blockchainsv
News

Solana Smart Contract Vulnerability Leads to $1.1 Million Theft in Rain Card Breach

1 million in stablecoins to a single attacker, according to Gadgets 360.

Caleb North·updated September 03, 2026

Solana Smart Contract Vulnerability Leads to $1.1 Million Theft in Rain Card Breach

An outdated smart contract in Rain's Solana card infrastructure lost roughly $1.1 million in stablecoins to a single attacker, according to Gadgets 360. The bypass collapsed a two-signature authorization check into one. Neobank platforms Avici and Tria absorbed the impact.

Collateral Withdrawal: The Failed Invariant

The intended invariant: collateral withdrawals require two valid signatures. The reported outcome: a single attacker-controlled signature satisfied the authorization.

This is signature verification desynchronization at the logic layer. The two-signature check accepted one. Funds moved. The contract did not revert.

For Solana developers, the audit signal is clear. Any authorization gate that a single signature can satisfy is a critical-severity finding. Treat single-signer satisfaction as equivalent to no satisfaction. The collateral withdrawal logic is now a confirmed attack vector. Treat the deployment as compromised until decommissioned.

Adjacent Failures in the Same Window

The pattern is not isolated. SlowMist Zone documents an attacker exploiting Ankr's ankrFLOW Solidity contract to mint 8.6 million unbacked liquid staking tokens. Those tokens were then leveraged as collateral on More Markets to drain 15.5 million WFLOW, yielding roughly $246,000 net after slippage. Different chain, same shape: unbacked mint, leveraged drain, state mutation unchallenged.

TNW reports AEREDIUM released AERSeal, a tool engineered to eliminate single-private-key failure points for protocol upgrades and administrative operations. The system replaces standalone keys with hardware-attested M-of-N key shares leveraging the CGGMP24 threshold signature protocol. Direct mitigation of the class of failure observed in Rain.

Separately, CryptoSlate reports Ethereum Layer-2 rollup Silicon halted incoming bridge deposits and initiated its network shutdown, giving users until December 31, 2026, to withdraw roughly $9.75 million in remaining onchain liquidity before explorer and infrastructure go offline.

Operational Checklist for Card and Custody Contracts

1. Authorization gates. Confirm every signature requirement is enforced before state mutation. No early returns. No partial acceptance. Two sigs required means two sigs verified.

2. Withdrawal paths. Map every code path that moves collateral. Confirm each requires the full signature set on every route.

3. Upgrade authority. Confirm administrative operations require M-of-N key shares, not single keys. Single keys are single points of failure.

4. Contract versions. Identify outdated deployments still serving value. Decommission or migrate. Outdated code is attacker code.

5. Pause authority. Confirm a pause function exists, is reached promptly, and propagates across all integration partners — not only the originating protocol.

The Rain exploit is not a one-off. It is a deterministic outcome of an unchecked authorization invariant. Audit accordingly.