Rain Solana Card Exploit Drains $1.1M Through Stale Contract and Tornado Cash

Daily Feed
Rain Solana Card Exploit Drains $1.1M Through Stale Contract and Tornado Cash

A stale Rain Solana card contract was exploited on Aug. 28, draining about $1.1 million in stablecoins before the attacker routed the proceeds through deBridge and into Tornado Cash.

  • Outdated contract, not a Solana network breach
  • Users’ self-custodial wallets and private keys were not hit
  • Avici and Tria disclosed $932, 804.22 in losses
  • Blockaid estimated total losses at about $1.1 million

Rain builds infrastructure for crypto card programs, with customer stablecoins parked in onchain collateral accounts that back card spending. Handy setup. Also a pretty big attack surface. One bad contract version can spread pain across multiple providers, which is a nice reminder that “modern finance” sometimes means shared plumbing held together with duct tape and optimism.

According to blockchain security firm Blockaid, the attacker found four Rain deployments that shared the same vulnerable contract logic. At least two of those deployments were drained. Blockaid recorded 2, 945 administrator additions, 5, 288 withdrawal calls, and 8, 233 core exploit transactions over about 2 hours and 29 minutes. The first two successful withdrawals were three seconds apart, which strongly suggests the attacker was not improvising.

The core flaw was in authorization. Blockaid said the attacker manipulated the contract’s second verification step so one attacker-controlled signature could be accepted as two separate approvals. In plain English: the contract was supposed to require independent authorization, but the bug let the attacker fake that requirement and act like they had permission they never earned. From there, the contract accepted withdrawals of USDC and USDT from collateral accounts.

The trail then moved off Solana. Blockaid traced the stolen funds through deBridge to Ethereum, then into Tornado Cash. The company said roughly 455.9 ETH entered the mixer between 19:20 and 19:49 UTC. Tornado Cash is designed to blur the trail by pooling deposits and breaking the obvious link between sender and receiver. It is privacy tech in the same way a getaway car is transportation tech.

Two programs publicly disclosed losses. Avici said $500, 859.22 was drained from 1, 685 users. Tria said it lost $431, 945 across 636 customers. Combined, that comes to $932, 804.22. Blockaid said other Rain-supported programs were also exposed, which is how the total estimate rises to about $1.1 million.

Rain said “a small number of programs” used the vulnerable version and that every program still running it was upgraded after the attack. Rain also said affected users would be made whole. Avici said it refunded all affected customers and offered 10% cashback, while Tria said it would reimburse customers as well.

The important distinction here is simple: this was not a Solana chain failure and it was not a private-key theft. The base network kept working. The attack hit application-layer contract logic and the shared infrastructure sitting on top of it. That matters because the crypto industry still has a habit of selling users the dream of self-sovereignty while quietly funneling funds through a few highly privileged contracts with all the operational discipline of a mattress warehouse.

Blockaid also said the attacker identified four deployments with the same opcode hash, basically a code fingerprint for the same logic. That is another way of saying the vulnerable setup was not some one-off glitch buried in a dead corner of the system. It was duplicated enough that one flaw could spill across multiple programs. Rain’s upgrade response may have stopped further damage, but the fact that older deployments were still live is the real operational faceplant.

The laundering route is familiar for a reason. Cross-chain bridges like deBridge are useful for moving assets between networks, but they also give attackers a fast escape hatch. Once funds land in Tornado Cash, tracing gets harder, even if it is not always impossible. The attacker’s workflow here was blunt and effective: drain on Solana, move across chains, mix on Ethereum, and try to disappear into the noise.

That pattern fits a larger industry problem. Security failures in crypto usually do not come from a dramatic chain-level collapse. They come from permissions, upgrade mistakes, stale deployments, and contract logic that was supposed to be “safe enough” until it wasn’t. Periodic audits help, but they are not a force field. Live financial contracts need version control, monitoring, and boring operational discipline, which is exactly the sort of stuff people ignore right up until it costs them real money.

Blockaid’s broader context is grim as well. The firm said crypto security failures caused approximately $1.1 billion in losses during the first half of 2026, based on its own research. That figure should be treated as a company estimate rather than gospel, but the direction is hard to dispute. Attackers keep finding the same weak spots because the industry keeps shipping money-moving systems faster than it secures them.

For users, the lesson is not “never use crypto cards.” It is to understand where the actual risk sits. Self-custodial wallets are only part of the picture. Once funds are deposited into a card program’s collateral contract, users inherit the provider’s contract risk, upgrade risk, and ops risk. Convenience is great until the vault door is controlled by code you did not write and cannot audit yourself.

For builders, this is even simpler: if production contracts can sit outdated long enough for one exploit to drain multiple programs, your security process is not mature. It is a liability with branding.

Key questions and takeaways

  • Was Solana hacked?
    No. The exploit targeted an outdated Rain contract on Solana, not the Solana network itself.
  • Were users’ wallets or private keys stolen?
    No. Blockaid said the attacker went after collateral contracts, not self-custodial wallets or private keys.
  • How much money was lost?
    Blockaid estimated about $1.1 million in total losses. Avici and Tria publicly disclosed $932, 804.22 combined.
  • Where did the stolen funds go?
    Blockaid traced them from Solana through deBridge and then into Tornado Cash on Ethereum.
  • Why is this more than one bad contract?
    Because Rain’s infrastructure was shared across multiple card programs, so one outdated deployment could affect several providers at once.
  • Can reimbursements fix the problem?
    They can make users whole financially, but they do not erase the security failure, the operational mess, or the trust damage.

Rain said the vulnerable deployments were upgraded and affected users would be compensated. Good. The real fix, though, is stricter contract version control, better live monitoring, and fewer “how is this still in production?” moments across the crypto stack.

Further reading

For a few more angles on the Rain exploit and the security mess around it:

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog