๐Ÿ“… Saturday, 5 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Satu Tanda Tangan Dihitung Dua Kali - Begini Cara Hacker Kuras Saldo Kartu Kripto $1,1 Juta di Solana

One Signature Counted Twice - How Hackers Drained $1.1M in Crypto Card Balances on Solana

Over 2,300 crypto card users lost their stablecoin balances in just two and a half hours. A hacker breached legacy Rain smart contracts on the Solana network on August 28, siphoning approximately $1.1 million from various card programs.

The exploit specifically targeted collateral contracts holding stablecoins that back card balances, rather than users’ personal wallets. Avici recorded losses of $500,859.22 affecting 1,685 customers, while Tria reported a $431,945 deficit impacting 636 users. Total losses across the two card providers exceeded $932,800.

How One Signature Tricked the System

Security firm Blockaid identified a vulnerability in the contract’s authorization mechanism. Legacy Rain contracts required two independent approvals via Ed25519 verification instructions before executing transactions. The attacker manipulated the second instruction to re-read data from the first instruction. As a result, the system accepted a single signature from the attacker as two distinct, valid approvals.

With the forged double approval, the attacker submitted an AddCollateralAdmin instruction to gain administrator status. After securing access privileges, the exploiter invoked the WithdrawCollateralAsset command to drain deposited USDC and USDT.

Blockaid detailed the hacker’s on-chain activity, noting that the perpetrator carried out 2,945 admin additions and 5,288 withdrawals. The entire sequence of 8,233 exploit transactions was executed in just two hours and 29 minutes.

Laundering Trail and Platform Response

The stolen USDC and USDT were promptly swapped for SOL via decentralized exchanges. The attacker then used the deBridge protocol to bridge assets to Ethereum. Once on Ethereum, approximately 455.9 ETH was routed into the Tornado Cash mixing service between 19:20 and 19:49 UTC to obscure tracking. The remaining funds were traced to a Solana wallet address FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj.

Rain stated that its monitoring systems detected the vulnerability and immediately upgraded all client programs to the new contract version. Avici reimbursed affected users in full along with a 10% cashback bonus, while Tria also confirmed the completion of its refund process.

Blockaid discovered four distinct contract deployments sharing the same vulnerable code. Two of them were confirmed drained, while the other two have recorded no confirmed losses. The incident demonstrates that the Solana network operated normally throughout, with the vulnerability stemming entirely from application-level code. Application-level security failures represent the largest contributor to losses this year, in line with Blockaid research reporting $1.1 billion in crypto security losses during the first half of 2026. Source: crypto.news.

Read also: OpenAI and Anthropic AIs Successfully Hack Real Companies - Hundreds of Institutions Issue Emergency Warnings


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share