Newsroom

Rain Smart Contract Flaw Drains $1.1 Million from Crypto Card Balances

30 August, 2026   /   News   /  AI   /   Tags:  avici, card, balances, rain, neobanks

Rain Smart Contract Flaw Drains $1.1 Million from Crypto Card Balances

Outdated Solana contracts from payments provider Rain allowed unauthorized withdrawals totaling about $1.1 million from neobank card balances, with full refunds pledged to affected users

A vulnerability in an outdated version of Solana smart contracts operated by crypto payments infrastructure provider Rain led to the unauthorized withdrawal of roughly $1.1 million from card balances held by customers of several neobanks on August 28, 2026. The largest reported impact fell on Avici, a Solana-based neobank offering Visa-linked spending, where $500,859.22 was taken from the card balances of 1,685 users.

Tria, another platform using the same infrastructure, reported losses exceeding $430,000 affecting 636 users. Combined disclosures from the two firms accounted for more than $930,000 across 2,321 users, with the remainder coming from additional programs running the vulnerable contract version.

How the Unauthorized Withdrawals Occurred

Rain provides the underlying stablecoin-powered card infrastructure used by multiple neobanks and fintech platforms. When users top up their cards, funds move from self-custodial wallets into a separate Solana contract that holds the spendable card balance. An authorization flaw in an outdated version of that contract allowed an attacker to register administrative privileges on individual collateral accounts and then withdraw the assets.

On-chain analysis showed the attacker funded an operational wallet with a small amount of SOL, approximately $190, before systematically calling functions to submit signatures, add itself as an administrator, and execute withdrawals. One reviewed transaction alone moved more than 2,300 USDT from a single account. Stolen stablecoins were subsequently swapped into SOL, bridged to Ethereum, and routed through the Tornado Cash mixer.

Every affected user will have their card balance refunded in full. We remain in close contact with our card-issuing and security partners and are monitoring the remediation closely.
Avici

Avici confirmed that its self-custodial Solana and EVM wallets remained untouched. Only the separate card-balance contracts were impacted. Rain stated that its monitoring systems identified the vulnerability affecting a small number of programs still running the outdated contract and that it had upgraded every such program, with no further unauthorized activity observed afterward.

Refunds and Remediation

Both Avici and Tria pledged to restore all affected balances in full. Avici later confirmed that refunds had been processed, in some cases with additional compensation. Tria similarly reported completing reimbursements that included an extra 10 percent for its affected customers. Rain covered the reimbursements in coordination with its partners.

Avici also stated that it had filed a report with the FBI’s Internet Crime Complaint Center. The company noted that the Solana contract had been updated and that continuous monitoring was in place.

Market Reaction and Broader Context

The incident prompted a sharp decline in the AVICI token, which fell as much as 49 percent from its 24-hour high to a record low before partially recovering. Tria’s token also experienced a temporary drop of more than 10 percent.

The episode drew attention to the concentration of crypto card infrastructure. Rain’s systems power a significant share of stablecoin-based card spending, which reached elevated monthly volumes in the period leading up to the incident. Because card balances sit in shared third-party contracts rather than remaining solely under user control, the self-custodial designation of the neobanks did not prevent losses on the spendable balances.

Security researchers classified the root cause as a smart-contract authorization vulnerability that permitted unauthorized administrative access prior to the withdrawal of collateral assets. Rain has not released a full technical post-mortem detailing the total losses across every affected program.

Associated cryptocurrencies
Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.