At 16:49:48 UTC on Friday, August 28, 2026, a Solana-based wallet—funded just three hours prior with 1.79 SOL via a bridge from Ethereum—initiated a series of transactions that would expose a critical vulnerability in the architecture of modern "non-custodial" banking. By the time the dust settled, 1,685 users of Avici, a prominent Solana neobank, had seen their card-balance accounts drained of $500,859.22. This incident was not merely a local technical failure; it served as a jarring wake-up call for the rapidly expanding $1.1 billion-a-month crypto card industry, highlighting the precarious gap between the marketing of "self-custody" and the reality of underlying smart contract infrastructure.
The drain originated from a "Solana card contract" shared by Avici and a limited number of other programs, all managed by Rain, the infrastructure powerhouse behind a significant portion of the self-custodial card market. While Avici’s terms of service, last updated in June 2025, assured users that the platform would "not, in any circumstance, be holding custody of your Collateral," the reality proved more complex. While the company technically did not hold the funds in a traditional custodial sense, the design of the smart contract allowed for an administrative override that circumvented user security.
A Chronology of the August Drain
The attack followed a precise, automated cadence. The attacker’s wallet (FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj) remained dormant for approximately three hours after funding. At 16:49:48 UTC, it launched the first of 21,405 exploit transactions. Using a signature-verification flaw in the Rain-controlled Solana program, the attacker exploited the SubmitSignatures instruction. By carefully manipulating the Ed25519 signature-verification offsets, the attacker was able to trick the contract into accepting a single signature as valid for a two-signature check.
This flaw allowed the attacker to grant themselves "collateral admin" status on over a thousand individual user accounts. With administrative privileges, the attacker methodically executed WithdrawCollateralAsset calls. The median loss per user was relatively small—approximately $24—but the aggregate impact was significant. The exploit window remained open for two hours and 29 minutes, concluding at 19:18:52 UTC.
The movement of the stolen funds was equally sophisticated. Throughout the attack, the perpetrator utilized deBridge to move over $1.1 million in USDC from the Solana blockchain to Ethereum. By 19:49:23 UTC, the stolen assets were being funneled into the Tornado Cash mixer in a standardized ladder of 455.9 ETH. Despite the speed of the theft, the remediation efforts were equally rapid. Avici confirmed that Rain, as the program manager, covered every refund, with both Avici and the secondary program Tria contributing an additional 10% on top of the losses to restore user confidence.
The Anatomy of Crypto Card Custody
To understand how this occurred, one must categorize the five distinct models of custody currently dominating the 18 major programs surveyed. At one end of the spectrum is the "Sold to the Operator" model, exemplified by KAST. As of their July 2026 terms, KAST treats user asset transfers as a sale, granting the user a debt claim against the company rather than ownership of the underlying assets. This essentially places the user in the position of an unsecured creditor in the event of bankruptcy.
At the other end is the "Self-Custodial Vault" model used by programs like Gnosis Pay and Ether.fi Cash. These programs utilize smart accounts where the user retains control via their own keys, with spend permissions scoped specifically to the card. The August exploit occurred in the middle-ground: a "Contract Pool" model where users own the collateral in a smart contract, but the contract is written and managed by a central entity—in this case, Rain—which retains upgrade authority.
The vulnerability was not in the users’ private keys, but in the upgrade authority of the contract itself. Before the incident, the upgrade authority for the affected programs was held by a plain keypair, allowing for single-point-of-failure risks. Following the exploit, Rain migrated the upgrade authority for these programs to a Squads multisig vault on September 5, 2026, effectively closing the administrative backdoor.

Data and Market Concentration
Paymentscan data indicates that the crypto card market has seen an unprecedented surge, with August 2026 volume hitting $1.116 billion across 11 million transactions. However, this growth masks significant concentration. Approximately 42% of this volume is routed through programs settling via Rain. When combined with RedotPay, which reports its own spend metrics, two entities account for roughly 78% of the entire tracked market.
This concentration introduces systemic risk. The issuer behind seven of the programs surveyed—including KAST, Avici, Ether.fi, Plasma One, Solayer, Payy, and Tria—is "Third National." Crucially, Third National is not a traditional bank, but a Puerto Rico-based money transmitter. Rain’s own documentation clarifies that it does not provide FDIC insurance or hold deposits, but rather manages a network of capital partners who borrow stablecoins to facilitate card settlements. Essentially, the "non-custodial" card is a charge card financed by institutional debt, creating a layer of financial fragility that is rarely transparent to the average consumer.
Regulatory and Industry Implications
The regulatory environment is shifting to address these ambiguities. Regulation (EU) 2024/1624, set to apply from July 2027, will likely curtail the "no-KYC" (Know Your Customer) card model by prohibiting anonymous crypto-asset accounts and restricting the use of anonymous prepaid cards. Current no-KYC offerings, which often rely on business-entity verification to bypass individual identity checks, are increasingly finding themselves in the crosshairs of global regulators.
The industry has already seen the consequences of these regulatory pressures. The collapse of Paytend Europe UAB in March 2026, which led to the discontinuation of Bit.Store card services, demonstrates that when a regulator pulls an electronic money institution’s license, the brand the consumer interacts with is often powerless to retrieve user funds. The decision to shut down is rarely made by the consumer-facing app, but by the sponsor bank or the card network.
The Lessons of 2026
The August 28 incident provides three vital lessons for the future of decentralized finance. First, the term "non-custodial" is a legal and technical descriptor that often obscures the reality of who controls the contract’s upgrade authority. Even if a user holds their own keys, if the smart contract governing the collateral can be updated or bypassed by an administrator, the asset is not truly under the user’s absolute control.
Second, the distinction between "audited" and "deployed" code is a critical failure point. Rain’s contracts had undergone audits, but the specific, older versions deployed on the live programs were not covered by these checks. This highlights a need for rigorous lifecycle management in smart contract deployments, ensuring that legacy code is systematically patched or deprecated.
Finally, the resilience of the ecosystem is currently backed by venture capital, not by decentralized protocol security. The fact that users were made whole within 24 hours was a result of Rain’s balance sheet and corporate commitment, not the inherent safety of the smart contract code. While this protected the user base, it is an unsustainable model for long-term scalability. As the industry matures, the focus must shift from rapid growth and aggressive rewards toward verifiable, immutable custody models where upgrade authority is decentralized and the regulatory status of the issuer is beyond reproach.
For the consumer, the August event served as a stark reminder: the next time a card program touts its non-custodial credentials, the critical question is not who holds the keys, but who holds the keys to the code. Until the infrastructure is as decentralized as the marketing claims, these programs will remain subject to the same systemic risks that have plagued traditional finance for decades.
