Sun. Aug 30th, 2026

Tria Refunds 636 Users Plus 10% After Rain Solana Card Exploit

ByShane Neagle

August 30, 2026 #Tria
SolanaSolana

Crypto finance platform Tria has fully reimbursed 636 users who lost a combined $431,945 from card balances after a vulnerability in card issuer Rain’s Solana infrastructure allowed unauthorized withdrawals.

Tria said on Sunday that every affected customer had received a full refund, together with an additional 10% payment. The extra compensation would equate to roughly $43,200 if applied directly to the amount affected, taking total payments to around $475,000.

The reimbursement completed a remediation process that began after users reported unauthorized withdrawals from Solana USDC and USDT balances that had been topped up to their Tria cards on Aug. 28.

“Every affected user has now received their full refund, plus an additional 10% to each user,” Tria said. The company said it worked with Rain and security partners throughout the investigation and remediation.

The vulnerability did not affect users’ main Tria wallets.

Tria said its self-custodial wallets and card balances operate separately. When customers top up their cards using assets on Solana, those assets move into a separate Solana contract supporting the card balance. It was that contract, rather than the underlying Tria wallet, that was affected.

Assets held in Tria wallets across Solana, EVM networks and Aptos remained untouched, according to the company.

Rain, which provides card-issuing infrastructure to Tria and a range of other crypto companies, said its monitoring systems had detected a vulnerability affecting a “small number” of programs still using an outdated version of its Solana contracts.

The company subsequently upgraded every program using the affected contract version and said it had observed no further unauthorized activity following the change. Rain also brought in third-party forensic specialists and said it would work with law enforcement and relevant regulators.

Rain has not publicly disclosed a complete figure for losses across all programs or provided a full technical post-mortem.

The incident was not limited to Tria.

Solana-focused financial app Avici said 1,685 users had $500,859.22 in card balances affected by the same Rain contract issue. Its self-custodial wallets were also unaffected, with the losses confined to the separate contract used for card funding. Security firm SlowMist classifies the incident as a smart-contract vulnerability and said the affected authorization flow allowed unauthorized administrative access before collateral was withdrawn.

Taken together, the figures disclosed by Tria and Avici alone put affected balances at more than $932,000 across 2,321 users. Rain’s description of a small number of affected programs leaves open whether additional card programs suffered losses.

The issue matters beyond the individual platforms because Rain operates infrastructure behind a growing number of stablecoin-linked card products.

Rain describes itself as a full-stack payments provider for fintech companies, wallets, neobanks and exchanges, offering card issuance, wallets, on- and off-ramps and stablecoin settlement. It says its infrastructure is used by hundreds of companies and supports card spending at more than 150 million merchants in over 150 countries.

Rain added native Solana support in May 2025 as part of an expansion of its multi-chain card infrastructure. It also operates as a Visa Principal Member and supports USDC and USDT across Solana, Ethereum and other networks.

Tria’s own card can be topped up from several networks, including Ethereum, Base, Arbitrum, Polygon, Bitcoin, Aptos and Solana. Its documentation specifically supports Solana-based USDC and USDT deposits, although users need SOL to pay transaction fees for those deposits.

The Aug. 28 incident therefore appears to have been tied to a particular version of Rain’s Solana card infrastructure rather than to Solana assets held generally or to Tria’s broader wallet architecture.

Rain has not said why some live programs remained on the outdated contract version, how long that version had been operating or whether mandatory upgrade procedures will change following the incident.

Those questions may become part of its continuing forensic investigation.

The Bigger Risk Is the Layer Between Self-Custody and Spending

The most interesting part of this incident is that Tria can accurately say its users’ wallets were not hacked while 636 of those same users still lost money associated with their cards.

That is not a contradiction. But it exposes an important boundary in the increasingly popular idea of a “self-custodial crypto card.”

Self-custody protects assets while they remain in the wallet controlled by the user. Turning those assets into something that can be spent through Visa introduces another system involving smart contracts, card issuers, authorization logic and settlement infrastructure.

In Tria’s case, the vulnerability sat in that bridge.

Once Solana assets were moved into the separate card contract, their security depended not just on the user’s wallet keys but also on Rain’s code and the version of that code running for the card program.

That distinction is easy to miss when consumers hear “self-custodial.”

Tria itself markets the card around users retaining control of their underlying wallet assets, while its top-up documentation separately explains that funds deposited to the card are converted and credited to a card balance.

The incident makes that distinction much more than technical wording.

There is also a concentration-risk issue. Rain’s business model lets many consumer-facing crypto companies outsource complicated card infrastructure rather than building issuing, compliance and settlement systems themselves. That makes it possible for smaller platforms to launch cards quickly.

It also means one infrastructure bug can surface simultaneously under several different brands.

The same vulnerability affected Tria and Avici even though customers interacted with different products. For the end user, the brand on the card was different; underneath, part of the infrastructure was shared.

Traditional finance works this way too. Banks, fintech apps and payment companies routinely rely on common processors and networks. The difference with on-chain card infrastructure is that vulnerable smart-contract logic can sometimes be exploited directly and rapidly before an operator can intervene.

Rain’s response therefore deserves to be separated into two questions.

The first is incident response. On that measure, the outcome was relatively clean: the contracts were upgraded, unauthorized activity stopped, forensic investigators were engaged and affected Tria users were reimbursed, with Tria going further by adding 10%.

The second is prevention.

Why were production programs still using an outdated vulnerable contract? Who was responsible for triggering upgrades? Could Rain have disabled the old version centrally or prevented partners from remaining on it?

Those questions matter more for the industry’s long-term credibility than whether this particular $431,945 was eventually returned.

Crypto cards are becoming one of the clearest attempts to turn stablecoins from assets people hold into money they use every day. That requires users to trust infrastructure they may never see.

The Tria incident shows that self-custody can substantially limit the blast radius: the users’ broader wallets stayed safe. But it does not eliminate infrastructure risk once funds cross into the payment layer.

The refund solves the immediate loss. The more important test for Rain and its partners is whether the outdated-contract problem that caused it can happen again.

ByShane Neagle

Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms. He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments. Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

Leave a Reply

Your email address will not be published. Required fields are marked *