Back to the news
Fraude

A stale version of Rain's card contract drains $1.1m from Avici and Tria

On 30 August 2026 an attacker made itself the administrator of collateral accounts backing cards issued on Rain's infrastructure, then withdrew their balances. Avici lost $500,800 across 1,685 users, Tria more than $430,000 across 636. Self-custodied wallets were not touched.

On 30 August 2026, about $1.1 million was withdrawn from the accounts that back card spending on the infrastructure of Rain, a provider of card programmes collateralised by digital assets on the Solana chain. Two programmes published their losses: Avici, $500,800 across 1,685 users, and Tria, more than $430,000 across 636 users. The gap to the total covers other programmes, which Rain has not named.

What was drained, and what was not

The attack hit the collateral accounts, the balances locked to back card spending. Those accounts are separate from the users' self-custodied wallets, which were not touched. The distinction sets the scope of the incident: the money that was taken is the money backing the spend, not the holdings that cardholders keep themselves.

$1.1m
withdrawn in total from the card programmes involved
KuCoin, 30 August 2026
$500,800
lost by 1,685 Avici users
Cryptometer, 30 August 2026
$430,000
lost by 636 Tria users, at least
eGamers, 30 August 2026

The mechanism: a signed authorisation submitted again and again

The attacker repeatedly submitted signed authorisations to register itself as the administrator of collateral accounts, one account at a time, then withdrew the balances. The flaw sat in a stale version of Rain's card contract that several programmes were still running. The control it granted applied to individual accounts, which is why the attack ran account by account rather than as a single draw on a shared reserve.

  • Repeated submission of signed authorisations to the card contract
  • Registration of the attacker as administrator of one collateral account
  • Withdrawal of that account's balance, then on to the next account
Lines of code on a dark screen
The flaw sat in the contract that administers the account backing the spend, upstream of the card and its holder.

Where the money went

The stablecoins were swapped for SOL, bridged to Ethereum, then run through the Tornado Cash mixer. A mixer breaks the public trail on the chain. Identifying the final recipient then depends on evidence from outside the chain, such as an exit point into official currency or a request to an intermediary.

⚠️
A fixed version existed; it was not everywhere
Rain says it spotted the vulnerability in a stale version of its card contract, used by Avici and a handful of other programmes. The current version existed before the attack; the programmes that were hit were still running the old one. Rain says it has upgraded every programme on that version and has recorded no further unauthorised activity.

What the two programmes have said

Avici has committed to reimbursing the affected balances in full and has filed a report with the FBI's Internet Crime Complaint Center. Tria has also committed to refunding its customers. Neither company has published a reimbursement timetable.

The AVICI token fell from a 24-hour high of $0.43 to a low of $0.217, a drop of 49%, before recovering to around $0.378. Tria's token fell by more than 10%.

Payment card on a dark surface
The card programme issues and distributes; the collateral that backs the spend is administered by a contract it does not write.

The second card programme cut off in a month

On 2 August 2026, the failure of the Paris issuer Kulipa switched off 120,000 stablecoin cards overnight. The causes differ, an insolvency in one case and a vulnerable contract in the other. The dependency is the same: a card programme runs on infrastructure it does not operate, and inherits flaws it cannot see.

Two things are still to be published before the reach of the incident can be measured: the reimbursement timetable both programmes have promised, and the list of programmes that were running the stale contract. Rain has not said how long that version had been in production.

Provenance

Published on 30 August 2026

4 sources, 4 distinct domains

Cryptometer — $1.1 Million Crypto Card Hack Sends Avici Token Plunging 49% · cryptometer.ioeGamers — Stale Rain Contract Bleeds $1.1M Across Crypto Card Programs, AVICI Sinks 49% · egamers.ioCoinSpot — Crypto card hack for $1.1M crashes Avici neobank token by 49% · coinspot.ioKuCoin — Solana-based Avici token plummets 49% after Rain Infrastructure is hacked · kucoin.com
All news