Overview
- An attacker exploited an outdated Rain Solana card contract on Aug. 28, reusing an Ed25519 signature to grant itself admin rights and withdraw roughly $1.1 million from multiple collateral contracts.
- Blockaid’s on‑chain analysis recorded about 8,233 core exploit transactions over roughly two hours and 29 minutes, including 2,945 admin additions and 5,288 withdrawal calls.
- The thief swapped stolen USDC and USDT for SOL, bridged the funds to Ethereum via deBridge, and about 455.9 ETH was deposited into Tornado Cash between 19:20 and 19:49 UTC, with those funds not yet recovered.
- Affected issuers Avici and Tria disclosed combined customer losses of roughly $932,800 and said they will reimburse users, while Rain says it upgraded all deployments running the vulnerable contract and has seen no further unauthorized activity.
- The incident highlights concentrated operational risk from shared, upgradeable provider code, the limits of point‑in‑time audits, and the need for continuous monitoring and clearer version and permission governance as forensic tracing and investigations continue.