Every affected user has now received their full refund, plus an additional 10% to each user.
We worked closely with Rain and our security partners from identification through resolution.
Building for the long term means choosing partners who share the same standard when it matters most: put users first and make things right.
Thanks,
@raincards , for moving quickly with us.
All affected card balances are being made whole in full.
Here's what happened and where things stand.
Our card-issuing partner, Rain, identified a vulnerability in a Solana card contract used by Tria and other Rain program cards. It has been upgraded and fixed across all programs, and no further unauthorised activity has been seen since.
Your Tria wallet was never affected. Wallets and card balances live in different places. Your wallet is self-custodial and stayed under your control throughout. When you top up your card with Solana assets, that money moves into a separate Solana contract, and that contract is the only thing this touched. Everything held in Tria wallets - EVM, Aptos, Solana and others is untouched.
Reconciliation so far shows 636 users affected, totalling $431,945 in card balances. Every one of them is being refunded in full.
We're working closely with Rain and our security partners while remediation completes, and we'll confirm here once refunds have landed.
To everyone affected: thank you for your patience. Your trust is what Tria is built on, and we will always stand by our users.