How Did The Rain Solana Card Exploit Affect Tria Users?
Crypto finance platform Tria has reimbursed 636 users who lost a combined $431,945 from card balances after a vulnerability in card issuer Rain’s Solana infrastructure allowed unauthorized withdrawals.
Tria said every affected customer received a full refund plus an additional 10%. If applied directly to the affected balance, the extra compensation would amount to roughly $43,200, taking total payments to around $475,000.
The incident began on Aug. 28 and affected Solana USDC and USDT that customers had transferred into their Tria card balances. Tria said its main self-custodial wallets were not compromised.
“Every affected user has now received their full refund, plus an additional 10% to each user,” Tria said. The company worked with Rain and security partners during the investigation and remediation.
Tria’s wallet assets and card balances operate separately. Once customers top up their cards using Solana assets, those funds move into a separate contract supporting the card balance. That contract, rather than the underlying Tria wallet, was affected. Assets held in Tria wallets across Solana, EVM networks and Aptos remained untouched.
What Did Rain Change After The Unauthorized Withdrawals?
Rain said its monitoring systems identified a vulnerability affecting a small number of programs still operating an outdated version of its Solana contracts. It subsequently upgraded every program using the affected version and said no further unauthorized activity had been observed.
The payments infrastructure provider also brought in third-party forensic specialists and said it would work with law enforcement and relevant regulators. Rain has not disclosed total losses across all affected programs or published a complete technical post-mortem.
The incident extended beyond Tria. Solana-focused financial app Avici said 1,685 users had $500,859.22 in card balances affected by the same contract issue. Its self-custodial wallets were also untouched.
Security firm SlowMist classified the incident as a smart-contract vulnerability and said the affected authorization flow permitted unauthorized administrative access before collateral was withdrawn.
Combined disclosures from Tria and Avici put affected balances above $932,000 across 2,321 users. Because Rain has only referred to a small number of affected programs, it remains unclear whether other card providers also suffered losses.
Investor Takeaway
The incident shows that self-custody can protect a user’s main wallet without eliminating risk after assets are transferred into card infrastructure. The security of a crypto card depends on both the wallet layer and the contracts, issuers and settlement systems used to make those assets spendable.
Why Does The Incident Matter Beyond Tria?
Rain provides card infrastructure to fintech companies, wallets, neobanks and exchanges, including card issuance, wallets, stablecoin settlement and on- and off-ramps. The company says its infrastructure supports hundreds of businesses and card spending at more than 150 million merchants across over 150 countries.
Rain added native Solana support in May 2025 as part of its multi-chain expansion and supports USDC and USDT across Solana, Ethereum and other networks. It also operates as a Visa Principal Member.
The shared infrastructure creates efficiency for crypto companies that do not want to build issuing and settlement systems themselves, but it also creates concentration risk. The same underlying contract vulnerability can affect users of several consumer-facing brands at once, as the Tria and Avici cases showed.
The unanswered issue is why live programs were still using an outdated contract version. Rain has not said how long that version remained in production, who was responsible for triggering upgrades or whether its upgrade procedures will change.
Where Does Self-Custody End And Payment Risk Begin?
The incident exposes an important distinction in the growing market for self-custodial crypto cards. Users can retain control of assets in their wallets, but converting those assets into a spendable card balance introduces another layer of smart contracts, authorization systems and third-party payment infrastructure.
In Tria’s case, the vulnerability existed in that bridge. Once Solana assets entered the separate card contract, their security depended not only on the user’s private keys but also on Rain’s contract code and the version deployed for the card program.
That distinction matters as stablecoin cards become a larger part of everyday crypto payments. A common infrastructure provider can make it easier for many companies to launch card products, but a weakness at that provider can also spread across several brands simultaneously.
Rain’s immediate response stopped the unauthorized activity, while Tria’s reimbursement removed the direct financial loss for its affected customers. The longer-term test is whether Rain’s contract management process can prevent outdated vulnerable versions from remaining active in production.







