An old Rain Card contract on Solana was exploited, affecting stablecoin-funded card programmes operated by services including Avici and Tria. Blockaid said the attacker targeted collateral contracts rather than customers’ self-custodial wallets or private keys. Rain identified the flaw in a small number of older contract deployments and upgraded those still running the vulnerable version.