At 16:49:48 UTC on Friday, August 28, 2026, a Solana wallet—funded just three hours prior with 1.79 SOL derived from $190 in USDC bridged from Ethereum—initiated a series of commands that began systematically draining card-balance accounts held by users of Avici, a prominent Solana-based neobank. By the time the exploit was neutralized, 1,685 users had seen their balances liquidated, totaling a loss of $500,859.22. This incident, while rapidly contained, has cast a harsh spotlight on the "non-custodial" crypto card market, a sector that has seen its monthly transaction volume explode to over $1.1 billion as of August 2026.
The vulnerability did not stem from stolen private keys or compromised user devices. Instead, it lay within a specific Solana card contract shared by Avici and several other programs. The underlying infrastructure belongs to Rain, a card-issuing company that has become the backbone of much of the self-custodial card market. While Avici’s terms of service, last updated in June 2025, assured users that neither the company nor the issuer held custody of their collateral, the technical reality of the smart contract architecture allowed for a systemic failure. The incident serves as a stark reminder that in the world of crypto-native finance, the definition of "non-custodial" is often dictated by the nuance of smart contract permissions rather than the absolute security of user assets.
A Chronology of the August Drain
The exploit was surgical and efficient. The attacker’s wallet, identified on-chain as 0xFVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj, remained dormant for 189 minutes after its initial funding before launching its first attack at 16:49:48 UTC. Over the next two and a half hours, the wallet executed approximately 21,405 transactions, with roughly 17,500 successfully interacting with the Rain-controlled Solana program.
The mechanics of the exploit relied on an authorization bug within the SubmitSignatures call. By manipulating the signature-verification instruction—pointing the signature, key, and message offsets back at one another—the attacker managed to satisfy a two-signature check with only a single signature. This granted the attacker administrative status over individual user collateral accounts, allowing for the immediate withdrawal of funds.
The fallout was swift. Between 19:03 and 19:49 UTC, as the drain was concluding, the stolen funds were bridged from Solana to Ethereum and moved through Tornado Cash. By 19:18 UTC, Rain had begun patching the affected programs. By September 5, all upgrade authorities for the involved contracts were successfully migrated to a Squads multisig vault, providing a long-term fix to the security architecture.
Market Growth and Concentration Risks
According to data from Paymentscan, the crypto card market has witnessed extraordinary growth, rising from $153 million in monthly volume in December 2024 to $1.116 billion by August 2026. This trajectory highlights a significant shift in consumer behavior, as users increasingly seek to bridge the gap between volatile digital assets and daily retail spending.
However, this growth is heavily concentrated. Paymentscan’s issuer mapping attributes approximately 42% of August’s total volume—$468 million—to programs settling through Rain. When combined with the self-reported figures from RedotPay, these two entities facilitate roughly 78% of the entire tracked crypto card market. This concentration presents a systemic risk: while the August exploit was limited to specific Solana contracts, the reliance on a narrow set of infrastructure providers means that a single architectural flaw can ripple across multiple independent brands simultaneously.

Decoding Custody Models
The industry’s terminology often obscures the legal reality of where money resides. An analysis of 18 major crypto card programs reveals five distinct custody models, ranging from direct debt claims to fully on-chain vaults:
- Sale-to-Operator: Programs like KAST have adopted language that characterizes user deposits as a "sale" of assets to the company. In this model, the user holds a USD-denominated debt claim against the operator, often with limited liability protections and no guarantee of asset segregation in the event of bankruptcy.
- Nominee Custody: Platforms like Revolut act as a "nominee" for the user. While the platform holds legal title, the user is defined as the beneficial owner. This model relies on the robustness of the platform’s balance sheet and the clarity of its insolvency procedures.
- Fiat-Only Issuers: Many exchange-based cards, such as those from Crypto.com or Kraken, do not hold crypto assets on the card account at all. Crypto is held in exchange custody and converted to fiat only at the moment of a transaction. In the EU, this is governed by strict e-money safeguarding regulations.
- Shared Program Pools: This is the category that suffered the August exploit. In this model, user collateral is held in a smart contract. While the user technically owns the collateral, the contract is managed by an operator with administrative upgrade keys. If the authorization logic is flawed, the "non-custodial" nature of the account provides no protection.
- Self-Custodial Vaults: Programs like Gnosis Pay and Ether.fi Cash utilize sophisticated smart account architectures (such as Safe) where the user maintains control over their assets, often utilizing modules for spend permissions or time-delayed transactions. These are currently the most robust designs, though they are not immune to logic errors.
The Issuer Landscape: Beyond Traditional Banking
A significant finding in the current market structure is the role of "Third National." Seven of the programs analyzed—including Avici, KAST, and Ether.fi Cash—list Third National as their card issuer. Investigations reveal that Third National is not a chartered bank, but rather a Puerto Rico-based money transmitter operating under the corporate umbrella of Signify Holdings, Inc. (Rain).
This underscores a broader trend: many crypto-native card programs are built on non-bank infrastructure, utilizing stablecoin lending networks to facilitate settlement. When a user taps their card, Rain settles with the merchant via Visa and is subsequently repaid from the user’s collateral contract. This "charge card" model, financed by institutional stablecoin liquidity, is highly scalable but introduces dependencies on the creditworthiness and operational security of the underlying infrastructure provider.
The Regulatory Horizon and Future Outlook
The regulatory landscape is poised to change dramatically with the implementation of the EU’s Anti-Money Laundering Regulation (Regulation (EU) 2024/1624), effective July 2027. This framework will effectively prohibit anonymous crypto-asset accounts and limit the usage of anonymous prepaid cards. These impending rules are expected to force a consolidation in the market, favoring programs that maintain transparent KYC (Know Your Customer) and KYB (Know Your Business) compliance.
The recent failures of programs like Kulipa and the closure of Bit.Store following the revocation of its issuer’s license serve as reminders that card programs are fragile. Often, the decision to terminate a service is made by a sponsor bank or a network, leaving the consumer brand with little recourse.
Lessons from the August Incident
Despite the loss of $500,000, the August 28 incident had a relatively positive outcome for users. Rain and the affected programs, such as Avici and Tria, stepped in to refund all impacted users within 24 hours. This response highlights that, for now, the industry is operating on a model of "socialized risk," where venture-backed entities prioritize reputation and customer retention by covering losses out of their own balance sheets.
However, the event serves as a warning for the next phase of market development. As transaction volumes continue to grow, the industry can no longer rely on the promise of venture-backed refunds to mitigate smart contract risks. The path forward requires a transition toward more transparent, immutable, and fully audited on-chain vault architectures. For the end user, the lesson is clear: "non-custodial" is not a synonym for "invulnerable." Before topping up a card, users should look past the marketing, verify the issuer’s regulatory standing, and understand whether the smart contract holding their collateral is truly isolated or subject to the administrative whims of a single, centralized key.
As of September 2026, the sector stands at a crossroads. The integration of stablecoin-powered payments into the Visa network is a major technological milestone, but the infrastructure supporting this growth remains a work in progress. For the millions of users participating in this ecosystem, the security of their assets depends as much on the quality of the legal documentation and the strength of the multisig upgrade keys as it does on the underlying blockchain technology.
