Home Decentralized Finance (DeFi) Crypto Card Volume in 2026: $1.1 Billion a Month, and What Is Inside It

Crypto Card Volume in 2026: $1.1 Billion a Month, and What Is Inside It

by Iffa Jayyana

At 16:49:48 UTC on Friday, August 28, 2026, a Solana wallet funded just three hours earlier with 1.79 SOL began systematically draining card-balance accounts held by users of Avici, a Solana-based neobank. The incident, which exposed a fundamental structural vulnerability in the rapidly growing "non-custodial" crypto card sector, resulted in the loss of $500,859.22 from 1,685 individual user accounts. By the time the breach was contained, the total impact across the ecosystem underscored the fragility of financial products that promise decentralization while relying on centralized technical infrastructure.

The drain did not target private keys or individual wallets directly. Instead, it exploited the specific smart contract architecture used by the card-issuing company, Rain. Rain serves as the back-end infrastructure provider for a significant portion of the self-custodial card market, including Avici and Tria, the latter of which also suffered losses. While Avici’s terms of service claimed that "Avici and Issuer will not, in any circumstance, be holding custody of your Collateral," the reality was more complex: the funds were held in smart contracts that, while technically distinct from the company’s own operating funds, were subject to upgrade authority held by a single, plain signing key controlled by the program manager.

The Anatomy of the August 28 Exploit

The breach followed a precise, automated trajectory. The attacker’s wallet, identified as 0xFVNFzq…nCEj, received 1.79 SOL via a deBridge cross-chain swap from Ethereum. After a three-hour period of inactivity, the wallet initiated a series of 21,405 transactions against Rain-controlled Solana programs. Approximately 17,500 of these attempts succeeded.

Each successful exploitation involved a three-step sequence: a "SubmitSignatures" call utilizing a native Ed25519 signature-verification instruction, followed by "AddCollateralAdmin" and "WithdrawCollateralAsset" calls. The vulnerability lay in the signature-verification logic. The attacker’s transaction pointed the signature, key, and message offsets of the second verification instruction back to the first, effectively tricking the contract into accepting one signature as two. This authorized the attacker to act as a "collateral admin" on over a thousand user accounts, granting them withdrawal permissions.

The median loss per user was approximately $24, though some accounts lost significantly more, with the largest single loss in tracked samples reaching $5,268. By 19:03 UTC, while the drain was still active, the attacker initiated a series of deBridge orders to bridge the stolen funds—swapped into ETH and SOL—back to the Ethereum mainnet. The total haul, amounting to approximately $1.11 million, was subsequently funneled through Tornado Cash in standard mixing increments.

The Role of Rain and the "Non-Custodial" Myth

The incident highlights a growing concentration of risk within the crypto card ecosystem. Rain is not merely a service provider; it is the infrastructure backbone for at least seven major card programs, including KAST, Avici, Ether.fi Cash, Plasma One, Solayer, Payy, and Tria. Investigations into these programs reveal that "Third National"—the entity named in their terms of service as the card issuer—is an affiliate of Signify Holdings, Inc., which operates under the "Rain" brand.

This issuer is not a traditional chartered bank, but a Puerto Rico-licensed money transmitter. The business model, as outlined in Rain’s public filings and disclosures, involves facilitating card payments through a network of capital partners who lend stablecoins to settle credit card receivables. When a user swipes their card, Visa settles the transaction; Rain pays Visa using borrowed capital and is then reimbursed by the user’s smart contract collateral.

This model effectively makes these cards "charge cards" that are pre-financed by the issuer. The "non-custodial" label is therefore a marketing descriptor for the user’s interface, rather than a technical guarantee of total sovereignty. While the user retains ownership of the collateral in a smart contract, the contract’s code, upgrade authority, and security auditing remain under the control of the program manager.

Crypto Cards 2026: Who Holds the Money Before the Swipe

Industry Response and Market Remediation

In the immediate aftermath of the August 28 exploit, the industry reaction was swift, albeit largely informal. Rain issued statements via X (formerly Twitter) confirming that a vulnerability in "outdated versions" of its Solana contracts had been exploited. Within 24 hours, Rain, Avici, and Tria confirmed that all affected users would be made whole, with the companies covering the losses from their own balance sheets—a testament to the high venture capital funding levels currently supporting these firms.

By September 5, Rain had migrated the upgrade authority for its core programs to a Squads multisig vault, a critical security upgrade that should have been in place prior to the deployment of the vulnerable code. Despite this, the lack of a formal, public post-mortem remains a point of concern for regulatory observers and security researchers.

The Broader Landscape: A $1.1 Billion Monthly Market

Paymentscan, an industry tracker, reported that crypto card volume reached $1.116 billion in August 2026, marking the second consecutive month of volume exceeding the $1 billion threshold. Cumulative volume since March 2023 now stands at $11.61 billion. However, this growth mask significant heterogeneity in custodial and operational models.

The market can be divided into five distinct categories of custody:

  1. Sold to the Operator: Models like KAST, where user deposits are legally treated as a sale to the company, leaving the user with a debt claim against a firm that often operates in offshore jurisdictions with minimal liability caps.
  2. Custodial Nominee: Programs like RedotPay or Revolut, where the operator holds legal title on behalf of the user, necessitating trust in the operator’s balance sheet and regulatory standing.
  3. Fiat-Converted: Exchange-based cards (Crypto.com, Kraken, Bybit) where crypto is sold for fiat immediately upon or before the swipe, meaning the user holds zero digital assets at the point of payment.
  4. Program-Pool Collateral: The Avici/Rain model, where assets are held in smart contracts under program-manager-controlled logic.
  5. Direct Vault/Self-Custodial: The Gnosis Pay or Ether.fi Cash model, where the user maintains control via a self-custodial vault or smart account with specific, limited spend permissions.

Regulatory and Economic Implications

The regulatory environment is shifting rapidly. The EU’s Anti-Money Laundering Regulation (2024/1624), set to apply in July 2027, will effectively prohibit anonymous crypto-asset accounts and restrict the use of anonymous prepaid cards loaded from crypto-assets. This will likely force a consolidation in the "no-KYC" card market, which currently relies on loopholes involving business-level verification (Know Your Business) rather than individual-level scrutiny.

Infrastructure failures in 2026—including the collapse of Kulipa in July and the shutdown of Paytend Europe UAB in March—demonstrate that "self-custody" does not insulate a user from product-level failures. When an issuer loses its license or an infrastructure provider winds down, the card functionality ceases, regardless of whether the underlying collateral remains safe.

Conclusion: Assessing the Risk

For the average consumer, the distinction between these models is often buried in lengthy, complex terms of service. The August 2026 incident served as a stark reminder that in the world of crypto-native finance, terms like "non-custodial" are not synonymous with "risk-free."

While the rapid reimbursement of victims in August demonstrated a commitment to brand protection, it was a discretionary act of corporate goodwill rather than a systemic guarantee. As the volume of crypto-card transactions continues to scale, the industry faces an unavoidable choice: either move toward more transparent, fully auditable self-custodial architectures—like those championed by Gnosis Pay or Ether.fi—or accept that their users remain vulnerable to the same single-point-of-failure risks that have plagued traditional fintech and banking for decades. The future of the category depends not on marketing, but on whether the industry can move beyond the "black box" of proprietary smart contract administration and into an era of verifiable, decentralized trust.

You may also like

Leave a Comment