Tria has put hard figures on the Solana card incident it first flagged on August 28. In a follow-up post, the vendor said the flaw sat in a Solana card contract run by its issuing partner, Rain, and that reconciliation so far shows 636 users affected across $431,945 in card balances. Every one of those users is being refunded in full.
The disclosure follows Tria's earlier notice that the "issue affecting Solana card balances has now been resolved." This update names the cause and quantifies the damage, moving the story from a resolved outage to a documented post-mortem.
The flaw sat in the card contract, not the wallet
Tria drew a hard line between two places money lives in its app. Balances held in a self-custodial wallet were never in scope. When you top up a Tria card with Solana assets, that money leaves the wallet and moves into a separate Solana contract, and that contract is the only thing the vulnerability touched.
"Your Tria wallet was never affected. Wallets and card balances live in different places," the company wrote. Holdings across EVM, Aptos, Solana, and other chains inside Tria wallets stayed under user control throughout.
The distinction matters for how much users can read into the event. A wallet compromise would implicate Tria's core self-custody model. A card-contract flaw is narrower: it affects funds that have already been staged for spending, and it points at the card-issuing layer rather than the wallet architecture.
Rain is the shared point of failure
Rain is the card-issuing partner behind Tria and several other programs. Tria said Rain identified the vulnerability, that the contract has been upgraded and fixed across all programs, and that no further unauthorized activity has been seen since the patch.
Because Rain sits under multiple front-end brands, the same contract flaw rippled beyond Tria on the same day. Avici told its users it would refund all affected card balances after the same partner incident. Jupiter's card partner briefly paused withdrawals as a precaution before confirming no user funds were at risk. Others, including KAST and Ether Fi, posted that they were not affected at all.
That spread is the real lesson here. When several consumer card brands lean on one issuing processor and one shared contract, a single bug becomes an industry-wide event in hours rather than a problem contained to one app.
Steps for affected cardholders
If you hold a Tria card and topped it up with Solana assets, your card balance is the part that was exposed, and Tria says it is making those balances whole in full. The company is still completing remediation with Rain and its security partners and said it will confirm again once refunds have landed. Watch for that confirmation and check that your refunded balance matches what you held before the incident.
If you only ever kept funds in your Tria wallet and never moved them onto the card, nothing about this touched you. Payments through the card also kept working across the affected programs, so the disruption was to withdrawals and balance integrity on the card contract, not to point-of-sale spending.
For anyone weighing a card that stages stablecoin balances on-chain, the practical takeaway is to treat the card-contract layer as a distinct risk surface from wallet custody, and to keep only what you plan to spend loaded onto the card.
Overview
Tria's second statement turned a vague "resolved" note into a specific accounting: 636 users, $431,945 in card balances, a patched Rain contract, and full refunds in progress. Wallet holdings were never in scope. The event is less a Tria-specific failure than a demonstration of concentration risk in the crypto card supply chain, where one issuing partner's contract underpins several brands at once. The open item is confirmation that every refund has landed, which Tria said it will post when remediation completes.



