Outdated Rain Solana Contract Exploited, $1.1M Drained From Crypto Card Programs
The incident exposes concentrated operational risk from upgradeable shared‑authority contracts and has led issuers to promise refunds while investigations proceed.
Overview
- On Aug. 28 on‑chain observers traced repeated SubmitSignatures → AddCollateralAdmin → WithdrawCollateralAsset calls that moved roughly $1.1 million out of multiple Solana card‑collateral contracts.
- The attacker exploited a legacy Rain‑managed contract by adding themselves as an admin via repeated signed authorizations and withdrawing card balances from affected accounts.
- Avici reported $500,859 lost from 1,685 users and pledged full refunds while filing a report with the FBI, and Tria reported more than $430,000 lost across 636 users and also vowed to repay customers.
- Rain said its monitoring found the flaw, upgraded programs running the outdated contract version, and has detected no further unauthorized activity as forensic tracing shows funds were swapped to SOL, bridged to Ethereum and routed through Tornado Cash.
- The case highlights how third‑party card infrastructure, upgradeable contracts and a single upgrade authority can concentrate contagion risk and underlines calls for public post‑mortems, independent audits and stronger on‑chain operational controls.