← Back to News
Fraud

Stale Rain contract lets attacker drain $1.1M from Avici, Tria

An attacker made itself administrator of the collateral accounts behind cards issued on Rain’s infrastructure and withdrew about $1.1 million. The flaw sat in an outdated contract version that several card programs were still running.

An attacker withdrew about $1.1 million on August 30, 2026, from the accounts that back spending on payment cards issued on the infrastructure of Rain, which runs card programs backed by digital assets on the Solana blockchain. Two programs have disclosed their losses: Avici, $500,800 across 1,685 users, and Tria, more than $430,000 across 636 users. The rest of the total falls on other programs that Rain has not named.

The flaw sat in an outdated version of Rain’s card contract that several programs were still running, even though a current version already existed. Users’ self-custodied wallets were not affected.

Only the collateral behind the cards was hit

The attack targeted the collateral accounts: the balances locked up to guarantee card spending. Those accounts are separate from the self-custodied wallets users hold, which were untouched. That line defines the scope of the incident. The money taken was the money standing behind the cards, not the assets cardholders keep under their own control.

$1.1M
withdrawn in total from the affected card programs
KuCoin, August 30, 2026
$500,800
lost by 1,685 Avici users
Cryptometer, August 30, 2026
$430,000
lost by 636 Tria users, at a minimum
eGamers, August 30, 2026

The attacker replayed signed authorizations, one account at a time

The attacker repeatedly submitted signed authorizations that registered it as administrator of individual collateral accounts, then withdrew each balance. Because the control it gained applied to one account at a time, the attack moved account by account rather than draining a single shared reserve in one go.

  • Signed authorizations submitted to the card contract again and again
  • The attacker registered as administrator of a collateral account
  • The account’s balance withdrawn, then on to the next account
Lines of code on a dark screen
The flaw was in the contract that administers the account backing card spending, a layer above the card and its holder.

Stolen funds went through Tornado Cash

The stolen stablecoins were swapped for SOL, bridged to Ethereum, and run through the Tornado Cash mixer. The mixer breaks the public on-chain trail. Identifying the final recipient now depends on evidence from outside the blockchain, such as an off-ramp into fiat currency or a legal request to an intermediary.

⚠️
A patched version existed but was not deployed everywhere
Rain says its monitoring flagged the vulnerability in an outdated version of its card contract used by Avici and a handful of other programs. The current version predated the attack, but the programs that were hit were still running the old one. Rain says it has upgraded every program running that version and has seen no further unauthorized activity.

Avici and Tria promise refunds but give no timeline

Avici has pledged to refund affected balances in full and has filed a report with the FBI’s Internet Crime Complaint Center (IC3). Tria has also pledged to make its customers whole. Neither company has said when the refunds will be paid.

The AVICI token fell 49%, from a 24-hour high of $0.43 to a low of $0.217, before recovering to around $0.378. Tria’s token dropped more than 10%.

Payment card on a dark surface
The card program issues and distributes the cards, but the collateral behind the spending is administered by a contract it did not write.

A second card program disruption in a month

On August 2, 2026, the collapse of Paris-based issuer Kulipa shut down 120,000 stablecoin cards overnight. The causes differ: an insolvency in one case, a vulnerable contract in the other. The dependency is the same. A card program runs on infrastructure it does not operate, and it inherits that infrastructure’s flaws without seeing them.

Two disclosures are still needed to gauge the full reach of the incident: the refund timeline both programs have promised, and a list of the programs that were running the outdated contract. Rain has not said how long that version had been in production.

Provenance

Published August 30, 2026

4 sources, 4 distinct domains

↗ Cryptometer, $1.1 Million Crypto Card Hack Sends Avici Token Plunging 49% · cryptometer.io↗ eGamers, Stale Rain Contract Bleeds $1.1M Across Crypto Card Programs, AVICI Sinks 49% · egamers.io↗ CoinSpot, Crypto card hack for $1.1M crashes Avici neobank token by 49% · coinspot.io↗ KuCoin, Solana-based Avici token plummets 49% after Rain Infrastructure is hacked · kucoin.com
← All news