Rain Crypto Card Infrastructure Breach Drains Over $930,000 from 2,321 Users
A critical vulnerability in an outdated Solana smart contract used by Rain, a crypto card infrastructure provider, led to unauthorized withdrawals exceeding $930,000 across at least 2,321 users. The incident began on August 28 and exposed a weakness in the bridge between self-custodial wallets and card balance contracts.
The attacker exploited a flaw in the legacy version of Rain's Solana contracts that were still running on a small number of card programs. This allowed them to insert themselves as an administrator on individual card-collateral wallets and extract funds.
Rain confirmed its monitoring systems identified the issue, and all programs using the compromised contract version received immediate upgrades. The stolen stablecoins were converted to SOL, transferred to Ethereum via a cross-chain bridge, and laundered through Tornado Cash, a mixing service that obscures transaction trails.