Who hacked Rain and took $1M: an on-chain investigation
I traced the exploit on-chain and found a chain of connected wallets that leads straight out to centralised exchanges and payment processors. Those are the services that can turn this attacker from an address into a name
Here is the trail, wallet by wallet
- 13:38 UTC, 0.0794667 ETH leaves 0x775028B2CE02844e8947905E4d655940a76cf559
- 13:40 UTC, it lands on a fresh address 0xa1a15f1b0d4878873f2933573e4385ab1e4df25c, created for this one job
- 13:40 UTC, it is bridged into 1.78855 SOL and arrives at the attacker wallet FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj
- 16:56 UTC, the draining of the contract starts
Then I ran the funding address through its own history. It has direct deposits and withdrawals with seven services: Binance, Bybit, HTX, MEXC, Cryptomus, BitPanda and Heleket
1. Heleket
On August 20 the address 0x775...f559 received four transfers from 0x22a10b43952479f7306e147789aed8e19a00fa7b:
- 08:51:47, received 38,626.90175 USDC (TxId: 0xd1feabf8b153506310c598daa9ef331fe1700424503ad94dbd4e6440a076164c)
- 08:51:47, received 2.15 ETH (TxId: 0xb12e826a8b0ded9bc6c55991178203e068daab55b393fd0ddb89a533d542ff91)
- 08:51:47, received 1,495 DAI (TxId: 0x3ac4c63b93df6313dc875966f41b9f886858baff8cebb4a5defa643ed1bdfb94)
- 08:51:47, received 16,888.808742 USDT (TxId: 0x1dcd56b07d81ff65d503d5309dfed17f9c8313eae7d138e4f6326f3880883bbb)
2. @Bitpanda_global
- August 24, 09:41:35, sent 497.35 USDT to 0xa9F623Eb84a995dB4D2F785D272Ad70E3fB7B8C1 (TxId: 0xcdce3fb52b647d8bc20b48a0117ee7a7b5b5965349aee17b93560ac929190823)
- August 26, 13:34:23, received 497.35 USDT from 0x74dec05e5b894b0efec69cdf6316971802a2f9a1 (TxId: 0x52b1abd63b7906f4e214e0f49fd2ff283a5ea4d45d9e9bf0c80a2daf373a2ec5)
3. @Cryptomus
- August 25, 09:05:01, sent 20.01 USDT to 0x107B844868FDeFC79AA8B8435A691662D3aD1C38 (TxId: 0xcdf828de0b636e180a36315af89ab066bc06124596fac56281eb69a23f196bfe)
- August 25, 17:50:47, sent 264.99 USDT to 0x71e3aF92EDD52Bb241bcE04666F2791b7862D965 (TxId: 0x01f75fdb347c902c12e279c044a129e9a7ba484e9811323c826092dde1006dea)
- August 25, 19:07:47, sent 50 USDT to 0xBA701bAD11519D47eb227E9bA6A1894e0850e981 (TxId: 0x2de031799e11ffb5fc4a4968dc99fc6f3302d0736e63966734bd61e64966537d)
- August 26, 00:23:59, sent 56.84 USDT to 0x667736E5be4f62A7107E4450d5a8578bC3C086C4 (TxId: 0xf1b110fe4c531567e0942b5c0cf51d7254a15651d377e65c2c0ba056150ac858)
- August 28, 13:05:47, sent 71.99 USDT to 0xB09f2c950b4240172E7374b6699F1710Ce668837 (TxId: 0x40fcd7d5e5d66d125486b177229c378040c22d760732e7986a20953c4dde61ac)
4. @Bybit_Official
- August 20, 12:07:35, sent 74.137749 USDT to 0xd94a0736980a883b2f914214653d2Db38662Ddd6 (TxId: 0x4a4a70706189d73d60b160ebcad31d59df5bcfa291229ffc660fb6ec8ce1d23c)
- August 24, 05:45:35, sent 11.52 USDT to 0x42A1CaB49e6Cf3317137a6deF72Cafe73bde2353 (TxId: 0x3cc75351f1efefbda1840a71db2c5737407eb8f738b1f9c0c1836a71c13d94b1)
- August 26, 06:03:11, sent 56.679 USDT to 0xd94a0736980a883b2f914214653d2Db38662Ddd6 (TxId: 0xbc4bec9d4e22fb8c61ea2b3c46479fb73e149cfeedacdc8dd870254c4516e1e7)
- August 26, 20:03:23, sent 111.268 USDT to 0xd94a0736980a883b2f914214653d2Db38662Ddd6 (TxId: 0xcbd5e22ae08f1ae8f8826d13079872cddff5a2c89f2bc53dde870fcc576d0f14)
- August 27, 16:03:11, sent 61.287166 USDT to 0xd94a0736980a883b2f914214653d2Db38662Ddd6 (TxId: 0x608139eb482ec2ee1bae67a6fed7523ddcf8ab85bc8d6470e25e803ce2b281a8)
- August 28, 11:04:47, sent 221 USDC to 0xa5B97c97E27f9865dDb61f073625A6eB3c6B45aa (TxId: 0x7204bef64536e18052842e4ac5f424dd53e9aea1723c13965cd72dcd164ca168)
- August 28, 19:03:11, sent 64.446 USDT to 0xd94a0736980a883b2f914214653d2Db38662Ddd6 (TxId: 0xdb9b6b84c659a5c19acdaea46811c93282c31cd296a7aa8f71ffc1db4dab6c19)
5. @MEXC
- August 26, 07:42:23, sent 30 USDC to 0x7CfF146DE88686473e2aaC08595E2bd1Ab53cA20 (TxId: 0xf841c846e3b2081f4fac15e2061330e4f35a1ea30aa4fa2ac40ddde606d04850)
6. @HTX_Global
- August 27, 11:13:47, sent 49.88 USDT to 0x097f9127b7FA721dD31E2b03Bf592B73ca556EcF (TxId: 0xb1a5c44a99bffa4430e72a1524801f31fab0242e0512025d1455517a512cfd44)
One pattern is worth pulling out before the last service. On Binance the four transfers went to four different deposit addresses. On Bybit five of the seven went to the same one, 0xd94a0736980a883b2f914214653d2Db38662Ddd6, across eight days. A deposit address that gets reused is a handle on a single account, which makes it the strongest lead in here. And the Bybit transfer at 19:03:11 on August 28 went out while the contract was still being drained
7. @binance
- August 27, 17:48:23, sent 25 USDT to 0x754D16DDEbE107E862B57B716b9A5eA4472EcaE7 (TxId: 0xd3deb4f6e50b1e90ff3b7e7af3836de26d4f30636537abe345ec760427d1fbd1)
- August 28, 16:15:11, sent 400 USDT to 0x649B873Eaf791f5A0C6C0237E3CE752ED231b4Ab (TxId: 0x309f093901870cc20f5612ceb57ae5ad8217eb728c5404edbe51773082b2ec36)
- August 28, 16:15:35, sent 400 USDT to 0x1C1275633d060A4C86DAcdfc4345941E276e8Fbd (TxId: 0x786c465939891542ca2b807b5a9d4d24a1310b472cec425c003a7a6fb162adb6)
- August 28, 16:50:23, sent 618.27 USDT to 0xAD5AdEBcb567592b0D487861c438deeeb99FC082 (TxId: 0x0d5eff682cb42cb376166a37e1307c56ae36e33481807b28638ab3127d0a796d)
8. It did not stop on August 28
- August 29, 19:33:59, sent 50 USDC to 0xabC802b8c854db09c954fBCEfF9F2A273623594d (TxId: 0xcd4dc3124ad4198ca1be2d87d839191835898fe6f8ea4f974bc28f485a1ca1c4)
- 30 minutes later that address paid through Cryptomus, to 0xf52605c7b778563a5a9144EF4Dc53B57463ca2c7 (TxId: 0xf9625b1d44e0db9ec1b83efe2c7c40d017a8c07f8287aeabe35c4a893da65462)
A full day after the hack, on the same rails, in no hurry at all
Seven services may be sitting on a name, a document and an IP right now
@zachxbt you have taken cases apart with far less than this, and I would really like your read on it. The addresses are still warm
@raincards should be running its own investigation and filing information requests with all seven services. That is how an attacker stops being a wallet address and starts being a person
UPDATE: Refunds are processed in full, with an extra 10% cashback.
The Solana contract has been updated. We haven't seen any further related activity, and we're constantly monitoring it.
If your Solana card balance was withdrawn a few hours ago, we've restored the full amount and added 10% cashback on what was withdrawn. Open the app and cross-check your balance.
Here's exactly what was affected and what wasn't:
1. This was limited to card contracts on Solana holding balances added through Avici's Top Up flow.
2. Your regular Avici Solana and EVM wallets were never affected. Those wallets are self-custodial and stayed under your control the entire time.
3. EVM card balances, onramps, offramps, and swaps were not affected.
4. Funds outside these Solana card-balance contracts were never exposed.
We made a very deliberate choice to keep your Avici wallet separate from your card balance. It's why you have to manually Top Up before spending. Combining both would've made the app easier to use, but we didn't do it because we believed keeping them separate was safer.
That separation is why this stayed limited to the affected Solana card contracts while wallets and everything else in Avici stayed untouched. That doesn't make what affected users went through okay. We're sorry for the stress and uncertainty this caused.
We're not proud that this happened. We are proud that Avici is built onchain, where balance movements are immediately visible and independently verifiable instead of hidden behind a private ledger. In traditional fintech, the number shown in an app can stay unchanged while what is happening underneath remains invisible. Here, anyone could see the movement onchain as it happened.
We're pushing the frontier of onchain finance, and that road was never going to be easy. Moments like this are painful and humbling, but they show us what has to improve and will make Avici stronger. We're not stepping back. We're going to keep pushing forward.
Rain, our card issuing partner, covered all reimbursements in full. Huge credit to their team for moving quickly, working closely with us, restoring every affected balance, and fixing the issue.
We'll publish a full postmortem once the investigation is complete.
And a huge thank you to every partner who jumped in immediately to help us through this: @solana, @raincards, @Helius, @MetaDAOProject, @zeroshadow_io, and @asymmetric_re.
Thank you for staying with us through the uncertainty and stress this caused today.
We’re aware of an issue affecting card balance withdrawals and are closely monitoring the situation.
We’re working directly with all relevant partners to resolve it and will share updates as soon as we have more information.
We’re aware of an issue affecting card balance withdrawals and are closely monitoring the situation.
We’re working directly with all relevant partners to resolve it and will share updates as soon as we have more information.
Benar2 menguji kesabaran saya n komunitas metadao.
Inilah resiko yang harus dihadapi, selalu tempat kan dana anda di 7 tempat yang tidak berkorelasi satu sama lain. Thanks to @avici n @RamXBT I am believe in your vision. @0xVishnya@Ponyin@bukanpamanmu. Sudah selesai dng crypto
We’re aware of an issue affecting card balance withdrawals and are closely monitoring the situation.
We’re working directly with all relevant partners to resolve it and will share updates as soon as we have more information.
UPDATE: All affected card balances will be refunded in full
Earlier today, our card-issuing partner, Rain, identified a vulnerability in an version of a Solana card contract used by Avici and a small number of other programs. The contract has now been upgraded across all programs, and no further unauthorised activity has been observed.
Avici wallets and card balances are separate. Avici wallets are self-custodial and remain under users’ control.
When users top up their cards, funds move into a separate Solana contract that holds their card balance. Only this contract was affected.
Note: Funds held in Avici’s Solana and EVM wallets are safe and were not affected.
Our current reconciliation shows that 1,685 users were affected, representing $500,859.22 in card balances.
Every affected user will have their card balance refunded in full. We remain in close contact with our card-issuing and security partners and are monitoring the remediation closely.
Avici has also filed a report with the FBI’s Internet Crime Complaint Center. We are deeply sorry for the concern and inconvenience this has caused.