# A Deprecated Rain Card Contract on Solana Gave an Attacker Admin Control and 1.1 Million Dollars

Avici lost about 500,800 dollars across 1,685 users and Tria more than 430,000 dollars across 636 users, with both firms pledging full reimbursement while the stolen funds moved through Tornado Cash.

- Published: 2026-09-03T05:55:38.226Z
- Canonical: https://polylog.news/crypto/2026-09-03/a-deprecated-rain-card-contract-on-solana-gave-an-attacker-a
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [crypto.news](https://crypto.news/rain-contract-exploit-drains-1-1m-from-card-users/), [DeFiHackLabs](https://github.com/SunWeb3Sec/DeFiHackLabs/commit/3736721a2859fb21b79fc32adaae8dd2d556d9a0), [Rekt News](https://www.rekt.news/)

An outdated version of a card contract from the crypto card infrastructure firm Rain let an attacker take administrative control of individual card-collateral accounts on Solana and withdraw their balances, [taking about 1.1 million dollars](https://crypto.news/rain-contract-exploit-drains-1-1m-from-card-users/) from programs that relied on it. The root cause was access control in a deprecated contract that customers were still using, not a novel cryptographic break.

The neobank Avici said roughly 500,800 dollars was taken from 1,685 users, and Tria [reported losses above 430,000 dollars across 636 users](https://www.coindesk.com/web3/2026/08/29/a-usd1-1-million-crypto-card-hack-crashed-a-neobank-s-token-49). Both said they would reimburse affected accounts in full. Rain said it identified the problem in the outdated contract version and upgraded the programs still running it, and reported no further unauthorised activity afterwards. The AVICI token fell as much as 49 percent. Blockchain data showed the attacker converted the stolen stablecoins into SOL, moved them across networks, and routed them through Tornado Cash.

Two smaller incidents also mattered this week. Researchers at DeFiHackLabs published a [proof of concept for spot-price manipulation of a Hypervisor position on FloatProtocol](https://github.com/SunWeb3Sec/DeFiHackLabs/commit/3736721a2859fb21b79fc32adaae8dd2d556d9a0) using Uniswap V3, the standard pattern in which a protocol reads an instantaneous pool price instead of a time-weighted one. Separately, KiiChain said an attacker moved 148.3 million KII tokens out through the Hyperlane bridge to BNB Smart Chain across 18 transactions on 22 August, and has not published a dollar figure or an attribution. Rekt News is tracking that incident alongside Mantra, Term Labs and TAC.

## What this means

The costly failure here was operational, not cryptographic. Rain released a fixed contract, but the money was lost because integrators were still using the old one, so the party exposed was the end user of a consumer card product who had no way to know which contract version held their collateral. Fintech firms that build on shared crypto infrastructure inherit the deprecation risk of every dependency, and audits scoped to the current version do not cover it. Reimbursement by Avici and Tria shifts the loss onto the companies' balance sheets, which is the practical reason consumer crypto products keep moving toward custodial models where a firm can absorb a failure.

## What to watch

- Whether Rain publishes a full post-mortem naming which integrators were still on the outdated contract, which would show how common version drift is across card infrastructure.
- Whether AVICI and the affected neobanks fund reimbursement from treasury or from new token issuance, since the second route shifts the loss onto existing holders.
- KiiChain's disclosure of a dollar loss figure for the Hyperlane bridge withdrawal, still missing more than a week after the event.
