Community Investigation

The $1.1M Rain Card Exploit: What the Chain Confirms—and What It Still Cannot

REPORT
REPORT

September 03, 2026

EXECUTIVE SUMMARY

On 28 August 2026, an outdated Solana collateral program used by Rain-powered stablecoin card products was reportedly exploited through a reused Ed25519 verification proof. Blockaid reports roughly $1.1 million drained across multiple programs, followed by swaps into SOL, a bridge to Ethereum, and approximately 455.9 ETH deposited into Tornado Cash.

Our SentinelTX investigation reached a narrower, transaction-anchored conclusion. It independently confirmed two USDC inflows totaling 1,780.973441 USDC into the reported Solana collection wallet on the incident date and confirmed the published Ethereum router as a sanctioned Tornado Cash endpoint. It did not reproduce the reported $1.1 million total, the deBridge leg, or the 455.9 ETH deposit from the supplied seeds. Those gaps are central findings, not details to hide.

INCIDENT MECHANICS

According to Blockaid, the vulnerable contract accepted one attacker-controlled Ed25519 proof where two independent authorizations were expected. That enabled AddCollateralAdmin, followed by repeated WithdrawCollateralAsset calls across user collateral accounts. The failure was in shared card-balance infrastructure—not in users’ private keys.

The diagram below separates the authorization failure from the later asset movement.

VERIFICATION MATRIX

Claim

Status

Evidence

~$1.1M loss

Reported

Blockaid / press

2,945 admin + 5,288 withdrawals

Reported

Blockaid

1,780.973441 USDC on Aug 28

Confirmed

2 Solana txs

deBridge + 455.9 ETH to mixer

Unanchored

No matching path from seeds

Tornado router identity

Confirmed

Sentinel label

Claim | Status | Evidence

Reported loss of about $1.1M | Reported, not independently reproduced | Blockaid and press reporting

2,945 AddCollateralAdmin and 5,288 WithdrawCollateralAsset calls | Reported, not independently reproduced | Blockaid

1,780.973441 USDC received by the reported collection wallet on 28 August | Confirmed | Two Solana transaction anchors

deBridge route and 455.9 ETH into Tornado Cash | Reported, not anchored in this session | No matching bridge or mixer transaction from supplied seeds

Tornado Cash router identity | Confirmed | Sentinel Protocol label

CONFIRMED SOLANA TRANSACTION ANCHORS

The reported collection wallet is FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj. SentinelTX found two incident-date inflows:

• 1,779.973441 USDC from HEgJutJjfCyG7RDtcS9xBc8sbty31TsqK3VCxyh4s7K1 in transaction 2oE6hQ7nFYpx9k1EUZuy93DsPqDUoo6MvSzMG8b8zGMZ7hUbzAzuYubicvRPK7Pcyvsxb1Hk35yB22dsC9jt3M5L.

• 1.000000 USDC from 83v8iPyZihDEjDdY8RdZddyZNyUtXngz69Lgo9Kt5d6d in transaction JV6xqGB4Xppfre5rYvSauypAxZGG3quqtR19utqsQTmot4BPSr8KoqPRUZWfhZ6rDC9SkH45Lu4gcU34pyeKudv.

No outbound movement from the collection wallet was observed in the 60-day window. Both counterparties were unlabeled. This means the supplied collection wallet explains only a small fraction of the reported loss and does not itself prove the subsequent swap, bridge, or mixer path.

REPORTED FUND FLOW AND EVIDENCE BOUNDARY

Blockaid describes a route from drained USDC and USDT through Solana DEX swaps into SOL, across deBridge to Ethereum, and finally into Tornado Cash. The diagram below shows that reported path while marking the mixer as the deterministic endpoint boundary.

WHAT THE EVM SEEDS DO—AND DO NOT—PROVE

The supplied address 0xa1a15f1b0d4878873f2933573e4385ab1e4df25c had no relevant value-flow connection to the Solana incident in the observed window and retained only about $4.39. The second seed, 0x775028b2ce02844e8947905e4d655940a76cf559, had an active multi-exchange history, but SentinelTX found no taint-traceable path from the Rain exploit. Service contacts visible around that address—including Binance, Bybit, MEXC, FixedFloat, Cryptomus, Bitpanda and CoinEx—must not be presented as destinations of Rain proceeds without that missing link.

The Tornado Cash router 0xd90e2f925DA726b50C4Ed8D0Fb90Ad053324F31b is independently labeled as a sanctioned mixer. The identity of the service is confirmed; the claimed 455.9 ETH incident deposit is not confirmed by this investigation.

WAS THE ENTIRE WALLET TRAIL TRACED?

No. Deterministic tracing stops at the supplied seeds because the collection wallet showed no outbound transaction in the observed window and neither EVM seed could be connected to the verified Solana inflows. The three strongest next steps are: obtain the full AddCollateralAdmin and WithdrawCollateralAsset transaction sets for all four matching deployments; trace upstream from HEgJutJjfCyG7RDtcS9xBc8sbty31TsqK3VCxyh4s7K1; and identify the reported 455.9 ETH Tornado Cash deposit cluster before tracing backward to a bridge arrival.

CONCLUSION

The most defensible conclusion is narrower than the headline. A shared, outdated authorization design reportedly widened one exploit across multiple card programs. SentinelTX confirmed two incident-date inflows and the mixer router’s identity, but it did not close the chain from those Solana inflows to the reported cross-chain laundering path. The gap between $1.1 million reported and 1,780.973441 USDC independently anchored points to missing wallet sets or incomplete public seeds.

That distinction matters: a labeled exchange contact is not automatically incident proceeds, and a published mixer address is not proof of a specific deposit. The next investigation should begin from the deployment-level withdrawal transactions, not from assumptions about the supplied EVM wallets.

SOURCES

Blockaid, “$1.1M Rain Ecosystem Exploit: How Onchain Monitoring Gives Stablecoin Card Issuers Fleet-Level Coverage” (2 September 2026): https://blockaid.io/blog/11m-rain-ecosystem-exploit-how-onchain-monitoring-gives-stablecoin-card-issuers-fleet-level-coverage

SentinelTX case CASE-ASYNCBE3, investigated 4 September 2026.

APPENDIX — EVIDENCE STATUS TABLE

post_like_sub0
post_total_comment_sub0

3 reads

0/500 bytes