At 16:49:48 UTC on Friday, August 28, 2026, a Solana-based wallet—funded just three hours prior with 1.79 SOL via a bridge from Ethereum—executed a precision strike on the digital balance accounts of Avici, a prominent Solana-native neobank. Within minutes, the attacker began siphoning funds from users’ card-balance accounts. By the time the dust settled, 1,685 users had seen a combined total of $500,859.22 vanish from their accounts. This incident, while relatively small in the context of the $1.1 billion monthly volume seen across the crypto-card sector, exposed a systemic vulnerability in the "non-custodial" architecture that has become the industry’s standard.
The breach targeted the "Solana card contract," a piece of infrastructure managed by Rain, a major card-issuing company that powers not only Avici but a substantial segment of the self-custodial card market. By 20:44 UTC on that same Friday, Avici issued a public reconciliation confirming the scope of the loss. Despite the terrifying nature of the breach, the outcome was uncharacteristic for the decentralized finance (DeFi) sector: Rain covered every cent of the stolen funds, and both Avici and Tria—a second program hit by the same vulnerability—added an additional 10% on top of the refunds as a gesture of goodwill.
A Failure of Authorization, Not Keys
Crucially, the August 28 exploit did not involve the theft of user private keys, nor did it involve the unauthorized entry into personal wallets. Instead, the vulnerability lay in the very mechanism that makes these cards "non-custodial." The funds were held in smart contracts designed to be funded by the user but managed by the program provider. These contracts were structured such that the program manager held a single, plain signing key capable of upgrading the contract’s logic.
The attacker leveraged an authorization bug in the contract’s signature-verification instruction. By crafting a malformed transaction where the verification offsets pointed back at the primary signature, the attacker tricked the system into accepting a single signature as the two-part approval required to add an administrative address. Once the attacker was granted "admin" status, they simply withdrew the collateralized assets from the affected accounts. This was not a breach of encryption, but a failure of procedural logic—a reminder that in the world of smart contracts, the code is only as secure as the person who holds the upgrade key.
The Landscape of Crypto Card Custody
The incident has ignited a fierce debate regarding what "non-custodial" actually means in a legal and technical sense. Based on an analysis of 18 major crypto card programs, the industry currently operates across five distinct custody models, each offering varying levels of protection for the user.
At the most restrictive end, programs like KAST describe a "sale" of assets to the operator. Under these terms, the user does not technically hold a deposit; they hold a USD-denominated debt claim against the company. If the operator faces insolvency, the user is merely an unsecured creditor. Conversely, at the other end of the spectrum, programs like Gnosis Pay utilize a self-custodial "Safe" architecture where the user retains control via their own signing wallet. In this model, the operator cannot move the funds; the card spend is merely a permissioned authorization for a specific amount.
Between these extremes lie custodial models where the operator holds legal title but acts as a nominee, and fiat-conversion models where the crypto is sold instantly upon authorization, leaving the user with a balance of government-issued electronic money. The Avici incident highlights the danger of the middle ground: contracts that claim to be "non-custodial" because they sit on-chain, but which are subject to centralized administrative control by the program manager.
Growth Amidst Turbulence
Despite the high-profile exploit, the crypto card market continues to expand at a rapid pace. According to data from Paymentscan, the total monthly volume for crypto-linked cards reached $1.116 billion in August 2026, spread across 11 million transactions and nearly 288,000 active addresses. This represents a significant climb from the $153 million recorded in December 2024.

However, these figures carry significant caveats. The data is often skewed by self-reported figures from issuers like RedotPay, which accounts for approximately 36% of the headline volume. When filtering for strictly on-chain observations, the volume is closer to $545 million. Regardless of the exact number, the concentration of power is undeniable. Approximately 42% of all tracked volume settles through Rain-managed programs. When combined with RedotPay, these two entities control nearly 78% of the entire market.
The Role of "Third National"
A primary focus for regulators and industry observers is the identity of the issuer. Seven of the 18 programs analyzed—including Avici, Tria, Ether.fi Cash, and Plasma One—all list "Third National" as their issuer. Investigation reveals that Third National is not a bank in the traditional sense. It is a trade name for Nimbus LLC, a Puerto Rico-licensed money transmitter and an affiliate of Rain.
This structure allows these programs to operate as "charge cards" where Rain finances the settlement through borrowed stablecoins. When a user swipes their card, Visa settles the transaction, and Rain covers the debt from the user’s collateral contract. This creates a complex web of financial dependencies where the "non-custodial" nature of the card is contingent upon the operational stability of a single money transmitter.
Regulatory Horizons and Future Risks
The regulatory environment is poised for a major shift. The European Union’s Anti-Money Laundering Regulation (EU 2024/1624), effective July 2027, will fundamentally alter the "no-KYC" card market. By prohibiting anonymous crypto-asset accounts and restricting the use of anonymous prepaid cards from third countries, the regulation threatens to end the era of "no-questions-asked" card spending.
The market has already seen the impact of regulatory intervention. In March 2026, the revocation of Paytend Europe’s EMI license by the Bank of Lithuania caused the immediate shutdown of Bit.Store card services, leaving users in a difficult position to recover funds. Similarly, the collapse of infrastructure providers like Kulipa and the strategic withdrawal of Fiat24 have demonstrated that the "front-end" card brand is often at the mercy of the "back-end" infrastructure provider.
Lessons from the August 28 Exploit
The aftermath of the August 28 exploit provides a blueprint for the industry’s future. The quick response from Rain to secure the contracts—transferring upgrade authority to a Squads multisig vault—was a critical remediation. Yet, the fact remains that 1,685 users were made whole not because the code protected them, but because a private entity decided to honor its commitment to the users.
For consumers, the takeaway is clear: the term "non-custodial" is a marketing label, not a technical guarantee. Before funding a card, users must ask five fundamental questions:
- Is the arrangement a sale of assets or a true self-custodial vault?
- Who is the actual legal issuer, and what is their regulatory status?
- What is the explicit insolvency protocol?
- Who holds the upgrade authority for the smart contracts?
- Is the reported transaction volume verifiable on-chain?
As the crypto card market matures, the distinction between these models will likely become the primary differentiator between sustained success and catastrophic failure. For now, the industry remains in a precarious balance, relying on the goodwill of infrastructure providers to bridge the gap between flawed code and the promise of financial sovereignty.











