Latest Crypto News | Token Chronicles
  • Artificial Intelligence
    • AI & Crypto
    • AI News
    • AI Tools & Apps
    • Machine Learning
  • Crypto
    • Projects & Launches
    • IDOs & Presales
    • Altcoin
    • Bitcoin
    • DeFi & Web3
    • Exchanges & Trading
    • Market Analysis
    • Regulations & Policies
    • NFTs
  • Fundraising
  • Research
    • Crypto & AI Insights
    • Industry Trends
    • Market Reports
    • On-Chain Analysis
    • Project Deep Dives
    • Tokenomics
  • Sponsored
No Result
View All Result
  • Artificial Intelligence
    • AI & Crypto
    • AI News
    • AI Tools & Apps
    • Machine Learning
  • Crypto
    • Projects & Launches
    • IDOs & Presales
    • Altcoin
    • Bitcoin
    • DeFi & Web3
    • Exchanges & Trading
    • Market Analysis
    • Regulations & Policies
    • NFTs
  • Fundraising
  • Research
    • Crypto & AI Insights
    • Industry Trends
    • Market Reports
    • On-Chain Analysis
    • Project Deep Dives
    • Tokenomics
  • Sponsored
No Result
View All Result
Latest Crypto News | Token Chronicles
No Result
View All Result
Home Crypto

Rain Card Contract Exploit Drains $1.1M in Stablecoins From Users

Gavin by Gavin
September 3, 2026
in Crypto
Reading Time: 7 mins read
Rain Card Contract Exploit Drains $1.1M in Stablecoins From Users

A vulnerability in an outdated Rain card contract on Solana allowed an attacker to bypass withdrawal protections and remove roughly $1.1 million in stablecoins from several crypto card programs. The incident affected funded card balances rather than customers’ personal self-custodial wallets, highlighting the risks created by shared smart-contract infrastructure.

  • An outdated Rain contract enabled unauthorized withdrawals from card collateral accounts.
  • Blockaid estimates total losses at approximately $1.1 million.
  • Avici reported about $500,859 lost across 1,685 users, while Tria reported roughly $431,945 affecting 636 customers.
  • The attacker converted the stolen stablecoins and moved part of the funds from Solana to Ethereum.
  • Rain says programs using the vulnerable contract version have been upgraded.
  • Customers’ self-custodial wallets and private keys were not compromised.

Outdated Rain Contract Exposed Card Collateral

The attack occurred on Aug. 28 and involved a vulnerability in an older version of Rain’s Solana-based card infrastructure.

Rain provides technology that allows crypto companies to offer payment cards funded with digital assets such as USDC and USDT. When customers deposit stablecoins to fund their cards, those assets can be held within dedicated collateral contracts rather than remaining in the users’ personal wallets.

That distinction became critical during the incident.

According to blockchain security firm Blockaid, the attacker exploited outdated contracts responsible for managing those collateral balances. The resulting losses affected multiple programs using Rain’s infrastructure.

Rain subsequently said it had identified the vulnerability and upgraded programs that were still operating with the affected contract version.

The company has stated that users will be compensated, although a complete breakdown of the total losses and reimbursement arrangements has not yet been publicly provided.

Attack Bypassed a Two-Signature Security Check

Blockaid’s analysis indicates that the vulnerability involved the way the older contract validated transaction signatures.

The affected contract was designed to require two separate authorizations for certain sensitive operations. It relied on Solana’s Ed25519 signature-verification instructions to establish that the required approvals were legitimate.

The attacker found a way to manipulate the verification process so that information associated with one signature could effectively be reused as if it represented a second authorization.

As a result, the contract incorrectly accepted an attacker-controlled signature as satisfying both approval requirements.

After defeating the authorization check, the attacker was able to assign administrative privileges to targeted collateral accounts and subsequently initiate withdrawals.

The stolen assets included USDC and USDT, which were transferred from accounts holding stablecoins used to support customers’ card balances.

This was therefore not an attack on Solana’s underlying blockchain. The network itself continued operating normally; the weakness existed in application-level smart-contract code deployed on the network.

Thousands of Exploit Transactions Were Recorded

Blockaid identified extensive activity during the attack.

Its analysis recorded thousands of administrative-permission changes and withdrawal operations, with the attacker moving rapidly between affected accounts.

The security firm identified 8,233 core exploit transactions over roughly two and a half hours.

The speed of the operation suggests that much of the process was automated. Blockaid said the first successful withdrawals were separated by only a few seconds, indicating that the attacker had prepared infrastructure capable of targeting multiple accounts in quick succession.

The incident demonstrates why vulnerabilities in shared infrastructure can have a broader impact than an isolated smart-contract failure. A single flaw can potentially expose multiple applications that rely on the same underlying technology.

Avici and Tria Report More Than $932,000 in Combined Losses

Two affected crypto-financial platforms have publicly disclosed customer losses.

Avici reported that approximately $500,859 was taken from card balances belonging to 1,685 users. The company said it reimbursed affected customers and also offered 10% cashback following the incident.

Tria separately reported approximately $431,945 in losses involving 636 customers and said affected users would be reimbursed.

Together, the two incidents represent approximately $932,804.

Blockaid’s broader estimate places the total amount stolen at around $1.1 million, suggesting that additional affected Rain-supported programs may account for the remaining losses.

Solayer Pay was also identified as an affected program, although a separately verified loss figure was not available.

The different figures illustrate that the full financial impact cannot yet be independently reconciled from the publicly disclosed information.

Stolen Stablecoins Were Converted and Bridged to Ethereum

After withdrawing the assets, the attacker consolidated the stolen USDC and USDT in a Solana address.

The stablecoins were subsequently exchanged for SOL through decentralized trading platforms.

Blockaid then traced the movement of the funds from Solana to Ethereum through the deBridge cross-chain infrastructure.

Approximately 455.9 ETH was later transferred into Tornado Cash over a short period, according to Blockaid.

Tornado Cash is designed to make the connection between deposits and subsequent withdrawals less straightforward on public blockchains. Moving assets through cross-chain infrastructure and mixing services can therefore make forensic tracing more difficult.

Blockaid said the stolen funds had not been recovered at the time of its analysis.

Self-Custody Wallets Were Not Directly Affected

One of the most important distinctions from the incident is that customers’ personal wallets were not compromised.

The attacker did not obtain users’ private keys or directly drain their self-custodied crypto holdings.

Instead, the exploit targeted smart contracts responsible for holding stablecoins that had already been deposited into card programs.

This creates an important security consideration for crypto payment users.

A person can maintain strong security practices around a personal wallet while still being exposed to risks after transferring assets into another application’s smart contract.

Once funds enter a third-party contract, their safety depends not only on the user’s wallet security but also on the contract’s code, authorization mechanisms, upgrade procedures and monitoring systems.

Rain Upgrades Vulnerable Deployments

Rain said it had upgraded every card program still using the affected contract version following the attack.

The company also indicated that no further unauthorized activity had been detected after the upgrades and that affected users would be made whole.

However, several technical questions remain open.

Rain has not publicly provided a complete history of the vulnerable contract, explained exactly when the flaw was introduced or detailed why older deployments remained active.

It has also not disclosed whether previous security audits identified the authorization weakness.

A comprehensive technical postmortem could help independent researchers determine the full scope of the vulnerability and establish whether similar versions of the code remain deployed elsewhere.

The Incident Highlights the Limits of Smart-Contract Security

The Rain exploit adds to a broader pattern of security incidents involving decentralized applications and shared blockchain infrastructure.

Traditional security audits can identify vulnerabilities before deployment, but production environments can change over time. Older contract versions may remain operational, new integrations can introduce additional risks, and attackers can discover weaknesses that were not identified during earlier reviews.

For platforms holding customer assets, continuous monitoring and contract-version management can therefore be just as important as the original security audit.

The Rain incident also illustrates the difference between blockchain security and application security.

Solana itself was not compromised. Instead, an application running on the network contained flawed authorization logic that allowed an attacker to gain control over protected balances.

The episode serves as a reminder that crypto users face risks beyond private-key theft. Even when personal wallets remain secure, assets deposited into payment platforms, DeFi protocols or other smart contracts can become vulnerable if the underlying infrastructure contains an overlooked flaw. For companies building financial products on public blockchains, keeping deployed contracts updated, continuously monitoring them and rapidly responding to vulnerabilities are becoming essential parts of protecting user funds.

Share this:

  • Share on X (Opens in new window) X
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Facebook (Opens in new window) Facebook

Related

Previous Post

Kalshi Plans WTI Perpetual Futures as It Expands Beyond Crypto

Next Post

Hyperscale Data Ends Michigan Bitcoin Mining as BTC Holdings Plunge 79%

Gavin

Gavin

Next Post
Hyperscale Data Ends Michigan Bitcoin Mining as BTC Holdings Plunge 79%

Hyperscale Data Ends Michigan Bitcoin Mining as BTC Holdings Plunge 79%

Latest Crypto News | Token Chronicles

We bring you the latest news in crypto and AI. Get to know about the latest IDOs, presale and launches.

Follow Us

Browse by Category

  • AI & Crypto
  • AI News
  • AI Tools & Apps
  • Altcoin
  • Artificial Intelligence
  • Bitcoin
  • Crypto
  • Crypto & AI Insights
  • DeFi & Web3
  • Exchanges & Trading
  • Fundraising
  • IDOs & Presales
  • Market Analysis
  • Market Reports
  • NFTs
  • On-Chain Analysis
  • Projects & Launches
  • Regulations & Policies
  • Research
  • Sponsored
  • Uncategorized
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2026 Token Chronicles - Latest IDO, Presale and Launch news by Token Chronicles.

No Result
View All Result
  • Artificial Intelligence
    • AI & Crypto
    • AI News
    • AI Tools & Apps
    • Machine Learning
  • Crypto
    • Projects & Launches
    • IDOs & Presales
    • Altcoin
    • Bitcoin
    • DeFi & Web3
    • Exchanges & Trading
    • Market Analysis
    • Regulations & Policies
    • NFTs
  • Fundraising
  • Research
    • Crypto & AI Insights
    • Industry Trends
    • Market Reports
    • On-Chain Analysis
    • Project Deep Dives
    • Tokenomics
  • Sponsored

© 2026 Token Chronicles - Latest IDO, Presale and Launch news by Token Chronicles.

Discover more from Latest Crypto News | Token Chronicles

Subscribe now to keep reading and get access to the full archive.

Continue reading