At 16:49:48 UTC on Friday, August 28, 2026, a Solana wallet—funded just three hours prior with 1.79 SOL derived from $190 in USDC bridged from Ethereum—initiated a series of commands that began systematically draining card-balance accounts held by users of Avici, a Solana-based neobank. By the time the event concluded, 1,685 users had seen their balances liquidated, totaling a loss of $500,859.22. This incident, while localized to a specific set of smart contracts, exposed the precarious structural reality behind the rapidly expanding market for "non-custodial" crypto debit cards.
The drain was facilitated not by a theft of private keys or a compromise of individual user wallets, but by a critical authorization vulnerability within a shared smart contract infrastructure used by Avici and several other programs. This contract was managed by Rain, a prominent card-issuing infrastructure provider. Although Avici’s terms of service, last updated in June 2025, explicitly stated that neither Avici nor the issuer held custody of user collateral, the technical reality was that the program manager maintained the ability to upgrade these contracts using a single, plain signing key.
A Chronology of the August 28 Breach
The exploit demonstrated the speed and precision with which vulnerabilities in smart contract architecture can be weaponized. The attacker’s wallet, identified on the Solana ledger as FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj, sat idle for 189 minutes after receiving its initial funding. Between 16:49:48 UTC and 19:18:52 UTC, the wallet executed 21,405 transactions, of which approximately 17,500 were successful.
The mechanism was an authorization bypass. Each successful transaction interacted with a Rain-controlled program, utilizing a SubmitSignatures call paired with native Ed25519 signature-verification instructions. The attacker discovered that by pointing the signature, key, and message offsets of the second verification instruction back to the first, they could satisfy a two-signature requirement with a single signature. This allowed the attacker to designate themselves as a "collateral admin" for over a thousand individual user accounts, granting them the privilege to withdraw assets.
The impact was swift. By 19:03:18 UTC, while the drain was still in progress, the attacker had already begun bridging stolen assets. A series of deBridge orders moved over 1.1 million USDC from the Solana network to Ethereum. These funds were subsequently funneled through the Tornado Cash router, effectively masking the trail of the stolen capital. While the total volume across all impacted programs exceeded $1.1 million, the specific losses at Avici were eventually covered in full, with the firm and its partners adding a 10% premium for affected users—a move that likely saved the company’s reputation in the short term.
The Landscape of Crypto Card Custody
The "non-custodial" label in the crypto card sector is often a marketing term that belies a complex web of legal and technical arrangements. An analysis of 18 different card programs reveals five distinct custody models, ranging from direct sale to the operator to robust, user-controlled smart vaults.
The most controversial is the "Sale to Operator" model, exemplified by KAST. Following a public feud with Ether.fi’s CEO Mike Silagadze, KAST updated its terms in July 2026 to clarify that user assets transferred to the platform are considered sold to the company. In exchange, the user receives a "legally binding and enforceable payment obligation"—essentially becoming an unsecured creditor. If the platform faces insolvency, users have no claim to the original assets, only a debt claim against a potentially insolvent entity.
Conversely, programs like Gnosis Pay utilize a "Self-Custodial Vault" model. Here, the user retains control of a smart contract wallet—a "Safe"—that the operator cannot move. Spend permissions are scoped specifically to the card, and a "Delay module" provides a buffer for transactions. This model represents the gold standard for on-chain autonomy, as the funds remain outside the reach of the platform’s potential bankruptcy estate.

The Role of "Third National" and Issuer Concentration
A significant portion of the self-custodial card market relies on a single issuer: Third National. This entity, which is not a chartered bank but rather a Puerto Rico-licensed money transmitter operating under the Signify Holdings umbrella, serves as the issuer for Avici, Ether.fi Cash, Plasma One, Solayer, Payy, Tria, and KAST.
This concentration of infrastructure creates a systemic dependency. When Rain—the parent company of Third National—experienced the contract exploit on August 28, it was not merely an Avici issue; it was a structural issue for every program utilizing those specific contract versions. While Rain successfully patched the affected programs and moved upgrade authorities to a multi-signature Squads vault by September 5, the incident highlighted the "key-person risk" inherent in relying on a single infrastructure provider for the majority of the market’s "non-custodial" solutions.
Market Growth and Regulatory Realities
Despite these technical failures, the crypto card market continues to expand at an aggressive pace. Data from Paymentscan indicates that monthly transaction volume rose from $153 million in December 2024 to $1.116 billion by August 2026. This growth is driven by the increasing integration of stablecoin-powered payments into the global financial system. Visa’s recent announcement that its stablecoin-linked card programs have surpassed a $20 billion annualized run rate underscores the scale of this transition.
However, the regulatory environment is tightening. The European Union’s Anti-Money Laundering Regulation (EU) 2024/1624, which becomes fully applicable in July 2027, will effectively prohibit anonymous crypto-asset accounts and bar EU acquirers from processing payments from anonymous prepaid cards issued in third-party jurisdictions. This shift will likely force a consolidation in the "no-KYC" (Know Your Customer) card market, as many of these programs rely on regulatory arbitrage that will no longer be sustainable.
The "No-KYC" Market: A Niche Product
The sub-sector of "no-KYC" crypto cards, often promoted as a privacy-centric alternative, remains fraught with instability. Many of these cards—such as Laso, Freedomia, and SolCard—operate in a grey area, frequently changing issuers or facing sudden service terminations when a bank or payment network revokes their access. As noted by industry observers, these cards are often "niche products" that serve as a temporary bridge rather than a stable financial solution. The "loading fees" of 2% to 5% are, in effect, the premium users pay for the privilege of accessing a BIN (Bank Identification Number) that remains opaque to the user and the regulator.
Analysis: Lessons from the August Drain
The primary takeaway from the August 2026 exploit is not that self-custody failed, but that the implementation of "non-custodial" promises is only as robust as the smart contract code and the governance of the upgrade keys.
The fact that Avici and Tria users were made whole within 24 hours was not due to the inherent security of the "non-custodial" design, but due to the willingness of the program manager to absorb the loss from their own balance sheet. In the event of a larger, systemic failure where the platform lacks the venture capital reserves to reimburse users, the "non-custodial" claim might provide little legal comfort to those who have essentially parked their liquidity in an un-audited or outdated smart contract.
Moving forward, the industry is likely to see a divergence. Institutional-grade programs will likely move toward more transparent, multi-sig controlled, and audited vault architectures, while retail-facing programs may face increased regulatory pressure to adopt standard banking compliance. For the end-user, the lesson is clear: check the legal terms for "sale" language, verify the identity of the issuer, and ensure that the smart contract governing your collateral is not subject to the unilateral, single-key upgrade authority of an opaque intermediary. As the sector matures, the distinction between "marketed as non-custodial" and "technically non-custodial" will become the most important metric for any cardholder.



