At 16:49:48 UTC on Friday, August 28, 2026, a Solana wallet—funded just three hours prior with 1.79 SOL via a modest $190 USDC bridge from Ethereum—began systematically draining card-balance accounts associated with Avici, a prominent Solana-based neobank. The event marked a critical stress test for the burgeoning "non-custodial" crypto card sector, a category that has seen its monthly volume surge to over $1.1 billion by August 2026. While Avici’s terms of service, last updated in mid-2025, assured users that neither the company nor its issuer would hold custody of collateral, the reality of the technical architecture proved more vulnerable than the legal language suggested.
By the time the reconciliation was finalized, Avici confirmed that 1,685 users had lost a total of $500,859.22. The funds were held within a shared Solana card contract infrastructure utilized by Avici and several other programs, all managed by Rain, the card-issuing company that currently serves as the backbone of much of the self-custodial card market. In the immediate aftermath, Rain moved to cover every refund, with Avici and Tria—a second program hit by the same vulnerability—adding an additional 10% on top of the losses to appease their user base.
A Chronology of the August 28 Exploit
The exploit was characterized by precision and speed. The attacker’s wallet, identified as 0xFVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj, remained dormant for 189 minutes after its initial funding before launching the attack. Over the next two and a half hours, the wallet executed approximately 21,405 transactions, with 17,500 successfully bypassing security protocols.
The technical flaw lay in the signature-verification logic of the Rain-managed Solana program. The attacker utilized a SubmitSignatures call paired with a native Ed25519 verification instruction. By cleverly pointing the signature, key, and message offsets of the second verification instruction back at the first, the attacker was able to satisfy a two-signature requirement with a single valid signature. This effectively granted the attacker "collateral admin" status on over a thousand individual accounts, allowing for the subsequent unauthorized withdrawal of assets.
The impact was localized but significant. While the median loss per user was roughly $24, some accounts lost upwards of $5,000. It was not a breach of private keys or a compromise of individual user wallets; rather, it was an authorization bug within the program’s logic. By 19:18 UTC, Rain had begun deploying patches to the affected program IDs. By early September, the company had migrated the upgrade authority for these programs to a secure Squads multisig vault, effectively centralizing the "master key" that had previously been held by a single, vulnerable keypair.
The Ecosystem: Tracking $1.1 Billion in Monthly Flow
Data from Paymentscan indicates that the crypto card sector has reached a mature, if volatile, state. In August 2026, the sector recorded $1.116 billion in volume across 11 million transactions and nearly 290,000 active addresses. This figure represents a dramatic rise from the $153 million recorded in December 2024.
However, these figures require careful interpretation. A significant portion of this volume—roughly 42%—is attributed to programs settling through Rain. When combined with self-reported data from major players like RedotPay, two entities effectively account for nearly 78% of all tracked crypto card volume. The industry is characterized by significant concentration, which, while efficient, creates systemic points of failure. The collapse of institutions like the Bank of Lithuania’s revocation of Paytend’s license earlier in 2026 serves as a reminder that the underlying financial rails are often more fragile than the consumer-facing brand.

Understanding Custody Models: The Five Tiers of Risk
To understand how users’ money is handled, one must distinguish between five primary custody models identified across the 18 major card programs analyzed:
- Sold to the Operator: In models like KAST, user deposits are legally framed as a "sale" of assets to the platform. The user holds a USD-denominated debt claim against the operator, meaning that in the event of bankruptcy, users are treated as unsecured creditors.
- Held in Custody: Platforms like RedotPay or Revolut maintain assets in custodial accounts. While the user is the beneficial owner, the platform maintains legal title, creating a reliance on the operator’s solvency and regulatory standing.
- Fiat Conversion: Exchanges like Crypto.com and Kraken often convert crypto to fiat at the moment of the swipe. The crypto itself never sits on the card, and the fiat portion is handled by licensed e-money institutions subject to statutory safeguarding requirements.
- Shared Collateral Contracts: This is the model used by Avici, Tria, and Rain. While "non-custodial" in the sense that the user controls their own wallet, the card-spending mechanism requires funds to be moved into a smart contract managed by a third party. As seen in August, this "non-custodial" promise is only as secure as the underlying smart contract code and the operator’s upgrade authority.
- User-Controlled Vaults: The most robust model, utilized by Gnosis Pay and Ether.fi Cash, involves the user holding their own vault. Spend permissions are scoped strictly to the card, and the operator cannot move funds independently. Even here, however, complex "roles" and "delay" modules have previously been targeted by attackers.
The Role of "Third National" and Regulatory Implications
A critical, often overlooked finding is that many of these self-custodial programs name "Third National" as their card issuer. Investigations reveal that Third National is not a traditional chartered bank, but rather a Puerto Rico-based money transmitter operating as part of the Rain group. This is a vital distinction for consumers: Rain and its affiliates explicitly state they are not banks, do not provide FDIC insurance, and do not hold deposits.
The business model relies on a network of capital partners who lend stablecoins to facilitate network settlement for credit card receivables. When a user swipes, Visa settles with the merchant, Rain pays Visa from borrowed stablecoins, and the user’s contract is then liquidated to repay that loan. This infrastructure is scaling at an institutional pace, with heavyweights like Western Union, Ethena, and MoneyGram integrating with the Rain network.
Broader Implications for the "No-KYC" Market
Parallel to the mainstream programs, the "no-KYC" (Know Your Customer) card market remains a high-risk niche. Analysis of 11 such cards reveals a consistent lack of transparency regarding the issuing entity. Most rely on the "business verification" loophole, where a company completes business-level KYC and then issues cards to individuals as "authorized spenders."
Regulators are closing in on these gaps. The European Union’s Anti-Money Laundering Regulation (EU) 2024/1624, applicable from mid-2027, will effectively prohibit anonymous crypto-asset accounts and restrict the use of anonymous prepaid cards issued in third countries. As industry experts have noted, the no-KYC status is rarely a permanent feature; it is often a temporary state that ends abruptly when a BIN sponsor or network regulator demands compliance.
The Path Forward: Lessons from 2026
The August 28 incident was a wake-up call regarding the nomenclature of "non-custodial" crypto products. In the marketing materials of these programs, "non-custodial" implies safety. In the fine print of a cardholder agreement, however, it merely defines who cannot move your funds during normal operation. It says nothing about who wrote the contract, whether the code was audited, or who holds the keys to upgrade the protocol.
The fact that Avici and Tria users were made whole was not due to the inherent security of the smart contract, but rather the decision of a well-capitalized private company to absorb the loss to preserve its reputation. This highlights the paradox of the modern crypto-card sector: users are seeking the autonomy of self-custody while relying on the centralized balance sheets of venture-backed firms to act as the ultimate backstop.
For the end user, the lesson is clear. Before funding a crypto-linked card, one must move past the marketing. The key questions are: Is the asset truly in my control, or is it in a contract I cannot access? Who is the legal issuer? What happens to my balance if the issuer loses its license? And perhaps most importantly, who holds the ability to upgrade the smart contract that governs my collateral? As the industry continues to scale, transparency regarding these technical and legal structures will become the deciding factor between a sustainable financial tool and a recurring systemic risk. The growth of the sector to over $1 billion in monthly volume proves there is a massive appetite for these products, but the infrastructure remains in its infancy, characterized by rapid iteration, frequent failures, and a heavy reliance on the integrity of the entities behind the code.



