Logo Daily Crypto Briefs
Open menu

Rain Card Exploit Drains $1.1M From Stablecoin Neobanks

6 min read
Breaking News
Large official bright-pink Rain wordmark beside a greyscale unbranded payment card and open collateral vault on magenta, navy and off-white editorial panels.

TL;DR

  • Blockaid said an attacker drained roughly $1.1 million from at least two of four Rain card-contract deployments that shared the same vulnerable bytecode.
  • The Aug. 28 attack affected $500,859 across 1,685 Avici users and about $431,945 across 636 Tria users; Solayer Pay was also reported affected.
  • A reused-signature flaw let the attacker add itself as an account administrator and withdraw USDC and USDT without user approval.
  • Rain upgraded every program using the outdated Solana contract and promised to make affected users whole, but Blockaid said the stolen funds reached Tornado Cash and were not recovered.

CASABLANCA, September 3, 2026

An attacker drained roughly $1.1 million from stablecoin card programs using an outdated Rain contract on Solana, Blockaid said, more than doubling the previously confirmed Avici-only scope and exposing a shared infrastructure failure across multiple crypto neobanks.

The Aug. 28 exploit did not compromise users’ self-custody wallets or private keys. It targeted stablecoins that customers had moved into separate collateral contracts to fund card spending, allowing the attacker to empty accounts without their approval.

The dedicated loss review found two quantified programs. Blockaid’s Sept. 2 analysis attributed $500,859 to 1,685 Avici users and about $431,945 to 636 Tria users, while also reporting that Solayer Pay was affected. The security firm said the attacker cashed out roughly $1.1 million in total, but Rain has not released its own complete program-by-program reconciliation.

Blockaid attributed the attack to a reused-signature flaw in one old version of Rain’s Solana contract. Rain’s official statement said its monitoring found a vulnerability affecting a small number of programs, all deployments on the outdated version were upgraded, no other programs were affected and every affected user would be made whole.

The new findings materially extend Daily Crypto Briefs’ earlier Avici report, which carefully limited the confirmed impact to Avici’s $500,859.22 disclosure. What changed is the addition of a second quantified program, a roughly $1.1 million cross-program estimate, four matching contract deployments, thousands of exploit calls and a traced route into Tornado Cash.

SOL traded near $100.28 early Thursday, up about 0.6% over 24 hours with $2.87 billion in trading volume and a $58.69 billion market value, according to CoinGecko. The token was up about 35.5% over 30 days, but the exploit was a failure in application code deployed on Solana, not a compromise of the network’s consensus or ordinary SOL accounts.

Solana

SOL
August 4 to September 3, 2026
$100
+36.6%
Aug 4 - Sep 3 | High $109 Low $73.49

Rain Exploit Reused One Signature Twice

Rain’s affected card infrastructure expected two separate Ed25519 authorization checks before a sensitive account action. Blockaid said the malicious transactions made the second verification instruction point back to the signature, public key and message fields in the first, so one attacker-controlled signature was accepted twice.

The attacker used that bypass to call AddCollateralAdmin, adding its own address as an administrator on customer collateral accounts without the owners’ signatures. It then called WithdrawCollateralAsset to move USDC and USDT into one wallet.

Blockaid counted 2,945 administrator additions and 5,288 withdrawals, or 8,233 core exploit calls, over about two hours and 29 minutes. It said the first two successful drains landed three seconds apart, showing that the operation was automated rather than a handful of manual withdrawals.

Bytecode analysis identified four deployments with the same opcode hash. The attacker drained at least two, while the other two remained exposed to the same bug but had no confirmed losses, according to the report. Rain said it later upgraded all programs still using the outdated version and observed no further unauthorized activity.

The distinction between wallet custody and connected card infrastructure is important. A customer can control the keys to a wallet and still assume contract risk after moving money into a spending balance. A separate Gnosis Pay module exploit that drained 41 Safes showed a similar boundary, although its product design and signature flaw were different.

$1.1M Loss Reached Multiple Card Programs

Avici was the largest named program in Blockaid’s accounting. Its incident update said $500,859.22 across 1,685 users was affected, ordinary Solana and EVM wallets remained safe and all affected card balances would be refunded.

Blockaid added Tria to the quantified impact, estimating roughly $431,945 across 636 users. Tria published an official resolution report, while Blockaid also named Solayer Pay without disclosing a separate Solayer loss or affected-user count.

Those figures should not be mechanically added into a false exact total. The Avici and Tria estimates sum to about $932,804, while the broader $1.1 million figure represents Blockaid’s estimate of what the attacker ultimately cashed out across affected programs. Token swaps, timing and any unitemized program exposure can make those measurements differ.

As of 1:24 a.m. UTC on Sept. 3, the best-supported impact is therefore roughly $1.1 million stolen, at least two of four matching deployments drained, 2,321 users across the two programs with published counts, and one additional named program without a public figure. No evidence reviewed supports a claim that every one of Rain’s more than 100 live partners listed in its official media kit was exposed.

Stablecoin cards are expanding because they connect onchain balances with familiar merchant acceptance. Products such as the MetaMask Mastercard rollout show that demand, but the Rain incident demonstrates that a card balance can depend on shared smart-contract code even when the wallet feeding it remains self-custodial.

Refunds Do Not Mean Stolen Funds Were Recovered

Blockaid traced the USDC and USDT through Solana swaps into SOL, across deBridge to Ethereum and then into Tornado Cash. It recorded about 455.9 ETH deposited into the mixer between 7:20 p.m. and 7:49 p.m. UTC on Aug. 28 and said the roughly $1.1 million in proceeds was not recovered.

Rain’s make-whole promise and Avici’s refund are consequential for customers, but they are different from returning stolen assets. A company-funded credit transfers the economic loss away from cardholders; it does not reverse the exploit or establish that the attacker surrendered funds.

The current claim is rated Mostly True rather than fully verified because Rain confirmed the vulnerable old contract and remediation, while the aggregate $1.1 million total and transaction counts come from Blockaid’s analysis. Rain has not disclosed a final consolidated loss, every affected program, the total number of users or whether each refund has completed.

Broader crypto sentiment remained positive during the follow-up. Alternative.me’s Crypto Fear and Greed Index read 65, or Greed, on Sept. 3, compared with 25, or Extreme Fear, one month earlier. The Bitcoin-focused gauge does not measure Rain’s contract security or the likelihood of repayment.

Fear & Greed Index

September 3, 2026
65 Greed

The next material disclosures are Rain’s final reconciliation, confirmation that every affected customer has been repaid, an independent post-mortem and any law-enforcement or recovery result. Until then, the verified change is a broader and technically documented card-infrastructure exploit, not a compromise of Solana or users’ ordinary wallets.

Stay up to date

Get the latest crypto insights delivered to your inbox

Fact-checked by: Daily Crypto Briefs Fact-Check Desk

Frequently Asked Questions

How much was stolen in the Rain stablecoin card exploit?

Blockaid estimated that the attacker cashed out roughly $1.1 million across affected programs. It identified $500,859 from 1,685 Avici users and about $431,945 from 636 Tria users, while reporting that Solayer Pay was also affected. Rain has not published its own complete program-by-program loss table.

How did the Rain card-contract exploit work?

Blockaid said an outdated Solana contract accepted one attacker-controlled Ed25519 signature as if it were two independent authorizations. The attacker then added itself as an administrator on user collateral accounts and withdrew USDC and USDT.

Were users' self-custody wallets or private keys compromised?

No evidence reviewed for this report shows compromised user keys or wallets. The affected assets were card top-ups held in Rain-managed collateral contracts, and users did not sign the exploit transactions.

Will affected Rain card users be refunded?

Rain said all affected users would be made whole, and Avici said it refunded its affected customers in full. A refund shifts the loss away from users but does not mean the stolen assets were recovered.