00:00
Money for You
Money for You
USD/RUB
EUR/RUB
Cryptocurrency

Outdated Solana contract flaw leads to $1.1M stablecoin theft

An attacker exploited an outdated Rain smart contract on Aug. 28, draining $1.1 million from stablecoin card programs on the Solana blockchain. By manipulating signature verification instructions, the perpetrator bypassed authorization controls to seize collateral funds before laundering the assets through the Tornado Cash mixer.

Outdated Solana contract flaw leads to $1.1M stablecoin theft

The security breach targeted card collateral accounts managed by infrastructure provider Rain, affecting crypto neobanks including Avici and Tria. While the Solana network itself remained secure, the vulnerability resided in application-level code that required two independent authorizations for account actions. The attacker exploited this by pointing both verification instructions at the same signature, tricking the contract into approving the unauthorized withdrawals. Over roughly two and a half hours, the system executed thousands of automated transactions, stripping balances from 2,321 users across the two primary platforms alone.

Rain stated that all programs utilizing the vulnerable contract version have since been upgraded, though the company has not yet provided a comprehensive technical audit or explained why outdated infrastructure remained active in production. Avici and Tria have confirmed they are reimbursing affected customers, but the broader incident underscores recurring risks in shared crypto infrastructure. As security firms like Blockaid continue to trace the stolen assets, the event highlights the limitation of traditional point-in-time audits when compared to the necessity for continuous, real-time monitoring of onchain collateral contracts.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!