Home Decentralized Finance (DeFi) Crypto Card Volume in 2026: $1.1 Billion a Month, and What Is Inside It

Crypto Card Volume in 2026: $1.1 Billion a Month, and What Is Inside It

by admin

At 16:49:48 UTC on Friday, August 28, 2026, a Solana wallet—funded just three hours prior with 1.79 SOL derived from $190 in USDC bridged from Ethereum—initiated a series of commands that began draining balances from users of Avici, a prominent Solana-based neobank. While Avici’s legal documentation, last updated on June 23, 2025, explicitly stated that "Avici and Issuer will not, in any circumstance, be holding custody of your Collateral," this contractual language failed to protect the underlying assets. By the time the incident was resolved, 1,685 users had seen their accounts compromised, resulting in a collective loss of $500,859.22. The funds were siphoned from a smart contract architecture utilized not only by Avici but by several other programs, all of which relied on infrastructure provided by Rain, the dominant firm in the self-custodial card market.

The breach was not a traditional theft of private keys, nor was it a compromise of individual user wallets. Instead, the vulnerability lay within the central "program manager" contract—a mechanism designed to be non-custodial but which nonetheless contained a single, plain signing key capable of upgrading the contract’s logic. This event has cast a spotlight on the fragility of the "non-custodial" card category, which has seen transaction volumes nearly double since the spring of 2026, even as the industry grapples with the collapse of large issuers and the revocation of electronic money institution (EMI) licenses.

Chronology of the August 28 Exploit

The attacker’s wallet, identified on-chain as FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj, remained largely inactive for nearly three hours following its funding. At 16:49:48 UTC, the first exploit transaction was broadcast. Over the next two and a half hours, the wallet executed approximately 21,405 transactions, with roughly 17,500 resulting in successful fund transfers.

The exploit utilized a sophisticated authorization bug in the Rain-controlled Solana programs. By leveraging a native Ed25519 signature-verification instruction, the attacker forced the program to accept a single signature as valid for a two-signature requirement. This allowed the attacker to grant themselves "collateral admin" privileges on over 1,000 individual user accounts. Once administrative control was established, the withdrawal of funds became a trivial matter. The median loss per user was approximately $24, though some accounts saw significantly higher depletion, with the largest individual loss reaching $5,268.

The incident response was rapid but largely private. By 19:18:37 UTC, just fifteen seconds before the attacker’s final malicious transaction, Rain had pushed a patch to the most severely affected program. The remaining programs were updated by 19:43:42 UTC. By September 5, Rain had migrated the upgrade authority for all three compromised programs to a more secure Squads multisig vault (7MoSDo66QknjsyE8yX9VnsrbGj4cQTDYVjo2JHLt5RSL), finally closing the door on the vulnerability.

The Landscape of Crypto Card Volume

According to data from Paymentscan, total crypto card volume in August 2026 reached $1.116 billion, spanning 11 million transactions and over 287,000 active addresses. This marks the second consecutive month that volume has exceeded the $1 billion threshold. Since March 2023, cumulative volume in this sector has surpassed $11.6 billion, reflecting a 32% growth rate since March 2026 when adjusted for restated figures and improved data tracking.

However, these figures carry significant caveats. A large portion of this volume is "self-reported" by operators rather than verified on-chain. For instance, RedotPay—the largest card program by volume—accounted for $403.6 million in August, or roughly 36% of the industry total. Because Paymentscan tracks top-ups on-chain but relies on internal company data for spend, the true nature of liquidity remains opaque. Programs such as Ether.fi Cash, which allow for full on-chain visibility of every purchase, provide a more transparent, albeit smaller, data set. Ether.fi Cash processed $109.5 million in August, crossing the milestone of 10 million total transactions.

Crypto Cards 2026: Who Holds the Money Before the Swipe

Understanding Custody Models

The industry is currently divided into five distinct custody models, each with varying degrees of legal and technical risk.

  1. Sold to the Operator: Programs like KAST have moved toward a "sale" model where the user’s crypto assets are legally transferred to the company in exchange for a USD-denominated debt claim. In the event of bankruptcy, users are treated as general creditors.
  2. Held in Custody for You: This model, used by RedotPay and major exchanges like Coinbase, involves the operator holding assets on the user’s behalf. While legally distinct from the operator’s treasury, the enforceability of these claims in bankruptcy remains untested in many jurisdictions.
  3. Converted to Fiat at Licensed Issuers: Companies like Crypto.com and Kraken convert crypto to fiat at the point of sale. In the EU and UK, these fiat funds are often "safeguarded" under e-money regulations, providing a layer of protection against institutional insolvency.
  4. Smart Contract Pools: Programs like Avici and Tria allow users to maintain their own contracts, but these contracts are managed within a pool administered by a third party like Rain. This was the model compromised in August.
  5. Direct Vault/JIT Debit: The most robust model, used by Gnosis Pay and Bridge, involves a self-custodial smart account that the operator cannot move. Spend permissions are strictly scoped, and the operator only pulls the exact amount required at the moment of authorization.

The "Third National" Concentration Risk

A significant systemic vulnerability is the high level of concentration in card issuing. Seven of the 18 programs analyzed—KAST, Avici, Ether.fi Cash, Plasma One, Solayer, Payy, and Tria—name "Third National" as their issuer. Investigation reveals that Third National is not a bank in the traditional sense, but a brand name for Nimbus LLC, a Puerto Rico-licensed money transmitter and an affiliate of Rain.

Rain acts as the central hub, facilitating settlement through a network of capital partners who borrow stablecoins to cover card receivables. While this model allows for rapid scaling, it introduces a "single point of failure" for the infrastructure. If the issuer’s license is revoked or the network mandates a shutdown, multiple card programs could be rendered unusable simultaneously.

Implications and Regulatory Outlook

The August 28 exploit demonstrated that "non-custodial" marketing often masks the reality of centralized control over smart contract upgrade keys. While Avici and Rain successfully made all affected users whole, the recovery was funded by the companies’ own balance sheets, not by any inherent feature of the underlying protocol.

The industry is also bracing for the implementation of the EU’s Anti-Money Laundering Regulation (AMLR) in 2027. This regulation will effectively prohibit anonymous crypto-asset accounts and restrict the use of anonymous prepaid cards. As supervisors tighten their grip, the era of "no-KYC" cards appears to be reaching its end. Many of these services have already faced sudden shutdowns or BIN freezes as regulators and card networks prioritize compliance over the privacy features previously marketed to users.

Conclusion

The incident highlights a critical distinction between technical self-custody and legal protection. Even if a user retains their private keys, the smart contract governing their card spend may still be susceptible to administrative interference or design flaws. As the crypto card market continues to scale—now handling over $1 billion monthly—users must look beyond marketing buzzwords. They must scrutinize who holds the upgrade authority for their contracts, who the legal issuer is, and what happens to their assets in the event of an institutional insolvency.

For now, the sector remains in a state of rapid, often chaotic, evolution. The success of programs like Ether.fi Cash and Gnosis Pay suggests a path toward more secure, transparent architectures, but the concentration of risk within Rain-led programs indicates that systemic vulnerabilities remain a central concern for the next phase of the industry’s growth. The lesson from August 2026 is clear: in the world of crypto-native finance, where the money sits and who controls the code matters far more than the promise of being "non-custodial."

You may also like

Leave a Comment