← Tria1 decision on this page
Audit log
Every state-changing event for Tria: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-09-12 17:13:07ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 446,483,452
- sig
4V3mVbEqovum…qKB3mCpRexplorer ↗- hash
F2j9cMX8mnNG…fQW47e64sha256 → base58
verifying row…full verify ↗canonical bytes (16008 B) ▸
{"actor":"system:backfill","investigation_id":"2b1199a5-230d-4bf3-ab2e-5faf5f53ab7a","kind":"publish","page_slug":"tria","published_at":"2026-09-12T17:13:07.256Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Tria","sections":[{"content":"Tria was co-founded by Vijit Katta (CEO) and Parth Bhalla (CTO) in 2022. Katta previously built Polygon's in-house accelerator and held commercial roles at GSK and AstraZeneca; he holds a computer science degree from BITS Pilani and an MBA from INSEAD. The company raised $12 million in pre-seed and strategic funding announced on October 14, 2025, with participation from P2 Ventures, Aptos, and executives from Polygon, the Ethereum Foundation, Wintermute, and EigenLayer. Tria markets itself as a self-custodial neobank offering a Visa card operable in more than 150 countries, gasless cross-chain trading, and on-chain yield products. Its BestPath AVS routing engine is built in collaboration with EigenLayer and supports transactions across EVM, Solana, Move-VM, Cosmos, and Bitcoin L1 environments. The platform reported approximately 250,000 users serviced through its routing technology at the time of its funding announcement.","heading":"Background and Founding","severity":"low","sources":[{"credibility":2,"name":"Tria Raises $12M to Be the Leading Self-Custodial Neobank and Payments Infrastructure for Humans and AI","type":"news_article","url":"https://cryptoslate.com/press-releases/tria-raises-12m-to-be-the-leading-self-custodial-neobank-and-payments-infrastructure-for-humans-and-ai/"},{"credibility":3,"name":"Tria (TRIA): The Self-Custodial Crypto Neobank for Daily Use — Bitget Academy","type":"other","url":"https://www.bitget.com/academy/what-is-tria-self-custodial-crypto-neobank-how-it-works-price-prediction"}]},{"content":"On August 28, 2026, an attacker exploited an authorization-bypass vulnerability in an outdated version of the Rain Solana card contract to drain card-collateral balances from users of multiple neobank products, including Tria. According to Blockaid's on-chain analysis, the exploit worked by reusing a single attacker-controlled signature so that the contract's dual-authorization check accepted it as two independent approvals. The attacker then invoked the AddCollateralAdmin function to register a controlled address as administrator over individual user card-collateral accounts, and subsequently called WithdrawCollateralAsset to extract USDC and USDT without account-owner consent. Tria's self-custodial wallets — holding user assets across EVM, Aptos, Solana, and other chains — were not affected. Only funds that users had pre-loaded onto the card contract for spending were at risk. Blockaid recorded 2,945 administrator additions and 5,288 withdrawal calls across 8,233 exploit transactions over approximately two hours and 29 minutes, beginning at roughly 16:49 UTC. The attacker's Solana wallet address was publicly identified as FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj. Stolen USDC and USDT were converted to SOL via decentralized exchanges, bridged to Ethereum through deBridge, and approximately 455.9 ETH entered Tornado Cash mixers between 19:20 and 19:49 UTC on the same day. Tria disclosed that 636 of its users lost a combined $431,945 in card balances. The same underlying Rain contract flaw simultaneously affected Avici (1,685 users, $500,859.22) and, according to search-aggregated reporting, a third program identified by Blockaid as Solayer Pay. Total confirmed losses across Tria and Avici alone exceeded $932,800; total cross-product losses were estimated at approximately $1.1 million. Rain subsequently stated that every program running the outdated contract version had been upgraded and that no further unauthorized activity occurred after the patch.","heading":"August 2026 Rain Card Contract Exploit","severity":"high","sources":[{"credibility":1,"name":"A Solana-based $1.1 million crypto card hack crashed a neobank's token 49% — CoinDesk","type":"news_article","url":"https://www.coindesk.com/web3/2026/08/29/a-usd1-1-million-crypto-card-hack-crashed-a-neobank-s-token-49"},{"credibility":2,"name":"Rain contract exploit drains $1.1M from card users — crypto.news","type":"news_article","url":"https://crypto.news/rain-contract-exploit-drains-1-1m-from-card-users/"},{"credibility":2,"name":"Tria Details Rain Card Vulnerability: 636 Users, $431,945 Refunded — SpendNode","type":"news_article","url":"https://www.spendnode.io/blog/tria-rain-solana-card-vulnerability-636-users-refund-august-2026/"},{"credibility":2,"name":"Exploit on Rain crypto payments infrastructure provider causes losses for self-custodial neobanks — Web3 Is Going Just Great","type":"news_article","url":"https://www.web3isgoinggreat.com/single/avici-exploit"},{"credibility":2,"name":"Avici - Rain Card Exploit Explained: What Happened? — GizmoTimes","type":"news_article","url":"https://www.gizmotimes.com/security/avici-rain-card-exploit-solana-vulnerability-explained/51243"},{"credibility":2,"name":"Rain Card Exploit Drains $1.1 Million From Solana Users — Blockonomi","type":"news_article","url":"https://blockonomi.com/rain-card-exploit-drains-1-1-million-from-solana-users"}]},{"content":"The Rain exploit surfaced a structural tension in Tria's product design. Tria markets itself as a self-custodial platform, meaning users retain direct control of their assets in personal wallets. However, using the Visa card product required users to pre-load funds into a Rain-administered collateral contract — effectively transferring custody of those balances to a third-party smart contract. As noted by Web3 Is Going Just Great, this architecture meant that funds staged for card spending were held in a shared infrastructure contract rather than in the user's own wallet, creating a single point of failure across multiple consumer-facing neobank products. Rain has not publicly disclosed which audit firms reviewed the vulnerable contract version, when the defect was introduced, or what deployment controls existed to prevent version drift. The absence of these disclosures leaves open the question of whether the outdated contract was an isolated operational lapse or indicative of broader infrastructure governance gaps.","heading":"Supply-Chain Risk: Self-Custody Branding vs. Third-Party Contract Exposure","severity":"high","sources":[{"credibility":2,"name":"Exploit on Rain crypto payments infrastructure provider causes losses for self-custodial neobanks — Web3 Is Going Just Great","type":"news_article","url":"https://www.web3isgoinggreat.com/single/avici-exploit"},{"credibility":2,"name":"Tria Details Rain Card Vulnerability: 636 Users, $431,945 Refunded — SpendNode","type":"news_article","url":"https://www.spendnode.io/blog/tria-rain-solana-card-vulnerability-636-users-refund-august-2026/"},{"credibility":2,"name":"Crypto Cards in 2026: Who Holds the Money Before the Swipe — DeFi Prime","type":"research","url":"https://defiprime.com/crypto-cards-who-holds-the-money"}]},{"content":"Tria's native token declined more than 10% immediately following public disclosure of the exploit. By contrast, co-affected neobank Avici saw its token fall approximately 49% in the same period, according to CoinDesk reporting. Tria pledged full refunds for all 636 affected users and announced an additional 10% bonus on top of principal losses, as reported by multiple sources. As of the SpendNode article updated September 2, 2026, Tria stated it would confirm the completion of remediation with Rain and security partners before releasing final refund details. No independent confirmation of completed refund disbursements had been published at the time sources were gathered for this page.","heading":"Token Price Impact and Refund Commitment","severity":"medium","sources":[{"credibility":1,"name":"A Solana-based $1.1 million crypto card hack crashed a neobank's token 49% — CoinDesk","type":"news_article","url":"https://www.coindesk.com/web3/2026/08/29/a-usd1-1-million-crypto-card-hack-crashed-a-neobank-s-token-49"},{"credibility":2,"name":"Tria Details Rain Card Vulnerability: 636 Users, $431,945 Refunded — SpendNode","type":"news_article","url":"https://www.spendnode.io/blog/tria-rain-solana-card-vulnerability-636-users-refund-august-2026/"},{"credibility":2,"name":"Rain contract exploit drains $1.1M from card users — crypto.news","type":"news_article","url":"https://crypto.news/rain-contract-exploit-drains-1-1m-from-card-users/"}]},{"content":"After draining USDC and USDT from card-collateral accounts, the attacker consolidated proceeds in Solana wallet FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj. The stolen stablecoins were then swapped to SOL via decentralized exchanges and bridged to Ethereum through deBridge. Approximately 455.9 ETH entered Tornado Cash mixers between 19:20 and 19:49 UTC on August 28, 2026. Blockonomi reported that two Ethereum addresses were used to fund the attacker's initial Solana activity; neither address had been publicly attributed as of the reporting date. No law enforcement action, regulatory inquiry, or blockchain analytics firm attribution report had been publicly disclosed at the time this page was compiled.","heading":"Attacker Fund Movement and Obfuscation","severity":"high","sources":[{"credibility":2,"name":"Rain contract exploit drains $1.1M from card users — crypto.news","type":"on_chain","url":"https://crypto.news/rain-contract-exploit-drains-1-1m-from-card-users/"},{"credibility":2,"name":"Rain Card Exploit Drains $1.1 Million From Solana Users — Blockonomi","type":"on_chain","url":"https://blockonomi.com/rain-card-exploit-drains-1-1-million-from-solana-users"},{"credibility":2,"name":"Avici - Rain Card Exploit Explained: What Happened? — GizmoTimes","type":"news_article","url":"https://www.gizmotimes.com/security/avici-rain-card-exploit-solana-vulnerability-explained/51243"}]}],"sources_used":[{"credibility":1,"name":"A Solana-based $1.1 million crypto card hack crashed a neobank's token 49% — CoinDesk","type":"news_article","url":"https://www.coindesk.com/web3/2026/08/29/a-usd1-1-million-crypto-card-hack-crashed-a-neobank-s-token-49"},{"credibility":2,"name":"Tria Details Rain Card Vulnerability: 636 Users, $431,945 Refunded — SpendNode","type":"news_article","url":"https://www.spendnode.io/blog/tria-rain-solana-card-vulnerability-636-users-refund-august-2026/"},{"credibility":2,"name":"Rain contract exploit drains $1.1M from card users — crypto.news","type":"news_article","url":"https://crypto.news/rain-contract-exploit-drains-1-1m-from-card-users/"},{"credibility":2,"name":"Exploit on Rain crypto payments infrastructure provider causes losses for self-custodial neobanks — Web3 Is Going Just Great","type":"news_article","url":"https://www.web3isgoinggreat.com/single/avici-exploit"},{"credibility":2,"name":"Avici - Rain Card Exploit Explained: What Happened? — GizmoTimes","type":"news_article","url":"https://www.gizmotimes.com/security/avici-rain-card-exploit-solana-vulnerability-explained/51243"},{"credibility":2,"name":"Rain Card Exploit Drains $1.1 Million From Solana Users — Blockonomi","type":"news_article","url":"https://blockonomi.com/rain-card-exploit-drains-1-1-million-from-solana-users"},{"credibility":2,"name":"Tria Raises $12M to Be the Leading Self-Custodial Neobank — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/press-releases/tria-raises-12m-to-be-the-leading-self-custodial-neobank-and-payments-infrastructure-for-humans-and-ai/"},{"credibility":3,"name":"Tria (TRIA): The Self-Custodial Crypto Neobank for Daily Use — Bitget Academy","type":"other","url":"https://www.bitget.com/academy/what-is-tria-self-custodial-crypto-neobank-how-it-works-price-prediction"},{"credibility":2,"name":"Crypto Cards in 2026: Who Holds the Money Before the Swipe — DeFi Prime","type":"research","url":"https://defiprime.com/crypto-cards-who-holds-the-money"},{"credibility":2,"name":"Rain contract exploit drains $1.1 million from Solana card programs — NewsBytesApp","type":"news_article","url":"https://www.newsbytesapp.com/news/business/rain-contract-exploit-drains-11-million-from-solana-card-programs/tldr"}],"summary":"Tria is a self-custodial Solana-based neobank founded in 2022 by Vijit Katta and Parth Bhalla that raised $12 million in pre-seed and strategic funding in October 2025. On August 28, 2026, an attacker exploited an authorization-bypass vulnerability in an outdated Rain Solana card contract shared across multiple neobank products, draining $431,945 from 636 Tria card users. Tria pledged full refunds plus a 10% bonus to affected users; its native token fell more than 10% following public disclosure. The incident did not affect user self-custodial wallets — only card-collateral balances staged for spending were compromised.","timeline":[{"date":"2022-01-01","event":"Tria co-founded by Vijit Katta (CEO) and Parth Bhalla (CTO) as a self-custodial neobank.","source":"Bitget Academy — What Is Tria","source_url":"https://www.bitget.com/academy/what-is-tria-self-custodial-crypto-neobank-how-it-works-price-prediction"},{"date":"2025-10-14","event":"Tria announces $12 million in pre-seed and strategic funding from P2 Ventures, Aptos, and executives from Polygon, Ethereum Foundation, Wintermute, and EigenLayer.","source":"CryptoSlate press release","source_url":"https://cryptoslate.com/press-releases/tria-raises-12m-to-be-the-leading-self-custodial-neobank-and-payments-infrastructure-for-humans-and-ai/"},{"date":"2026-08-28","event":"Attacker's Solana wallet (FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj) begins exploiting an authorization-bypass flaw in an outdated Rain Solana card contract at approximately 16:49 UTC.","source":"GizmoTimes — Avici Rain Card Exploit Explained","source_url":"https://www.gizmotimes.com/security/avici-rain-card-exploit-solana-vulnerability-explained/51243"},{"date":"2026-08-28","event":"Exploit runs for approximately 2 hours and 29 minutes; Blockaid records 8,233 transactions including 2,945 admin additions and 5,288 withdrawal calls. Tria loses $431,945 across 636 users. Avici loses $500,859 across 1,685 users. Total losses estimated at $1.1 million.","source":"crypto.news — Rain contract exploit drains $1.1M from card users","source_url":"https://crypto.news/rain-contract-exploit-drains-1-1m-from-card-users/"},{"date":"2026-08-28","event":"Approximately 455.9 ETH enters Tornado Cash mixers between 19:20 and 19:49 UTC after stolen stablecoins are swapped to SOL and bridged to Ethereum via deBridge.","source":"Blockonomi — Rain Card Exploit Drains $1.1 Million From Solana Users","source_url":"https://blockonomi.com/rain-card-exploit-drains-1-1-million-from-solana-users"},{"date":"2026-08-29","event":"CoinDesk reports on the exploit; Tria's native token falls more than 10% and Avici's token falls approximately 49% following public disclosure. Tria pledges full refunds plus a 10% bonus to all 636 affected users.","source":"CoinDesk — A Solana-based $1.1 million crypto card hack crashed a neobank's token 49%","source_url":"https://www.coindesk.com/web3/2026/08/29/a-usd1-1-million-crypto-card-hack-crashed-a-neobank-s-token-49"},{"date":"2026-08-29","event":"Rain states that every program running the outdated contract version has been upgraded and that no further unauthorized activity occurred after the patch.","source":"Blockonomi — Rain Card Exploit Drains $1.1 Million From Solana Users","source_url":"https://blockonomi.com/rain-card-exploit-drains-1-1-million-from-solana-users"},{"date":"2026-09-02","event":"SpendNode publishes updated details of Tria's disclosure: 636 users affected, $431,945 total loss, full refund commitment pending confirmation of completed remediation with Rain and security partners.","source":"SpendNode — Tria Details Rain Card Vulnerability: 636 Users, $431,945 Refunded","source_url":"https://www.spendnode.io/blog/tria-rain-solana-card-vulnerability-636-users-refund-august-2026/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 95d15aca-ca1e-4e85-a21a-a169a7570448
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.