Home Decentralized Finance (DeFi) Crypto Card Volume in 2026: $1.1 Billion a Month, and What Is Inside It

Crypto Card Volume in 2026: $1.1 Billion a Month, and What Is Inside It

by Neng Nana

At 16:49:48 UTC on Friday, August 28, 2026, a dormant Solana wallet—funded just three hours prior with 1.79 SOL—executed the first of over 21,000 transactions that would systematically drain thousands of user accounts linked to the Avici neobank. Within hours, 1,685 users discovered that $500,859.22 had vanished from their card-linked collateral accounts. While the incident was localized to specific Solana smart contracts, it sent a shockwave through the burgeoning $1.1 billion-a-month crypto card industry, exposing the hidden architectural risks of "non-custodial" financial products.

The exploit was not the result of a stolen private key or a compromised user device. Instead, the attacker targeted a fundamental vulnerability in the smart contract infrastructure managed by Rain, the firm that serves as the card-issuing backbone for Avici and numerous other self-custodial programs. By exploiting an authorization logic flaw—specifically, a signature-verification bypass in an outdated version of the Rain Solana contract—the attacker granted themselves administrative control over individual user collateral pools.

A Chronology of the August 28 Breach

The incident began at 13:40:41 UTC when the attacker’s wallet received 1.79 SOL via a deBridge cross-chain swap. After a 189-minute incubation period, the malicious activity commenced at 16:49:48 UTC. Over the next two and a half hours, the attacker successfully pushed through approximately 17,500 unauthorized transactions.

The mechanism was surgical: the attacker utilized a SubmitSignatures call paired with a manipulated Ed25519 instruction. By pointing signature, key, and message offsets back at the initial input, the attacker tricked the contract into accepting a single signature as the two required approvals for administrative access. Once granted "collateral admin" status, the attacker systematically emptied the accounts.

By 19:03:18 UTC, while the drain was still in progress, the stolen funds were being laundered. A total of 1,113,096.76 USDC was bridged to Ethereum, where it was subsequently funneled into the Tornado Cash mixer in standard tranches of 100, 10, 1, and 0.1 ETH. Rain initiated patches for the three affected program IDs at 19:18:37 UTC, 19:41:08 UTC, and 19:43:42 UTC. On September 5, nearly a week after the incident, Rain finally migrated the upgrade authority for these contracts to a Squads multisig vault, adding a layer of security that had been absent during the exploit.

The Myth of Non-Custodial Security

The August 28 event highlights a critical distinction between "user-owned keys" and "operator-controlled logic." Marketing materials for many crypto cards emphasize that users retain custody of their assets. However, as this breach demonstrated, even if a user holds their own keys, their funds are often held in smart contracts designed and maintained by a third-party program manager.

If that program manager holds the "upgrade key" to the contract, or if the contract is fundamentally flawed, the non-custodial label becomes a semantic shield rather than a security guarantee. The aftermath of the Avici drain was resolved only because Rain, backed by substantial venture capital funding, opted to cover the losses out of its own balance sheet. Had the company been insolvent or unwilling to act, the users would have had no legal recourse, as their funds were technically held in a smart contract for which they lacked ultimate administrative authority.

Crypto Cards 2026: Who Holds the Money Before the Swipe

Industry Concentration and the "Third National" Factor

A deeper investigation into the infrastructure supporting these cards reveals a striking level of concentration. Seven of the 18 programs analyzed—including Avici, KAST, Ether.fi Cash, Plasma One, Solayer, Payy, and Tria—name "Third National" as their issuer. Documents reveal that Third National is a dba for Nimbus LLC, a Puerto Rico-licensed money transmitter that is itself an affiliate of Rain.

This means that a significant portion of the self-custodial crypto card market is not supported by traditional chartered banks, but by a network of entities under a single corporate umbrella. Rain’s own regulatory disclosures note that they are not banks, do not provide FDIC insurance, and do not hold deposits. Instead, their business model relies on borrowing stablecoins to facilitate network settlement. When a user swipes their card, the transaction is effectively a charge card settlement financed by Rain’s liquidity network.

This concentration represents a systemic risk. While the August incident was contained, the vulnerability existed across multiple programs using the same codebase. The fact that Ether.fi Cash remained untouched during the attack is attributed to its distinct vault architecture, where user funds are managed through a Turnkey signer in an AWS Nitro enclave, rather than the standardized Rain collateral pools used by Avici and Tria.

Regulatory Pressures and the No-KYC Sector

Beyond the mainstream programs, the "no-KYC" crypto card sector continues to operate in a high-risk gray area. A review of 11 such cards—including SolCard, Laso Finance, and OffGrid—shows that only one program clearly identifies its issuer. Most rely on vague references to "licensed partners," and many carry high load fees that effectively serve as a premium for anonymous access.

The regulatory environment is shifting rapidly. The European Union’s Anti-Money Laundering Regulation (Regulation 2024/1624), set to apply in July 2027, will effectively prohibit anonymous crypto-asset accounts and bar EU acquirers from processing transactions from anonymous prepaid cards issued in third-party jurisdictions. This will likely force a consolidation of the market, as programs that rely on regulatory arbitrage find it increasingly difficult to secure merchant connectivity.

The Landscape of Custody Models

To navigate the market, investors and users must categorize cards into one of five distinct custody buckets, each with varying levels of risk:

  1. Sold to the Operator: In this model, such as that employed by KAST, the user’s crypto is legally "sold" to the company upon transfer. The user holds a USD-denominated debt claim. In the event of bankruptcy, users are merely unsecured creditors.
  2. Custodial (Affiliate): Programs like RedotPay hold assets in a group-affiliated trust. While this offers some oversight, it lacks the independence of third-party institutional custody.
  3. Fiat-Converted: Cards like Crypto.com or Kraken’s Krak card do not hold crypto at all; they hold fiat currency. Once crypto is sold, the fiat is held by a licensed payment service provider, often protected by statutory safeguarding requirements in the EU or UK.
  4. Shared Collateral Pools: This is the model used by Avici and Tria. While users own the collateral in a smart contract, the manager retains administrative authority, creating a single point of failure.
  5. Direct Vaulting: This is the most secure tier, exemplified by Gnosis Pay or Ether.fi. These programs utilize self-custodial smart accounts where the user maintains control, and the card’s ability to pull funds is restricted by strictly scoped permissions and time-delay modules.

Future Implications

The collapse of Kulipa, the revocation of Paytend’s EMI license, and the winding down of Gnosis Pay’s consumer interface underscore a broader trend: the infrastructure of crypto cards is volatile. Even when the "non-custodial" promise holds true and users do not lose their funds, the underlying service can vanish overnight due to regulatory pressure or internal financial failure.

The August 2026 hack serves as a warning that the "non-custodial" label in the crypto card industry is often a misnomer. As the industry matures, the focus will likely shift toward transparency regarding contract ownership and issuer identity. Until then, users would be wise to treat their card-linked balances as temporary transit funds rather than long-term stores of value. For the $1.1 billion flowing through these cards monthly, the lesson is clear: convenience is often bought at the price of hidden, structural fragility. The industry’s ability to survive will depend on moving away from opaque, centralized collateral pools and toward the robust, transparent, and user-governed architectures that the category was originally intended to deliver.

You may also like

Leave a Comment