A vulnerability in an outdated Solana smart contract used by crypto card infrastructure provider Rain has resulted in unauthorized withdrawals exceeding $930,000 across at least 2,321 users, according to disclosures from two affected platforms.
Crypto Card Infrastructure Flaw Drains Over $930,000 From 2,300 Users
A vulnerability in an outdated Solana smart contract used by crypto card infrastructure provider Rain has resulted in unauthorized withdrawals exceeding $930,000 across at least 2,321 users, according to disclosures from two affected…
finance.biggo.com
Publisher
Aug 31, 2026 at 4:05 AM UTC · 3 min de lecture

The incident, which began on Aug. 28, exposed a critical weakness in the bridge between self-custodial wallets and card balance contracts. While users' personal wallets remained untouched, funds moved into card-specific contracts became vulnerable to exploitation.
Avici, a Solana-focused financial app, reported the largest impact: 1,685 cardholders lost a combined $500,859.22. The company said its standard Solana wallets and EVM-compatible wallets were not compromised. Tria, another platform using Rain's infrastructure, disclosed that 636 users suffered losses totaling $431,945.
How the Attack Unfolded
The attacker exploited a flaw in a legacy version of Rain's Solana contracts that were still running on a small number of card programs. According to security firm SlowMist, the vulnerability permitted unauthorized administrative access through repeatedly submitted signed authorizations. The perpetrator inserted themselves as an administrator on individual card-collateral wallets and extracted the funds.
Market Context
Article Intelligence
Key Entities
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
