Rain Card Contract (2026) — Crypto Hack
Fully RecoveredAttacker exploited an outdated version of Rain's Solana card-collateral contract, repeatedly submitting signed authorizations to register themselves as admin and withdraw card balances from Avici and Tria users (~$1.1M).
Summary
Attacker exploited an outdated version of Rain's Solana card-collateral contract, repeatedly submitting signed authorizations to register themselves as admin and withdraw card balances from Avici and Tria users (~$1.1M).
How It Was Compromised — Wallet via Legacy Contract Loophole / Admin Privilege Escalation
On August 28, 2026, an attacker exploited a vulnerability in an outdated version of Rain's Solana card-collateral contracts (used by a small number of card programs including Avici and Tria). The attacker signed 14,672 transactions (2,344 failed) repeating a three-instruction pattern: SubmitSignatures on the authorization program, then AddCollateralAdmin and WithdrawCollateralAsset on the collateral program — registering itself as an administrator on users' card-collateral accounts and withdrawing balances. Avici lost $500,859.22 from 1,685 users; Tria lost $431,945 from 636 users; onchain tracking showed ~10,000 SOL (~$1.07M) moved. Rain upgraded every program running the vulnerable version, engaged third-party forensics, and all affected users were made whole within 24 hours (Avici and Tria added a 10% credit). Self-custodial wallets were untouched.
Fund Flow & Laundering Analysis
Stolen stablecoins were swapped to SOL, bridged to Ethereum, and routed through the Tornado Cash mixer. Avici filed a complaint with the FBI's IC3.