Home Decentralized Finance (DeFi) Crypto Card Volume in 2026: $1.1 Billion a Month, and What Is Inside It

Crypto Card Volume in 2026: $1.1 Billion a Month, and What Is Inside It

by Laily UPN

At 16:49:48 UTC on Friday, August 28, 2026, a specific Solana wallet—funded just three hours prior with 1.79 SOL derived from $190 in bridged Ethereum-based USDC—initiated a systematic drainage of card-balance accounts held by users of Avici, a prominent Solana-based neobank. This incident exposed a critical vulnerability in the architecture of modern "non-custodial" crypto cards, triggering a cascade of concern across the $1.1 billion-a-month sector. While the term "non-custodial" often implies complete user autonomy, the August 28 exploit demonstrated that even when users hold the keys to their primary wallets, the smart contracts utilized for card-based spending often remain under the centralized administrative control of the card issuer.

The fallout was immediate. By 20:44 UTC that same day, Avici confirmed via its official communication channels that 1,685 users had lost a collective $500,859.22. The funds were siphoned from a shared Solana card contract infrastructure utilized by Avici and several other programs. The underlying technology belonged to Rain, a card-issuing firm that serves as the backbone for a substantial portion of the self-custodial card market. In a swift move to preserve market confidence, Avici announced that Rain had committed to covering 100% of the stolen funds, with both Avici and Tria—a second program hit by the exploit—contributing an additional 10% premium to affected users.

The Anatomy of the Exploit

The incident was not a result of compromised user private keys or a phishing attack on individual wallets. Instead, it was an authorization bug within the smart contract logic itself. Investigators found that the attacker’s wallet exploited a signature-verification flaw in the Rain-controlled Solana program. The exploit involved a SubmitSignatures call paired with a native Ed25519 signature-verification instruction. By cleverly manipulating the signature, key, and message offsets, the attacker was able to force the system to accept a single signature as fulfillment for a two-signature requirement.

This maneuver effectively granted the attacker administrative status over more than 1,000 individual user collateral accounts. Once granted "admin" status, the attacker had the authorization to initiate WithdrawCollateralAsset calls. The median loss per user was approximately $24, though the largest single loss in the sample reached $5,268.

The attacker’s efficiency was notable. The entire drainage operation lasted less than two and a half hours, during which 21,405 transactions were attempted, with roughly 17,500 succeeding. The stolen funds were bridged out to Ethereum and funneled through the Tornado Cash mixer in a standard "ladder" of transactions—four deposits of 100 ETH, five of 10, five of 1, and nine of 0.1—effectively obfuscating the trail.

Broader Industry Context and Data Trends

According to Paymentscan, the crypto card industry reached a significant milestone in August 2026, with total volume hitting $1.116 billion across 11 million transactions. This represents a staggering rise from $153 million in December 2024. However, analysts warn that these headline figures must be interpreted with caution. The data is heavily influenced by self-reported figures from firms like RedotPay, which accounted for roughly 36% of the August volume.

The industry currently relies on a handful of key infrastructure providers. Rain alone accounts for approximately 42% of all tracked volume when combined with RedotPay, meaning two entities control nearly 78% of the crypto-card market. This high level of concentration suggests that while the industry is growing rapidly, it is increasingly susceptible to systemic failures if the underlying infrastructure is compromised.

The "Non-Custodial" Terminology Debate

The August 28 exploit reignited a fierce debate regarding what "non-custodial" actually means in the context of consumer financial products. While Avici’s terms of service, last updated in June 2025, explicitly stated that the company would not hold custody of user collateral, this proved to be a legal distinction that did not translate into technical reality.

Crypto Cards 2026: Who Holds the Money Before the Swipe

For the purposes of a card program, funds must exist in a state that can be liquidated to settle with payment networks like Visa. This creates a "custody gap." Programs like Gnosis Pay attempt to mitigate this by utilizing a "Safe" architecture, where the user maintains ownership through a smart contract that the operator cannot unilaterally move. In contrast, other models—such as the one used by KAST—rely on a "sale-to-operator" model. Under the KAST terms, as revised in July 2026, transferring assets to the platform constitutes a sale, turning the user’s crypto into a USD-denominated debt claim against the company. This effectively strips the user of ownership, leaving them as unsecured creditors in the event of bankruptcy.

The Role of Third National and Rain

A critical finding in the investigation of the August 28 event is the central role played by "Third National." Seven of the programs reviewed—KAST, Avici, Ether.fi Cash, Plasma One, Solayer, Payy, and Tria—name Third National as their card issuer. However, Third National is not a bank in the traditional, chartered sense. It is a Puerto Rico-licensed money transmitter operating under Nimbus LLC, an affiliate of the Rain group.

This structure allows these companies to bypass many of the regulatory hurdles associated with traditional banking, but it also means that users do not benefit from FDIC insurance or traditional bank-level protections. When a user taps their card, Visa settles the transaction; Rain pays Visa using borrowed stablecoins; and Rain is subsequently reimbursed from the user’s smart contract collateral. This "charge card" model, financed by institutional stablecoin borrowing, is highly scalable but introduces significant counterparty risk.

Regulatory and Operational Risks

The fragility of the current crypto-card landscape is evidenced by the frequent shutdowns and license revocations seen throughout 2026. The collapse of the Kulipa infrastructure in July, which affected several card programs, and the revocation of Paytend’s e-money license in Lithuania earlier in the year, serve as reminders that the regulatory environment is tightening.

The European Union’s upcoming Anti-Money Laundering Regulation (EU 2024/1624), set to apply from July 2027, will likely eliminate the "no-KYC" card category entirely. Article 79 of the regulation explicitly prohibits the maintenance of anonymous crypto-asset accounts and bars EU acquirers from processing payments from anonymous prepaid cards issued in third countries. This will force a massive shift in the industry toward standard KYC compliance, potentially ending the era of "privacy-first" cards that lack identifiable issuers.

Lessons Learned and Future Implications

The primary takeaway from the August 2026 exploit is that technical audits are only as good as the code actually deployed to the mainnet. Rain’s post-mortem indicates that the vulnerability existed in an outdated version of their Solana contracts that had remained live long after a patch was developed. While Rain’s proactive decision to refund users in full prevented a total loss of trust, it also highlighted the dangerous reliance on centralized upgrade authority.

By September 10, Rain had moved the upgrade authority for its programs to a Squads multisig vault, a necessary step to decentralize the risk of future contract manipulation. However, the reliance on a single issuer for a large swath of the market remains a vulnerability.

Ultimately, the distinction between a "custodial" and "non-custodial" card program is becoming increasingly blurred by the operational requirements of the payment networks. Consumers are advised to look beyond marketing slogans and specifically evaluate five criteria:

  1. Ownership status: Does the contract represent a sale of assets or a true smart-contract vault?
  2. Issuer transparency: Is the issuer a recognized financial institution, or an opaque affiliate of the program manager?
  3. Insolvency protections: What legal rights exist if the program manager fails?
  4. Upgrade Authority: Who has the power to change the code governing the funds?
  5. Data Verifiability: Is the reported volume based on transparent on-chain data or self-reported platform metrics?

As the industry matures, the "move fast and break things" mentality that characterized the early adoption of crypto cards is facing a collision with the realities of global financial regulation. For the 1,685 users affected by the Avici exploit, the outcome was positive, but it was a result of corporate goodwill, not the inherent safety of the system. In the future, the stability of the sector will likely depend on moving away from centralized administrative control over collateral and toward architectures that provide verifiable, cryptographically guaranteed user control.

You may also like

Leave a Comment