At 16:49:48 UTC on Friday, August 28, 2026, a critical vulnerability within the Solana-based infrastructure used by several neobanking platforms resulted in the unauthorized drainage of over $500,000 from consumer card accounts. The breach, which primarily affected users of Avici and Tria, exposed the inherent risks in the burgeoning "non-custodial" crypto card sector. While the industry frequently markets these products as being free from the traditional custody risks associated with centralized exchanges, the August incident demonstrated that legal definitions of non-custodial status often fail to account for the technical realities of smart contract management, upgrade authorities, and shared infrastructure.
The incident originated from a wallet that had been funded just three hours prior with 1.79 SOL, purchased with approximately $190 in USDC bridged from Ethereum. This wallet remained dormant until it began systematically emptying user card-balance accounts. According to reconciliation reports published by Avici at 20:44 UTC on the same day, 1,685 users suffered losses totaling $500,859.22. The funds were held within a Solana card contract utilized by Avici and several other programs. This contract was maintained by Rain, the card-issuing company that serves as the backbone for a significant portion of the self-custodial card market. By the following day, Avici and Tria confirmed that all affected users were fully reimbursed, with both companies adding a 10% premium to the refunded amounts, a move intended to restore market confidence in their respective platforms.
The Anatomy of the Solana Exploit
The breach was not the result of stolen private keys or compromised user wallets, which would have been the case in a typical crypto-wallet hack. Instead, it was an authorization flaw within the smart contract architecture. The attacker’s wallet, identified as FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj, executed 21,405 transactions within a two-hour and twenty-nine-minute window, of which approximately 17,500 were successful.
Each successful transaction followed a precise three-step sequence against the Rain-controlled Solana program: a SubmitSignatures call utilizing the native Ed25519 signature-verification instruction, followed by AddCollateralAdmin and finally WithdrawCollateralAsset. The flaw resided in the signature-verification logic; the attacker manipulated the signature, key, and message offsets to point back to a single signature, thereby satisfying a requirement that was intended to necessitate two separate signatures. This granted the attacker administrative status over the collateral accounts.
The impact was swift and precise. The median account lost approximately $24, while the largest individual loss in the sampled data reached $5,268. Furthermore, the attacker moved to liquidate the stolen assets quickly. At 19:03:18 UTC, while the exploit was ongoing, a deBridge order moved over 1 million USDC from Solana to Ethereum, which was subsequently funneled through Tornado Cash in a standard laundering pattern. By the time Rain patched the vulnerability, the funds had been effectively moved beyond recovery.
The Landscape of Crypto Card Custody in 2026
The August event serves as a focal point for a broader inquiry into the "non-custodial" card industry. Paymentscan data indicates that crypto card volume reached $1.116 billion in August 2026, spanning 11 million transactions and 287,640 active addresses. This represents a significant increase from $153 million in December 2024. However, this growth is accompanied by increased complexity and fragmentation in how these platforms define the custody of user funds.
Custody models in the current market generally fall into five distinct categories:

- Sale to the Operator: In models like KAST, user deposits are treated as a sale of assets to the company in exchange for a debt claim. Users retain no ownership of the original cryptocurrency and are essentially unsecured creditors in the event of bankruptcy.
- Custodial Nominee: Platforms like RedotPay and Revolut hold assets on behalf of the user, with the company maintaining legal title.
- Fiat Conversion: Exchanges like Crypto.com and Kraken move crypto into fiat currency at the point of sale, with the fiat funds often held by a licensed electronic money institution (EMI).
- Contractual Collateral: This is the category occupied by Avici, Tria, and other Rain-based programs, where funds are held in smart contracts. While users technically own the collateral, the upgrade authority and administrative logic remain with the program manager.
- Direct Vault Debit: The most robust model, utilized by Gnosis Pay and Ether.fi Cash, involves smart accounts where the operator cannot move funds, and spending is scoped specifically to the card transaction.
The Role of Third National and Rain
A substantial portion of the self-custodial market relies on a single entity for card issuance: Third National. This entity is not a traditional chartered bank, but rather a Puerto Rico-licensed money transmitter operating under the Rain umbrella. Rain’s business model involves leveraging a network of capital partners to borrow stablecoins, which are then used to facilitate network settlement for credit card receivables.
When a user makes a purchase, the card network (Visa) settles with the merchant, Rain pays Visa from borrowed capital, and is subsequently repaid from the user’s collateral contract. This means that these "non-custodial" cards are essentially charge cards financed by institutional capital. The concentration of this infrastructure—with seven of the 18 examined programs using the same issuer—creates a systemic vulnerability. While concentration is not inherently synonymous with fragility, it does mean that a single codebase error or regulatory change can impact a wide swath of the market simultaneously.
Regulatory and Market Implications
The regulatory environment is shifting rapidly. The European Union’s Anti-Money Laundering Regulation (EU 2024/1624), which comes into full effect in July 2027, aims to close many of the loopholes that have allowed anonymous or "no-KYC" cards to proliferate. The regulation explicitly bars credit and financial institutions from maintaining anonymous crypto-asset accounts and places strict limits on the use of non-reloadable prepaid cards.
Market participants have already begun to feel the pressure. Programs like Bit.Store saw services discontinued after their underlying EMI, Paytend Europe, lost its license. Similarly, the Kulipa infrastructure shutdown in July 2026, while not resulting in lost user funds due to its non-custodial nature, forced several prominent platforms to cease operations overnight. These events reinforce the reality that the "product" a consumer believes they are using—a permanent, reliable crypto-card—is often subject to the whims of third-party sponsors and regulators.
Analysis: Defining Recourse and Risk
The primary lesson from the August 28 exploit is that "non-custodial" is a term often used for marketing rather than technical description. When a user deposits funds into a smart contract that can be upgraded by a single signing key held by a private company, the distinction between that model and a centralized custodian becomes blurred.
The fact that Avici and Rain were able to make users whole is a testament to the venture-backed capital buffers of these firms, but it does not change the underlying risk profile. For the average user, the security of their assets depends on three factors that are rarely transparent: the quality of the smart contract audit, the distribution of upgrade authorities (e.g., the use of multisig vaults rather than single keys), and the financial solvency of the program manager.
As the industry moves toward 2027, the gap between the marketing of crypto-native cards and the legal reality of these programs will likely continue to draw regulatory scrutiny. The market has proven that consumers prioritize the convenience of crypto-linked spending, but the August 2026 incident confirms that this convenience remains tethered to the traditional, and occasionally fragile, infrastructure of debt and institutional settlement. Investors and users alike must weigh the benefits of cashback rewards and "on-chain" marketing against the technical reality that, in the current landscape, the ability to spend crypto via a card is ultimately a service provided by a central actor, regardless of the underlying terminology.



