Blockaid traced a Rain contract vulnerability on Solana that drained about $1.1 million from stablecoin card programs on Aug. 28, with Avici and Tria committing to reimbursements.
Blockaid traced a Rain contract vulnerability on Solana that drained about $1.1 million from stablecoin card programs on Aug. 28, with Avici and Tria committing to reimbursements.

An attacker drained about $1.1 million from Solana stablecoin card programs on Aug. 28 by exploiting an outdated Rain contract, security firm Blockaid reported.
Blockaid traced the stolen funds from Solana to Ethereum through the deBridge cross-chain protocol, with roughly 455.9 ETH entering Tornado Cash between 19:20 and 19:49 UTC, the security firm said.
The vulnerable contract required two independent approvals before certain account actions, using Solana's Ed25519 verification system. The attacker reused one signature so it appeared as two separate approvals, bypassing the requirement without account owner permission. It then granted itself admin access and withdrew USDC and USDT, recording 2,945 admin additions and 5,288 withdrawal calls across 8,233 transactions over roughly two and a half hours.
Avici reported $500,859 drained from 1,685 users, while Tria identified $431,945 affecting 636 customers. Both said they would reimburse affected users. Rain said every program using the vulnerable contract version has been upgraded since the attack.
Rain provides infrastructure that lets crypto companies issue cards funded with stablecoins. Customer deposits move into collateral accounts controlled by onchain contracts, separate from users' personal wallets. Blockaid identified four contract deployments sharing the same code as the flawed version, with the attacker draining funds from at least two of them.
The first two withdrawals occurred three seconds apart, suggesting the attacker had built an automated system to target many accounts quickly. The stolen stablecoins were consolidated into one Solana wallet before being swapped for SOL through decentralized exchanges. Customers' self-custodial wallets were not compromised, as the attacker targeted separate contracts holding funded card balances.
Avici's token fell 49 percent from its daily high after news of the exploit spread, reaching a low of $0.217 before partially recovering. Tria's token also declined more than 10 percent at one point. Blockaid also named Solayer Pay as an affected program, though no confirmed loss figure was available. The gap between disclosed losses and Blockaid's $1.1 million estimate has not been fully explained.
Rain said its monitoring systems discovered the vulnerability affecting a "small number of programs" using an outdated version of its Solana card contract. The company has not released a full technical report or explained why older contract versions remained in use. The incident adds to wider concerns about contract security, with crypto security failures causing approximately $1.1 billion in losses during the first half of 2026, according to Blockaid research. Blockaid connected two Ethereum addresses to the initial financing of the attacker's Solana activity, though neither Rain nor law enforcement has publicly identified who controls them.
This article is for informational purposes only and does not constitute investment advice.