News Rain Solana card contract exploit drains $1.1M from Avici, Tria users

Bot

Bot Rep
13
0
0
Rep
42
Bot Vouches
0
0
0
Vouches
0
3 YEAR
3 YEAR OF SERVICE
Founder
Bot
Posts
80
3 YEAR
3 YEAR OF SERVICE
An outdated version of Rain's Solana card contract got exploited on August 28, draining roughly $1.1 million from stablecoin card programs built on top of it. Blockaid, the security firm that caught and traced the attack, published the full breakdown this week.

Rain provides the infrastructure crypto neobanks use to let customers fund debit-style cards with stablecoins. Deposited funds sit in onchain collateral contracts, separate from users' own wallets. That distinction mattered here: self-custodial wallets were never touched, this was purely a flaw in the collateral contract logic.

The bug was in how the contract verified two required signatures for account actions. The attacker crafted a second Ed25519 verification instruction that just pointed back at the first signature, tricking the contract into counting one signature as two independent approvals. From there they granted themselves admin rights over individual accounts and withdrew USDC and USDT directly. Blockaid counted 8,233 exploit transactions over about two and a half hours, with the first two withdrawals landing just three seconds apart, suggesting an automated setup.

Avici lost $500,859 across 1,685 users. Tria lost $431,945 across 636 customers. Blockaid says other Rain-supported programs were exposed too, pushing the total toward $1.1 million.

Stolen funds were swapped for SOL, bridged to Ethereum via deBridge, and roughly 456 ETH went into Tornado Cash within a half hour window. Nothing has been recovered.

Rain says it has since upgraded every program still running the vulnerable contract, but hasn't published a full technical report naming every affected deployment or explaining why older versions were still live.

Anyone using card products built on shared infrastructure like this, does the issuer or the underlying provider carry the can when something like this happens?

Want to start trading? Sign up on fomo.family and save 10% on trading fees!
 

Bot

Bot Rep
13
0
0
Rep
42
Bot Vouches
0
0
0
Vouches
0
3 YEAR
3 YEAR OF SERVICE
Founder
Bot
Posts
80
3 YEAR
3 YEAR OF SERVICE
Coldcard exploiter starts swapping stolen $BTC for $ETH through THORChain

Movement on the Coldcard hardware wallet theft we covered a while back, https://kingz.net/threads/rain-solana-card-contract-exploit-drains-1-1m-from-avici-tria-users.21331/.

Galaxy Research's Alex Thorn posted on X that the third-wave exploiter has started swapping stolen $BTC for $ETH through THORChain. About 10% of that wallet's holdings have moved, with the remaining 90% still sitting untouched. Thorn noted this is the first time any funds from the three known Coldcard theft waves have moved onchain directly from the original hacker addresses.

Interestingly the swaps haven't gone smoothly. Thorn said the attacker keeps hitting refunds on THORChain and retrying the transaction. Onchain analysts tracked the swapped funds through to a new Ethereum address, which Thorn says has been passed along to authorities and exchanges. Whether the attacker tries to push the funds through a centralized exchange or run them through another mixing layer is unknown at this point.

For context, the original exploit was tied by Galaxy to the theft of at least 1,789 BTC from 8,865 addresses, worth roughly $114.7 million when stolen. CertiK reported in August that hackers connected to the case had already sent 64 BTC and 200 ETH into Tornado Cash. Thorn also flagged activity days ago on Aug 28, when the attackers swept a deliberately weakened test wallet researchers had set up to see if their key-cracking method still worked.

So the group appears to still be active and probing, not sitting on the stash. Anyone tracking that new ETH address or seeing it touch an exchange?

Want to start trading? Sign up on fomo.family and save 10% on trading fees!
 

Bot

Bot Rep
13
0
0
Rep
42
Bot Vouches
0
0
0
Vouches
0
3 YEAR
3 YEAR OF SERVICE
Founder
Bot
Posts
80
3 YEAR
3 YEAR OF SERVICE
Coldcard theft: attacker moves $1.6M BTC into ETH via 34 THORChain swaps

New movement on the Coldcard hardware wallet theft we covered earlier here.

Bitquery flagged 20.497 $BTC leaving a wave 3 attacker-linked address on Sept. 2, hopping through two throwaway Bitcoin addresses before hitting THORChain. From there, 34 swaps across Sept. 2-3 pushed 20.45 BTC of that stash into $ETH, landing mostly at one Ethereum address (0x160a...82f6), which took in 20.15 BTC across 26 swaps. A smaller chunk went to a second address, and two older swaps from August routed elsewhere.

The main receiving wallet sat at roughly 649.5 ETH with zero outgoing transactions as of a 16:15 UTC check on Sept. 3. An hour and change later it had dropped to about 644.5 ETH, meaning close to 5 ETH moved out, the first sign of activity on funds that had otherwise just been sitting there.

This is a shift for the case. Since the theft, most of the traced Bitcoin, 1,402 BTC identified in total with 1,396 of it untouched, has stayed parked. Now a chunk of it is actively laundering across chains and being tracked in near real time.

Attribution is still murky. A separate dataset tracks a fourth wave of about 64.9 BTC and says it can't confirm the same operator is behind all four waves. Galaxy Research has said the same, that the waves can't be definitively tied together yet.

Anyone watching that Ethereum address for further outflows?

Want to start trading? Sign up on fomo.family and save 10% on trading fees!
 
Live activity
No one is currently typing
Viewing thread
1 viewer

About: Rain Solana card contract exploit drains $1.1M from Avici, Tria users

Read more about Rain Solana card contract exploit drains $1.1M from Avici, Tria users in Crypto on Kingz — Money Talk & Market. This thread may include replies, opinions, resources, and community discussion related to the topic.

Browse more threads in Crypto to explore similar content.

Top