$1.1M Rain Card Exploit Rocks Solana Users
A $1.1 million exploit occurred on Solana's Rain card system on August 28, allowing an attacker to drain funds from user accounts. The vulnerable contract was exploited by reusing one signature to bypass two separate approval requirements.
Rain's monitoring systems discovered the vulnerability and launched an investigation. Blockaid found that four contract deployments shared the same code as the flawed version, with at least two of them affected.
The attacker withdrew USDC and USDT from individual accounts after gaining admin access. The stolen funds were sent to one Solana wallet and later swapped for SOL using decentralized exchanges.