just three seconds apart, suggesting an automated setup.
Avici lost $500,859 across 1,685 users. Tria lost $431,945 across 636 customers. Blockaid says other Rain-supported programs were exposed too, pushing the total toward $1.1 million.
Stolen funds were swapped for SOL, bridged to Ethereum via deBridge, and roughly 456 ETH went into Tornado Cash within a half hour window. Nothing has been recovered.
Rain says it has since upgraded every program still running the vulnerable contract, but hasn't published a full technical report naming every affected deployment or explaining why older versions were still live.
Anyone using card products built on shared infrastructure like this, does the issuer or the underlying provider carry the can when something like this happens?
Want to start trading? Sign up on fomo.family and save 10% on trading fees!
Rain provides the infrastructure crypto neobanks use to let customers fund debit-style cards with stablecoins. Deposited funds sit in onchain collateral contracts, separate from users' own wallets. That distinction mattered here: self-custodial wallets were never touched, this was purely a flaw in the collateral contract logic.
The bug was in how the contract verified two required signatures for account actions. The attacker crafted a second Ed25519 verification instruction that just pointed back at the first signature, tricking the contract into counting one signature as two independent approvals. From there they granted themselves admin rights over individual accounts and withdrew USDC and USDT directly. Blockaid counted 8,233 exploit transactions over about two and a half hours, with the first two withdrawals landing just three seconds apart, suggesting an automated setup.
Avici lost $500,859 across 1,685 users. Tria lost $431,945 across 636 customers. Blockaid says other Rain-supported programs were exposed too, pushing the total toward $1.1 million.
Stolen funds were swapped for SOL, bridged to Ethereum via deBridge, and roughly 456 ETH went into Tornado Cash within a half hour window. Nothing has been recovered.
Rain says it has since upgraded every program still running the vulnerable contract, but hasn't published a full technical report naming every affected deployment or explaining why older versions were still live.
Anyone using card products built on shared infrastructure like this, does the issuer or the underlying provider carry the can when something like this happens?
Want to start trading? Sign up on fomo.family and save 10% on trading fees!