Home Decentralized Finance (DeFi) Crypto Card Volume in 2026: $1.1 Billion a Month, and What Is Inside It

Crypto Card Volume in 2026: $1.1 Billion a Month, and What Is Inside It

by admin

At 16:49:48 UTC on Friday, August 28, 2026, a Solana-based digital wallet initiated a sequence of transactions that would expose a critical vulnerability in the architecture of modern "non-custodial" crypto debit cards. The wallet, which had been funded just three hours earlier with 1.79 SOL—purchased via approximately $190 in USDC bridged from the Ethereum network—began systematically draining card-balance accounts held by users of Avici, a Solana-focused neobank. By the time the incident was contained, 1,685 users had seen a combined total of $500,859.22 siphoned from their accounts. The breach did not target the users’ personal keys or primary wallets; instead, it exploited the specific smart contract infrastructure that allows these cards to function as "non-custodial" financial instruments.

The incident highlights a growing tension in the decentralized finance (DeFi) sector between the promise of user sovereignty and the technical realities of card-issuing infrastructure. While Avici’s terms of service, last updated on June 23, 2025, explicitly stated that "Avici and Issuer will not, in any circumstance, be holding custody of your Collateral," the reality of the smart contract deployment told a different story. The contract in question belonged to Rain, a card-issuing entity that provides the backbone for a significant portion of the self-custodial card market. Despite the breach, Avici confirmed that Rain covered every refund in full, with Avici and Tria—a secondary program also affected by the same vulnerability—adding a 10% surplus to compensate users for the disruption.

Chronology of the August 28 Exploit

The exploit was characterized by a high degree of technical precision. The attacker’s wallet, identified by the address FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj, remained dormant for 189 minutes after its initial funding before launching the attack. Between 16:49:48 UTC and 19:18:52 UTC, the wallet executed over 21,400 transactions. Each successful hit followed a three-step process: a SubmitSignatures call utilizing native Ed25519 signature-verification, followed by an AddCollateralAdmin instruction, and finally a WithdrawCollateralAsset command.

The core of the vulnerability lay in the program’s signature-verification logic. The attacker’s second verification instruction redirected its signature, key, and message offsets back to the first, effectively allowing a single signature to satisfy a check intended to require two. This granted the attacker administrative privileges over more than 1,000 individual user accounts. Because the funds were held in a smart contract that the program manager—in this case, Rain—could theoretically upgrade with a single plain signing key, the "non-custodial" nature of the assets was undermined by centralized administrative authority.

Rain’s remediation was swift but highlighted the risks of legacy code. The first patch for the most heavily impacted program was implemented at 19:18:37 UTC, just 15 seconds before the attacker ceased activity. Subsequent patches for the other two programs were deployed shortly thereafter. By September 5, 2026, Rain had migrated the upgrade authority for these programs to a Squads multisig vault, a more secure arrangement that prevents any single key from unilaterally modifying the contract.

Market Context and Volume Growth

The incident occurred against a backdrop of rapid expansion for crypto-linked payment cards. According to data from Paymentscan, monthly crypto card volume reached $1.116 billion in August 2026, spanning 11 million transactions and over 287,000 active addresses. This figure represents the second consecutive month of volume exceeding the $1 billion threshold. Since March 2023, the cumulative volume for this sector has reached $11.61 billion.

Crypto Cards 2026: Who Holds the Money Before the Swipe

However, the headline figures require careful interpretation. Paymentscan recently restated its historical data to include ten additional programs and unattributed issuer flows. Notably, approximately 36% of the August volume is derived from self-reported data by RedotPay, which complicates independent verification. When excluding these self-reported figures, the total volume of on-chain observed spending stands at approximately $545 million, a 55% increase since March 2026. Ether.fi Cash currently stands as the largest program with fully transparent, on-chain visible purchases, accounting for $109.5 million in August volume.

Custody Models: A Spectrum of Risk

The diversity of custody models currently employed by the 18 programs reviewed reveals a wide spectrum of legal and technical risk. These models generally fall into five distinct categories:

  1. Sale to the Operator: Some programs, such as KAST, utilize terms that frame the transfer of assets as a "sale" to the company. In this model, the user holds a USD-denominated debt claim against the issuer rather than an ownership interest in the original crypto assets.
  2. Custodial Nominee: Programs like RedotPay and Revolut act as custodians, holding assets on behalf of the user. While this is a standard financial arrangement, it introduces dependency on the custodian’s solvency.
  3. Fiat Conversion: Exchange-based cards, such as those from Crypto.com and Kraken, convert crypto to fiat at the moment of the transaction. In these cases, no crypto balances are held on the card, and users are protected by established electronic money (e-money) regulations in jurisdictions like the EU and UK.
  4. Program-Pool Smart Contracts: Programs like Avici, Tria, and Payy utilize smart contracts where collateral is held in the card program’s pool. As demonstrated in the August 28 incident, the vulnerability of this model is linked to the administrative authority over the contract, not the user’s individual wallet keys.
  5. Self-Custodial Vaults: The strongest model, utilized by Gnosis Pay and Ether.fi Cash, involves smart contracts or vaults that the operator cannot move. These programs typically use scoped spend permissions or "delay modules" to ensure the user retains control, though even these systems are subject to potential signature-verification flaws.

The Role of "Third National" and Infrastructure Concentration

A critical finding in the investigation of these programs is the concentration of issuing services. Seven of the 18 programs reviewed—including KAST, Avici, Ether.fi, and Solayer—name "Third National" as their card issuer. Legal disclosures reveal that Third National is a business name for Nimbus LLC, an affiliate within the Signify Holdings (Rain) group.

This structure means that a substantial share of the "non-custodial" card market relies on a Puerto Rico-based money transmitter rather than a traditional chartered bank. Rain’s operational model involves borrowing stablecoins to facilitate network settlement for credit card receivables, effectively turning these "non-custodial" cards into charge cards financed by the issuer. While this model has allowed for rapid scaling—evidenced by Rain’s recent $250 million Series C funding round—it creates a single point of failure for the programs that rely on its codebase.

Implications for the Future of Crypto Payments

The events of August 2026 serve as a stark reminder that in the world of crypto-native finance, marketing terminology often diverges from technical reality. The term "non-custodial" in a cardholder agreement describes who cannot move funds during normal operation, but it remains silent on the critical issues of who wrote the smart contract, whether the deployed code matches the audited version, and who holds the administrative upgrade keys.

The rapid recovery of funds for affected users was made possible not by the robustness of the underlying code, but by the financial reserves of a private venture-backed entity. This provides a temporary safety net, but it does not resolve the systemic risks inherent in centralized administration of "decentralized" products. As the EU prepares to implement the Anti-Money Laundering Regulation (Regulation (EU) 2024/1624) in 2027, the regulatory landscape for anonymous or "no-KYC" cards is expected to tighten significantly. These regulations will likely prohibit anonymous crypto-asset accounts and bar EU acquirers from processing payments from anonymous prepaid cards issued in third-party jurisdictions.

For the end user, the path forward requires a higher degree of due diligence. Beyond the marketing slogans, participants must evaluate the specific custody model, the legal identity of the card issuer, the provisions regarding insolvency, and the security of the smart contract upgrade path. The August incident was a loud failure that necessitated a high-profile response, but as the broader industry matures, the quiet failures—such as the wind-downs of Kulipa and Gnosis Pay’s consumer interface—suggest that the market is beginning to prioritize sustainable, transparent infrastructure over rapid, experimental growth. The $1.1 billion monthly volume confirms the utility of crypto-linked cards, but the technical vulnerabilities exposed this summer emphasize that the bridge between traditional finance and blockchain remains under construction.

You may also like

Leave a Comment