Listen to Article — 6 min
A yet-unidentified attacker exploited an outdated Rain card contract on Aug. 28, siphoning approximately $1.1 million from multiple stablecoin card programs built on Solana. Blockchain security firm Blockaid disclosed the incident, which impacted crypto neobanks Avici and Tria, among others, raising fresh alarms over smart contract lifecycle management and custodial infrastructure risks in the digital asset sector. Exploit Hits Multiple Stablecoin Card Programs The attack targeted collateral contracts that hold stablecoins deposited by users to fund their card balances. According to Blockaid, the malicious actor drained funds from several programs that were still running an outdated version of Rain's Solana-based card contract. Affected companies Avici and Tria disclosed combined losses exceeding $932,800 across a total of 2,321 users. Blockaid further reported that other Rain-supported programs were also exposed, bringing the aggregate estimated loss to approximately $1.1 million. Affected Program Clients Impacted Reported Loss Security Status Avici Unconfirmed Part of $932,800+ combined total Outdated contract exploited Tria Unconfirmed Part of $932,800+ combined total Outdated contract exploited Other Rain-supported programs Unconfirmed Remaining portion of ~$1.1M Vulnerability identified; losses confirmed by Blockaid Attack Targeted Card Collateral Contracts, Not User Wallets A critical distinction emerged from initial security reviews: the attacker did not access customers’ self-custodial wallets or private keys. Instead, the exploit specifically targeted collateral contracts holding the stablecoins users had deposited to fund their card balances. These balances are maintained separately from assets held inside customers’ personal wallets. Once funds enter a card collateral contract, their security depends entirely on the infrastructure provider’s code and authorization controls. Rain stated that its monitoring systems discovered a vulnerability affecting a “small number of programs” using an outdated version of its Solana card contract. The company said it upgraded every program still running the affected version, according to its public statement. Security Firm Alerts Ecosystem Via Social Media Blockaid took to social media platform X to broadcast the findings, posting: An attacker exploited an outdated Rain contract, draining $1.1M in user card balances from @avici, @useTria, and other crypto neobanks.Blockaid's Onchain Monitoring gives stablecoin card issuers the capability to detect exploits across their fleet of contract deployments.Read... pic.twitter.com/vzMQfPkdtT The security company also identified four deployments containing code with the same opcode hash as the vulnerable contract. Blockaid said the attacker drained at least two of those deployments. The other two reportedly carried the same vulnerability but had no confirmed losses. Questions Mount over Contract Lifecycle Management Rain has confirmed that an outdated contract caused the incident. However, the company has not published a complete technical report identifying every affected deployment or explaining why some programs continued using the older version. The lack of full disclosure has left affected users and industry observers speculating about the scope of the breach and operational oversight gaps at infrastructure providers. The incident adds to wider concerns about contract and operational vulnerabilities across the crypto ecosystem. According to research published by Blockaid, crypto security failures caused approximately $1.1 billion in losses during the first half of 2026. That figure underscores a persistent trend of high-value exploits tied to smart contract bugs, privileged key compromises, and outdated code deployments. Infrastructure Risk Spotlighted in Neobanking Sector Rain provides card-issuing infrastructure that allows crypto companies to offer payment cards funded with stablecoins. The business model has grown increasingly popular among crypto neobanks seeking to bridge traditional payment rails with digital asset liquidity. When customers fund their cards, the deposited assets move into collateral accounts managed through onchain contracts, making the security of those contracts paramount. Blockaid's public alert highlighted the importance of continuous onchain monitoring for stablecoin card issuers, particularly those managing multiple contract deployments. The firm's detection capability appeared to be instrumental in identifying the exploit across the fleet of affected programs. The Security Breakdown Attack Vector: Exploit of outdated Solana card contract code Target: Collateral contracts holding stablecoin deposits for card balances Assets Accessed: User funds within card collateral accounts only Assets Safe: Customer self-custodial wallets and private keys unaffected Vulnerable Deployments: 4 identified by Blockaid via opcode hash matching Confirmed Drained: At least 2 deployments What Happens Next for Affected Card Users? Avici and Tria have yet to announce any remediation or compensation plans for the 2,321 affected users. The absence of formal notification details or customer restitution frameworks could prompt regulatory scrutiny, particularly in jurisdictions with established consumer protection guidelines for payment services. The incident further complicates the operational landscape for crypto neobanks, which must balance offering seamless card experiences against maintaining rigorous contract security standards. Rain's statement that it has upgraded all programs running the vulnerable version suggests an immediate mitigation effort. However, the broader industry lesson centers on the necessity of proactive contract upgrade pathways and the risks embedded in legacy code within fast-moving DeFi and payments infrastructure. What Precise Data Did Blockaid Reveal? Blockaid identified four contract deployments sharing the same opcode hash as the vulnerable Rain card contract. Two deployments were confirmed drained by the attacker. The remaining two deployments carried the identical vulnerability but showed no confirmed losses at the time of disclosure. Was There Any Warning Before the Exploit? Rain said its own monitoring systems discovered the vulnerability after it was exploited. No prior public audit notice or upgrade advisory had been issued regarding this specific outdated contract version before the attacker struck. Are User Funds Backed or Insured? There is no indication that affected funds are covered by any insurance scheme. The companies have not yet disclosed whether users will be reimbursed. Customers' self-custodial wallets were not compromised, but the stablecoins inside the card collateral contracts were directly drained by the attacker. How Did the Attackers Choose Their Targets? The attacker targeted programs still running the outdated Rain Solana card contract. These programs were identifiable on-chain by their contract code. The attacker likely scanned Solana for deployments matching the vulnerable opcode hash before executing the drain. Has Rain Issued a Full Technical Report? No. Rain confirmed that an outdated contract caused the incident and stated that it upgraded all affected programs, but has not published a complete technical report detailing every affected deployment or the reasons why some programs remained on the older version.
Follow Our News on Google
Be instantly informed of developments.
A yet-unidentified attacker exploited an outdated Rain card contract on Aug. 28, siphoning approximately $1.1 million from multiple stablecoin card programs built on Solana. Blockchain security firm Blockaid disclosed the incident, which impacted crypto neobanks Avici and Tria, among others, raising fresh alarms over smart contract lifecycle management and custodial infrastructure risks in the digital asset sector.
Exploit Hits Multiple Stablecoin Card Programs
The attack targeted collateral contracts that hold stablecoins deposited by users to fund their card balances. According to Blockaid, the malicious actor drained funds from several programs that were still running an outdated version of Rain’s Solana-based card contract. Affected companies Avici and Tria disclosed combined losses exceeding $932,800 across a total of 2,321 users. Blockaid further reported that other Rain-supported programs were also exposed, bringing the aggregate estimated loss to approximately $1.1 million.
| Affected Program |
Clients Impacted |
Reported Loss |
Security Status |
| Avici |
Unconfirmed |
Part of $932,800+ combined total |
Outdated contract exploited |
| Tria |
Unconfirmed |
Part of $932,800+ combined total |
Outdated contract exploited |
| Other Rain-supported programs |
Unconfirmed |
Remaining portion of ~$1.1M |
Vulnerability identified; losses confirmed by Blockaid |
Attack Targeted Card Collateral Contracts, Not User Wallets
A critical distinction emerged from initial security reviews: the attacker did not access customers’ self-custodial wallets or private keys. Instead, the exploit specifically targeted collateral contracts holding the stablecoins users had deposited to fund their card balances. These balances are maintained separately from assets held inside customers’ personal wallets. Once funds enter a card collateral contract, their security depends entirely on the infrastructure provider’s code and authorization controls.
Rain stated that its monitoring systems discovered a vulnerability affecting a “small number of programs” using an outdated version of its Solana card contract. The company said it upgraded every program still running the affected version, according to its public statement.
Security Firm Alerts Ecosystem Via Social Media
Blockaid took to social media platform X to broadcast the findings, posting:
An attacker exploited an outdated Rain contract, draining $1.1M in user card balances from @avici, @useTria, and other crypto neobanks.Blockaid’s Onchain Monitoring gives stablecoin card issuers the capability to detect exploits across their fleet of contract deployments.Read… pic.twitter.com/vzMQfPkdtT
The security company also identified four deployments containing code with the same opcode hash as the vulnerable contract. Blockaid said the attacker drained at least two of those deployments. The other two reportedly carried the same vulnerability but had no confirmed losses.
Questions Mount over Contract Lifecycle Management
Rain has confirmed that an outdated contract caused the incident. However, the company has not published a complete technical report identifying every affected deployment or explaining why some programs continued using the older version. The lack of full disclosure has left affected users and industry observers speculating about the scope of the breach and operational oversight gaps at infrastructure providers.
The incident adds to wider concerns about contract and operational vulnerabilities across the crypto ecosystem. According to research published by Blockaid, crypto security failures caused approximately $1.1 billion in losses during the first half of 2026. That figure underscores a persistent trend of high-value exploits tied to smart contract bugs, privileged key compromises, and outdated code deployments.
Infrastructure Risk Spotlighted in Neobanking Sector
Rain provides card-issuing infrastructure that allows crypto companies to offer payment cards funded with stablecoins. The business model has grown increasingly popular among crypto neobanks seeking to bridge traditional payment rails with digital asset liquidity. When customers fund their cards, the deposited assets move into collateral accounts managed through onchain contracts, making the security of those contracts paramount.
Blockaid’s public alert highlighted the importance of continuous onchain monitoring for stablecoin card issuers, particularly those managing multiple contract deployments. The firm’s detection capability appeared to be instrumental in identifying the exploit across the fleet of affected programs.
The Security Breakdown
- Attack Vector: Exploit of outdated Solana card contract code
- Target: Collateral contracts holding stablecoin deposits for card balances
- Assets Accessed: User funds within card collateral accounts only
- Assets Safe: Customer self-custodial wallets and private keys unaffected
- Vulnerable Deployments: 4 identified by Blockaid via opcode hash matching
- Confirmed Drained: At least 2 deployments
What Happens Next for Affected Card Users?
Avici and Tria have yet to announce any remediation or compensation plans for the 2,321 affected users. The absence of formal notification details or customer restitution frameworks could prompt regulatory scrutiny, particularly in jurisdictions with established consumer protection guidelines for payment services. The incident further complicates the operational landscape for crypto neobanks, which must balance offering seamless card experiences against maintaining rigorous contract security standards.
Rain’s statement that it has upgraded all programs running the vulnerable version suggests an immediate mitigation effort. However, the broader industry lesson centers on the necessity of proactive contract upgrade pathways and the risks embedded in legacy code within fast-moving DeFi and payments infrastructure.
What Precise Data Did Blockaid Reveal?
Blockaid identified four contract deployments sharing the same opcode hash as the vulnerable Rain card contract. Two deployments were confirmed drained by the attacker. The remaining two deployments carried the identical vulnerability but showed no confirmed losses at the time of disclosure.
Was There Any Warning Before the Exploit?
Rain said its own monitoring systems discovered the vulnerability after it was exploited. No prior public audit notice or upgrade advisory had been issued regarding this specific outdated contract version before the attacker struck.
Are User Funds Backed or Insured?
There is no indication that affected funds are covered by any insurance scheme. The companies have not yet disclosed whether users will be reimbursed. Customers’ self-custodial wallets were not compromised, but the stablecoins inside the card collateral contracts were directly drained by the attacker.
How Did the Attackers Choose Their Targets?
The attacker targeted programs still running the outdated Rain Solana card contract. These programs were identifiable on-chain by their contract code. The attacker likely scanned Solana for deployments matching the vulnerable opcode hash before executing the drain.
Has Rain Issued a Full Technical Report?
No. Rain confirmed that an outdated contract caused the incident and stated that it upgraded all affected programs, but has not published a complete technical report detailing every affected deployment or the reasons why some programs remained on the older version.
This article is provided for informational and educational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice. The digital asset market is highly volatile, speculative, and subject to rapid regulatory changes. While we strive to ensure the accuracy of the information presented, market conditions change quickly, and data may become outdated. You are solely responsible for your own research (DYOR) and financial decisions. ATHPost, its owners, and its authors assume no liability whatsoever for any direct or indirect financial losses, liquidations, or damages arising from the use of this content.