Home Gadgets Smart Contract Exploit Drains $1.1 Million From Rain Card Users

Smart Contract Exploit Drains $1.1 Million From Rain Card Users

0

An attack using an old Rain Card contract happened on August 28, stealing around $1.1 million (roughly Rs. 10.3 crore) from various stablecoin card schemes running on the Solana blockchain network, as per the blockchain security firm Blockaid. Companies like Avici and Tria were victims of the attack. The two companies stated that the losses stood at over $932,800 (roughly Rs. 8.8 crore) across 2,321 users in total. According to Blockaid, other services supported by Rain were affected as well, pushing the estimated damage figure to about $1.1 million (roughly Rs. 10.3 crore). 

Flawed Signature Verification Enabled Unauthorised Collateral Transfers

As per Blockaid, the attacker did not attack customers’ self-custodial wallets or their keys. In fact, the vulnerability exploited was related to the collateral contracts storing stablecoins from deposits into the card balance. Rain also stated that its monitoring systems discovered. Rain stated that its monitoring system found a weakness present in a “small number of programs” employing an older version of its Solana card contract. It was able to upgrade all programs that were still running the vulnerable version, as per its press release. Rain enables crypto companies to launch card products that would be funded via stablecoins. Once users deposit money for their cards, funds get stored in collateral wallets via onchain contracts.

These funds are then separated from assets that are within the customer’s own personal wallets, and after going through the card collateral agreement, the security is purely dependent on the coding of the infrastructure provider and its authorisation controls. Blockaid discovered four deployments that contained code having the same opcode hash as the vulnerable contract. Blockaid stated that the attacker had drained at least two of the deployments, while the remaining two had the same flaw and had not suffered any loss.

However, the old Rain contract required two separate verifications for particular account operations. Solana’s Ed25519 instructions were used to verify the required signatures. Although, according to Blockaid’s findings, the second verification was tampered with by the attacker. This verification’s signature, public key, and message offsets referenced the data of the first verification instruction. Thus, the insecure contract took a single signature controlled by the attacker as two separate signatures. This made it possible for the attacker to meet the authorisation criteria without the consent of the owners of the collateral accounts. 

This is another example of where vulnerable and old infrastructures continue to operate. Verus Protocol’s Ethereum bridge was reportedly exploited in May in a similar way. The incident happened when a hacker was able to fraudulently transfer out at least $11.5 million (roughly Rs. 108 crore) in cryptocurrency through a fake cross-chain transfer message. Blockaid stated that its detection system had caught this ongoing exploit on the Verus-Ethereum bridge. 

Cryptocurrency is an unregulated digital currency, not a legal tender and subject to market risks. The information provided in the article is not intended to be and does not constitute financial advice, trading advice or any other advice or recommendation of any sort offered or endorsed by NDTV. NDTV shall not be responsible for any loss arising from any investment based on any perceived recommendation, forecast or any other information contained in the article.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.


IFA 2026: Acer Swift Blade 14, Swift Air 16 (2026) Launched With Up to Intel Core 7, Aspire G 3D 16 Tags Along

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version