Security Risk Intelligence

Rain Card Protocol Exploit Drains $1.1 Million in Stablecoins from Solana Programs

According to reporting by crypto.news and blockchain security firm Blockaid, an outdated Rain contract on Solana suffered an exploit draining approximately $1.1 million from card collateral accounts. The incident, which is not officially confirmed by all affected entities in full, impacted neobanks including Avici and Tria while funds were moved through deBridge into Tornado Cash.

Solana card contract security breach analysis graphic
Image: crypto.news

Overview of the Solana Card Infrastructure Exploit

Recent reports from crypto.news outline a significant security breach affecting multiple stablecoin card programs operating on the Solana blockchain network. The incident reportedly took place when an attacker leveraged an outdated card contract maintained by infrastructure provider Rain, resulting in unauthorized withdrawals totaling approximately one million one hundred thousand dollars. Security researchers at Blockaid identified that several crypto neobanks and card issuing applications relied on vulnerable code deployments that had not been updated to the latest secure specifications before the malicious activity commenced.

The unauthorized withdrawals specifically targeted collateral accounts where users deposited stablecoins to fund their daily payment card balances, leaving personal self-custodial wallets untouched by the compromise. While blockchain operations on Solana continued smoothly without network-wide consensus disruptions, application-layer vulnerabilities permitted the extraction of funds across multiple separate deployments. Providers such as Avici and Tria subsequently disclosed substantial losses affecting hundreds of active customers, prompting immediate remediation efforts, security patches, and public assurances regarding full customer balance reimbursements across their respective platforms.

Technical Vector and Signature Verification Bypass

According to detailed analysis published by blockchain security specialists, the targeted Rain contract required two independent authorizations prior to permitting sensitive account actions through Solana instruction sets. The implementation utilized standard verification parameters to confirm required cryptographic signatures before executing administrative updates or asset withdrawals. Investigators discovered that the attacker successfully manipulated the second verification instruction by aligning its signature, public key, and message offsets with information drawn from the initial verification instruction. This manipulation effectively forced the vulnerable contract to accept a single attacker-controlled signature as two separate authorized approvals, circumventing security controls completely.

Once the signature check was successfully bypassed, the malicious actor utilized administrative instructions to grant itself elevated privileges over individual user collateral accounts. The attacker then executed automated withdrawal commands to transfer stablecoins out of the collateral pools at a rapid pace over a duration of approximately two and a half hours. Blockaid monitoring systems recorded thousands of core exploit transactions that drained balances without triggering any user-facing authorization requests or warnings. This automated execution demonstrates that the attackers prepared sophisticated scripts capable of targeting multiple shared deployments simultaneously upon discovering the outdated contract vulnerability.

Fund Laundering via Cross-Chain Protocols and Tornado Cash

Following the extraction of stablecoins from the vulnerable Solana card contracts, the accumulated assets were consolidated into a specific Solana wallet address controlled by the attacker. The perpetrator subsequently exchanged the stolen digital assets for native Solana tokens through decentralized trading venues to facilitate the cross-chain transfer process. Security analysts tracked the subsequent movement of these funds across different blockchain networks, noting that the stolen proceeds entered the deBridge cross-chain transfer protocol before being bridged over to the Ethereum network for further obfuscation.

Once the assets reached the Ethereum ecosystem, substantial amounts of the proceeds were deposited into Tornado Cash, a decentralized cryptocurrency mixer that pools deposits and obscures transaction histories. The use of this privacy-enhancing tool effectively broke the public traceability of the funds on the blockchain ledger, making recovery operations significantly more challenging for affected platforms and law enforcement agencies. Blockaid and other reporting entities noted that despite comprehensive onchain tracking efforts, the laundered funds remained unrecovered, underscoring the persistent difficulties associated with cross-chain laundering techniques employed by modern cyber attackers in the digital asset sector.

Impact on Issuing Neobanks and Market Reactions

The fallout from the Rain contract exploit directly affected several prominent crypto neobanks and card issuing platforms that utilized the shared infrastructure. Avici publicly disclosed that the attacker removed more than five hundred thousand dollars from card balances belonging to nearly seventeen hundred users, while Tria reported losing over four hundred thousand dollars across several hundred customer accounts. Both companies announced comprehensive reimbursement plans designed to make affected users whole, with Avici additionally offering supplementary cashback incentives to restore customer trust following the unexpected security incident.

Public reports and disclosures regarding the exploit triggered immediate negative reactions across digital asset markets, particularly affecting tokens associated with the impacted protocols. Market data indicated that Avici’s native token experienced a steep decline, shedding nearly half of its value from its daily high before achieving a partial recovery as management issued statements addressing the breach. Tria’s token also suffered notable downward pressure as traders reacted to the news of compromised collateral contracts, illustrating how infrastructure-level vulnerabilities can rapidly translate into token devaluation and reputational damage for participating fintech entities.

Conclusion and Infrastructure Security Outlook

In conclusion, the reported exploit of outdated Rain card contracts on the Solana blockchain resulted in an estimated one million one hundred thousand dollars in stablecoin losses across multiple neobank programs, affecting thousands of users. This finding is not officially confirmed by all involved administrative parties, and reported figures remain based on independent blockchain security analysis by Blockaid and statements from specific issuers like Avici and Tria. The affected entity is Rain as the infrastructure provider, alongside client platforms including Avici and Tria, while the affected user group comprises retail cardholders who deposited stablecoin collateral into the vulnerable programs.

What changes now is that card issuing platforms utilizing shared codebases must implement rigorous version tracking, continuous onchain monitoring, and automated upgrade verification to ensure outdated deployments are retired before malicious actors can exploit authorization flaws. The next action for users and protocol operators involves auditing active contract addresses, confirming that infrastructure updates have been successfully applied across all fleets, and maintaining heightened vigilance regarding collateral contract security until independent post-mortem reviews are officially completed.

Cexvia conclusion

Incident Conclusion and Next Monitoring Actions

The reported exploit targeted shared infrastructure provided by Rain, impacting thousands of users across Avici, Tria, and other crypto card programs. This finding is not officially confirmed across all deployment records, and investigations by security firms indicate that attackers bypassed authorization controls using manipulated signature verification instructions.

Risk meaning
This incident highlights systemic operational risks tied to shared infrastructure and outdated contract deployments in the crypto card sector. When stablecoin collateral accounts rely on third-party code implementations, any oversight in version upgrades or signature validation mechanisms can expose thousands of retail balances to automated exploits without compromising self-custodial wallets directly.
User action
Users utilizing crypto-funded payment cards should verify whether their service providers have completed infrastructure upgrades and secured collateral contracts. Account holders must monitor project communications regarding fund safety and assess whether alternative self-custodial options offer superior risk isolation for primary digital asset holdings.
Rain