At 16:49:48 UTC on Friday, August 28, 2026, a Solana wallet—funded just three hours prior with 1.79 SOL derived from $190 in USDC bridged from Ethereum—initiated a series of precise, automated commands that began draining user funds from Avici, a prominent Solana-based neobank. This event exposed the precarious architecture underpinning the rapidly expanding market for "non-custodial" crypto debit cards. By the time the exploit concluded, 1,685 users had seen a combined $500,859.22 siphoned from their card-balance accounts. While the industry frequently markets these products as self-custodial, the August incident demonstrated that the legal and technical reality of these assets is significantly more nuanced, and often more fragile, than the marketing suggests.
The incident was not a breach of user private keys, nor was it a theft from personal wallets. Instead, the vulnerability lay within the specialized smart contracts that facilitate card spending. These contracts, used by Avici and several other programs, were managed by Rain, a dominant infrastructure provider in the self-custodial card sector. According to reconciliation data released by Avici at 20:44 UTC on the day of the attack, the vulnerability allowed an unauthorized party to manipulate collateral accounts that were supposedly isolated from the firm’s direct custody.
A Chronology of the August 28 Exploit
The timeline of the attack reveals a highly sophisticated operation. The attacker’s address, 0xFVNFzq…nCEj, remained dormant for 189 minutes after its initial funding before executing the first exploit transaction at 16:49:48 UTC. Over the next 149 minutes, the wallet broadcasted 21,405 transactions, of which approximately 17,500 were successful.
The exploit relied on an authorization bug within the Solana program’s logic. The attacker invoked a SubmitSignatures call paired with the native Ed25519 signature-verification instruction. By cleverly aligning the signature, key, and message offsets, the attacker bypassed the program’s two-signature requirement, allowing a single signature to validate the transaction. This granted the attacker administrative status over individual collateral accounts, enabling the withdrawal of assets.
The financial impact was immediate. Between 19:20 and 19:49 UTC, the stolen funds—swapped across various assets—were consolidated and moved through Tornado Cash, totaling approximately 1.11 million USDC. While Avici and Tria, another affected program, moved to cover the losses, the speed of the drain and the subsequent laundering of funds highlighted the systemic risks inherent in centralized smart contract management.
The Infrastructure of Trust: Rain and Third National
The concentration of risk is largely tied to Rain and its issuing arm, Third National. Although many programs market themselves as independent, seven of the 18 programs reviewed—including Avici, KAST, Ether.fi Cash, and Tria—name Third National as their card issuer. Third National is not a traditional chartered bank; it is a Puerto Rico-based money transmitter. Rain’s own disclosures state that it is not an asset custodian and does not provide FDIC insurance.
This concentration of infrastructure creates a "single point of failure" scenario. When the Rain Solana contract code was exploited, the vulnerability was present across multiple programs simultaneously. While companies like Ether.fi remained untouched, it was due to their specific implementation of user-controlled vaults rather than a blanket security measure provided by the underlying infrastructure. The fact that Rain was able to patch the vulnerability and transition upgrade authority to a secure Squads multisig vault by September 5 suggests that the industry is beginning to recognize the dangers of centralized upgrade keys, but the August 28 event served as a stark reminder of the cost of learning those lessons in production.

Crypto Card Volume and Market Dynamics
Paymentscan data for August 2026 places the total crypto card volume at $1.116 billion, marking the second consecutive month exceeding the $1 billion threshold. Cumulative volume since March 2023 has now surpassed $11.6 billion. However, this growth requires careful interpretation.
The reported figures often include self-reported spend metrics from companies like RedotPay, which accounted for approximately 36% of the headline volume in August. Other programs, such as KAST and Karta, lack direct spend feeds and are instead proxied by their settlement batches to Rain. When isolating strictly on-chain observed spend—which provides a more granular view—the volume sits closer to $545 million. Ether.fi Cash currently stands as the largest program with fully visible on-chain activity, recording $109.5 million in August across 1.45 million transactions.
The Spectrum of Custody Models
To understand the risks, one must distinguish between the five distinct custody models currently employed by the 18 major programs:
- Sold to the Operator: Models like KAST treat asset transfers as a sale, where the user holds a debt claim against the operator rather than ownership of the underlying assets. In the event of bankruptcy, users are treated as unsecured creditors.
- Held in Custody for the User: Programs like RedotPay and Revolut act as custodians, holding legal title or managing assets on the user’s behalf. While this provides institutional-grade security, it subjects the user to the custodial risk of the firm and its affiliates.
- Fiat Conversion at a Licensed Issuer: Exchange-based cards, such as those from Crypto.com or Kraken, often hold no crypto on the card itself, instead converting assets to fiat at the moment of purchase. In the EU and UK, these programs benefit from statutory "safeguarding" requirements, which protect fiat funds in the event of an issuer’s insolvency.
- Shared Collateral Contracts: This model, used by Avici and Tria, places user collateral in smart contracts managed by a third party. While the user technically owns the assets, the program manager retains the authority to update the contract, creating a vulnerability where a logic error can lead to a total loss of funds.
- Directly Debited Vaults: The most robust model, utilized by Gnosis Pay and Ether.fi, involves a smart contract or vault that the operator cannot move. Spending is limited to specific permissions, and the user maintains ultimate control, providing the highest level of protection against both operator insolvency and technical exploits.
Regulatory Horizons and Future Stability
The regulatory environment is shifting toward more stringent oversight. The European Union’s Anti-Money Laundering Regulation (EU) 2024/1624, effective July 2027, will effectively prohibit anonymous crypto-asset accounts and limit the use of anonymous prepaid cards. This regulation aims to close the "no-KYC" loophole that has historically fueled the rapid but unstable growth of off-shore crypto card programs.
The history of these cards is littered with sudden shutdowns—from Wave Crest in 2018 to Paytend and Bit.Store in 2026. In almost every instance, the decision to cease operations was made by the BIN sponsor or the network, rather than the consumer-facing brand. For users, this emphasizes the importance of understanding who the true issuer is, rather than relying on the marketing materials of the interface provider.
The Lessons of 2026
The August 28 incident was not a failure of self-custody as a concept, but rather a failure of implementation and transparency. Avici’s users held their own keys for their personal wallets, but by moving assets into a "card layer" managed by a third party, they inadvertently introduced a centralized risk point. The fact that users were made whole within 24 hours was a testament to the venture-backed capital reserves of the providers involved, rather than the intrinsic security of the smart contracts themselves.
For the industry to mature, providers must move toward greater transparency regarding contract upgrade authority and issuer relationships. As demonstrated by the divergence in outcomes between Ether.fi and the Rain-reliant programs, the architecture of the "vault" matters as much as the promise of non-custodial access. As the crypto card market continues to scale toward a multi-billion dollar annualized run rate, the distinction between "marketing-led non-custodial" and "code-enforced self-custody" will become the defining factor for user security. The current reliance on venture-funded "refunds" as a substitute for robust, audited, and immutable security is a model that may not withstand the next, more significant market stress test.



