Home Decentralized Finance (DeFi) Crypto Card Volume in 2026: $1.1 Billion a Month, and What Is Inside It

Crypto Card Volume in 2026: $1.1 Billion a Month, and What Is Inside It

by Laily UPN

At 16:49:48 UTC on Friday, August 28, 2026, a Solana wallet funded three hours earlier with 1.79 SOL began systematically draining card-balance accounts belonging to users of Avici, a prominent Solana-based neobank. This event, which saw 1,685 users lose a total of $500,859.22, exposed critical vulnerabilities in the burgeoning "non-custodial" crypto card sector. While the industry frequently markets itself as a secure, user-controlled alternative to traditional banking, the incident revealed that "non-custodial" is often a legal designation rather than a technical guarantee. The stolen funds were not sitting in a personal wallet, but rather in a smart contract that the program manager—in this case, the infrastructure provider Rain—could upgrade with a single, plain signing key.

The breach was not the result of stolen private keys or compromised user devices. Instead, it was a failure of authorization logic within the card program’s architecture. As the dust settled, the reality of the ecosystem’s interconnected nature became clear: Rain serves as the card-issuing company behind not only Avici but a significant portion of the self-custodial market. While Avici and the second affected program, Tria, successfully covered every refund, the event served as a stark reminder that users are often beholden to the technical security and corporate solvency of the underlying infrastructure provider, regardless of what the terms of service claim regarding custody.

A Chronology of the August Drain

The exploit was surgical and swift. The attacker’s wallet, identified as FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj, received 1.79 SOL via a deBridge order that converted 189.99 USDC. After a period of dormancy, the wallet began executing transactions at 16:49:48 UTC. Over the next two and a half hours, the attacker pushed over 21,000 transactions, of which approximately 17,500 were successful.

The technical flaw lay in a SubmitSignatures call paired with the native Ed25519 signature-verification instruction. The attacker exploited a vulnerability where the second verification instruction pointed its signature, key, and message offsets back to the first, effectively allowing one signature to satisfy a two-signature check. This granted the attacker administrative control over collateral accounts, allowing for the subsequent WithdrawCollateralAsset calls.

By 19:18 UTC, Rain had begun patching the affected programs. However, the damage was already done. The stolen funds were bridged to Ethereum and funneled through Tornado Cash in a standard laundering pattern. While the companies involved managed to make users whole from their own balance sheets, the incident sent shockwaves through the Solana ecosystem, leading to a 49% drop in the $AVICI token price and raising uncomfortable questions about the "self-custodial" narrative.

The Scale of the Crypto Card Market

Paymentscan data indicates that the crypto card sector reached a volume of $1.116 billion in August 2026, spanning 11 million transactions and nearly 288,000 active addresses. This figure represents a massive maturation of the market, which stood at just $153 million in monthly volume in December 2024. However, these headline figures mask significant volatility and methodological differences.

The market is heavily concentrated. Approximately 42% of August’s volume—$468 million—was attributed to programs settling through Rain. When combined with self-reported spend data from major players like RedotPay, two companies effectively control nearly 78% of the tracked market. This concentration represents a systemic risk. If a single provider like Rain suffers a technical outage or a security breach, the ripple effects are felt across a dozen different consumer brands simultaneously.

Crypto Cards 2026: Who Holds the Money Before the Swipe

Decoding Custody: Five Models of Risk

The ambiguity surrounding the term "non-custodial" is the greatest hurdle for consumer trust. An analysis of 18 different card programs reveals that they fall into five distinct buckets of risk, ranging from simple debt claims to true on-chain self-custody.

  1. Sale to the Operator: Programs like KAST have updated their terms to explicitly frame the transfer of assets as a "sale." In this model, the user holds a USD-denominated debt claim against the company. In the event of bankruptcy, users are relegated to the status of general creditors, often behind senior debt.
  2. Custodial Nominee: Platforms like RedotPay and Revolut hold assets in custody for the user. While this offers more protection than a debt claim, the user is still reliant on the custodian’s integrity and legal standing.
  3. Fiat Conversion: Exchange-based cards, such as those from Crypto.com or Kraken, often hold only fiat currency on the card itself, with crypto assets remaining in exchange custody until the moment of sale. In the EU, this is governed by strict e-money regulations that require the safeguarding of funds.
  4. Program-Pool Contracts: This is the model used by Avici, Tria, and Rain. While users believe their funds are in their own custody, they are actually in a smart contract controlled by the program manager. The "non-custodial" claim is accurate only in the sense that the company does not hold the keys to the user’s main wallet, but the collateral for the card is entirely subject to the manager’s technical implementation.
  5. Debited at Authorization: The strongest model, seen in Gnosis Pay and Ether.fi Cash, uses smart accounts where the operator cannot move funds independently. Spend permissions are strictly scoped, and the user retains control over the underlying assets until the exact moment of transaction authorization.

The "Third National" Infrastructure Layer

A recurring name in the card issuer column is "Third National." Investigation reveals that Third National is not a bank, but a brand name for Nimbus LLC, a Puerto Rico-based money transmitter that holds Visa principal membership. This entity acts as the issuer for KAST, Avici, Ether.fi Cash, Plasma One, Solayer, Payy, and Tria.

The fact that a money transmitter—rather than a chartered bank—is the issuer for a large portion of the self-custodial card market is a significant nuance. Rain’s own disclosures state that they are not banks, do not provide FDIC insurance, and facilitate card settlement by borrowing stablecoins to cover receivables. This creates a complex web of financial exposure. When a user swipes their card, they are essentially utilizing a charge card financed by an on-chain credit facility.

Regulatory and Future Implications

The landscape for these cards is set to change dramatically with the implementation of the EU’s Anti-Money Laundering Regulation (AMLR) in July 2027. Article 79 of the regulation explicitly prohibits the maintenance of anonymous crypto-asset accounts and bars EU acquirers from processing payments from anonymous prepaid cards issued in third countries. This will likely force a consolidation in the market, pushing anonymous, no-KYC cards out of the European economic zone.

Furthermore, the industry’s reliance on "outdated" contract versions—a primary defense offered by Rain following the August exploit—highlights a lack of standardized maintenance protocols. While audit firms like Sherlock are employed for pre-deployment, the ongoing management of deployed code remains a human-led, manual process that is prone to error.

Lessons Learned and the Path Forward

The "self-custody failed" narrative is simplistic and, ultimately, inaccurate. The users who were impacted by the Avici exploit did indeed hold their own private keys; the failure occurred in the infrastructure layer that bridged those assets to the traditional payment network. The real lesson is that "non-custodial" is a marketing term that currently lacks a standardized technical definition.

For the average user, the takeaway is one of caution. Before funding a card, one must verify where the assets physically reside, who holds the upgrade authority for the smart contracts, and what the legal recourse is in the event of an insolvency or a hack. As the sector matures, the market will likely favor providers who offer transparency regarding their contract security and those who move away from centralized "collateral pools" in favor of true, permissionless on-chain spending. Until then, the $1.1 billion flowing through these cards remains a testament to both the innovation of the space and the persistent, hidden risks that accompany rapid technological adoption.

The resilience of the sector, evidenced by the quick refunds provided by Avici and Rain, provides a temporary buffer for consumer confidence. However, trust built on company balance sheets is a fragile thing. True, sustainable growth in the crypto card sector will require the industry to move beyond "move fast and break things" and toward a paradigm where technical auditability, transparent governance, and clear legal protections are the baseline, not the exception. The August 28 incident was not a death knell for the industry, but it was an essential stress test that revealed the limitations of current custodial claims. As 2026 draws to a close, the market finds itself at a crossroads: either embrace the rigor of regulated finance or continue to operate in a gray area where the promise of self-custody is undermined by the reality of centralized infrastructure.

You may also like

Leave a Comment