Person typing on a laptop displaying green computer code in a dark room, representing cybersecurity threats and hacking.
TECHNOLOGY

Rain Exploit Drains $1.1M From Card Users

Image credit: Shutterstock

A vulnerability in an outdated Rain Solana contract allowed an attacker to drain an estimated $1.1 million from card balances across multiple crypto payment programs on August 28.

Avici and Tria have confirmed $932,804 in combined losses affecting 2,321 users. Rain has since upgraded every program that used the vulnerable contract and says all affected cardholders have been reimbursed.

Outdated Rain Contract Gave Attacker Withdrawal Permissions

The flaw impacted Rain infrastructure used to hold collateral backing customers’ card spending. When users funded their cards, those assets moved from their wallets into separate on-chain collateral accounts.

The attacker exploited an authorization flaw in an older version of Rain’s Solana contract to grant itself withdrawal permissions over those accounts. It then repeated the process across individual users and removed their balances.

The attack did not compromise users’ self-custodial wallets or expose private keys. The vulnerable component was the separate Rain-managed contract holding funds allocated for card payments.

Rain said only a few programs were still using the outdated contract when the attack occurred.

Avici and Tria Confirm $932,804 Stolen From 2,321 Users 

Avici reported $500,859.22 drained from 1,685 card users. Tria separately identified $431,945 in unauthorized withdrawals impacting 636 customers. Those disclosures confirm at least $932,804.22 in losses. Blockaid’s broader on-chain analysis puts the total across Rain-powered programs at roughly $1.1 million.

The attacker converted stolen stablecoins into SOL, moved the funds from Solana to Ethereum and later routed the proceeds through Tornado Cash. Blockaid said the stolen assets reached the mixer and have not been recovered.

Rain Upgrades Contracts and Reimburses All Affected Cardholders 

Rain upgraded every program still running the vulnerable contract after identifying the flaw and reported no further unauthorized activity.

The company brought in third-party forensic specialists and said it is working with law enforcement and regulators. It has not published a final breakdown of the total amount stolen or identified every affected program.

Rain said by August 29 that all impacted cardholders had been reimbursed. Avici and Tria also confirmed repayments, with both programs adding an extra 10% for affected customers.

Rain has not yet published a full technical postmortem, while investigators are also tracing the attacker’s fund movements after the proceeds reached Ethereum.

More For You

OpenSea Adds Solana NFT Trading
BUSINESS

OpenSea Adds Solana NFT Trading

OpenSea now supports Solana NFTs, allowing users to buy and sell selected Solana collections…

Sep 2, 2026 2 min read
Explore More News