At 16:49:48 UTC on Friday, August 28, 2026, a Solana wallet—funded just three hours prior with 1.79 SOL derived from $190 in USDC bridged from Ethereum—initiated a series of transactions that would trigger a crisis for Avici, a prominent Solana-based neobank. By the time the dust settled, 1,685 users had been drained of $500,859.22. This incident was not a breach of individual private keys or a compromise of user wallets; rather, it was a structural failure within a shared smart contract infrastructure managed by Rain, the firm that serves as the card-issuing backbone for a significant portion of the self-custodial crypto card market.
The breach highlights the growing, often invisible complexity of the $1.1 billion-a-month crypto card industry. While marketing materials frequently tout these products as "non-custodial," the technical reality is far more nuanced. In the case of Avici, the funds were held in smart contracts that, while technically accessible to users, were subject to administrative authority that could be—and was—exploited.
A Chronology of the August Drain
The exploit was surgical and efficient. The attacker’s wallet, identified as FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj, remained dormant for 189 minutes after its initial funding before launching the attack. Between 16:49:48 UTC and 19:18:52 UTC, the wallet executed approximately 21,405 transactions against a Rain-controlled Solana program. Roughly 17,500 of these were successful.
Each successful transaction utilized a specific authorization loophole. The attacker performed a SubmitSignatures call paired with a native Ed25519 signature-verification instruction. By manipulating the signature, key, and message offsets, the attacker bypassed the program’s two-signature requirement, effectively tricking the smart contract into granting them "collateral admin" status. Once this status was achieved, the attacker systematically withdrew assets from over a thousand individual user accounts.
The impact was swift. By 19:03:18 UTC, while the drain was still in progress, the attacker utilized a deBridge order to move over $1 million in USDC to Ethereum. This was followed by a series of smaller swaps through Jupiter to convert the remaining 886.94 SOL. The total haul, approximately 1,113,096.76 USDC, was funneled into a single Ethereum address. Within less than thirty minutes of the final bridge, the funds were processed through the Tornado Cash mixer in a standard laddered sequence.
The Institutional Response
The resolution of the incident was as rapid as the theft. Because the affected programs—Avici, Tria, and Solayer—relied on Rain’s infrastructure, the response was coordinated at the issuer level. By 19:18:37 UTC, Rain had begun patching the most severely affected program. The remaining two were patched within thirty minutes.
Avici confirmed that all 1,685 affected users were fully reimbursed, with the capital provided by Rain and an additional 10% buffer added by the programs themselves. This rapid "make-whole" approach served to stabilize the ecosystem, but it also underscored a critical reality: the "non-custodial" nature of these cards is a spectrum. While the users held their keys, the underlying collateral was stored in a contract governed by an upgradeable key held by a private entity. When that entity—Rain—suffered a failure, the company’s own balance sheet became the insurance policy.
Data and Market Concentration
Paymentscan data for August 2026 illustrates the sheer scale of this sector. Total volume reached $1.116 billion across 11 million transactions, marking the second consecutive month above the billion-dollar threshold. However, this headline number requires careful interpretation. Approximately 42% of this volume, or $468 million, is tied to programs settling through Rain. When including RedotPay—which self-reports spend metrics—two entities effectively control nearly 78% of the tracked market.

This concentration of infrastructure creates systemic risk. The August incident proved that when a single issuer’s codebase is vulnerable, the failure propagates across multiple, seemingly distinct brands simultaneously. While Ether.fi Cash remained untouched, its isolation was not due to luck but to its specific architectural design, which utilizes individual, isolated vaults rather than a shared collateral pool managed by an overarching program administrator.
Custody Models: Five Tiers of Risk
To understand the risks, one must categorize how these programs hold value. The industry generally falls into five tiers:
- Sold to the Operator: In this model, as seen with KAST, users essentially trade their crypto for a debt claim. Once the assets are transferred, the user no longer holds an ownership interest in the crypto but rather an enforceable claim against the operator’s corporate treasury.
- Custodial Nominee: Platforms like Revolut and RedotPay hold assets on behalf of the user. While the user is the beneficial owner, the legal title rests with the platform, making the assets subject to the platform’s insolvency risk.
- Fiat Conversion: Cards from major exchanges like Crypto.com or Kraken often do not hold crypto at all. Instead, the crypto is converted to fiat at the moment of sale, and the resulting fiat is held by a regulated e-money institution.
- Program-Managed Collateral: This is the model used by Avici and Tria. Funds reside in smart contracts that are "non-custodial" in that they are not held in a central omnibus account, but they are subject to an administrator’s logic, which can be altered or exploited.
- Vault-Based Self-Custody: Programs like Gnosis Pay and Ether.fi Cash represent the highest tier of security. Funds are held in individual smart contracts (Safes or Vaults) that are controlled by the user, with spend permissions strictly limited and automated by code rather than administrative decree.
The "No-KYC" Illusion
Parallel to the main market, a "no-KYC" card segment has proliferated, often operating in a regulatory gray area. These cards, frequently marketed as privacy-centric, often mask significant counterparty risks. An analysis of eleven such cards revealed that only one named its issuer. The majority rely on "licensed partners" or opaque corporate entities.
The mechanism, as reported by industry observers, typically involves a company completing "Know Your Business" (KYB) verification to act as a master account, which then issues cards to individuals. This approach is highly vulnerable to regulatory crackdowns. When the sponsor bank or network—such as Visa or the institution behind the BIN—decides to terminate the program, the brands themselves are often powerless to assist their users, as seen in the 2026 collapse of Bit.Store following the revocation of its issuer’s license.
Implications and Regulatory Horizon
The European Union’s Anti-Money Laundering Regulation (EU 2024/1624), set to take effect in July 2027, poses a significant threat to the anonymous prepaid card segment. By prohibiting the use of anonymous crypto-asset accounts and restricting the ability of EU acquirers to accept payments from anonymous cards issued in third countries, the regulation will likely force a consolidation of the market.
For the mainstream, self-custodial sector, the August 2026 incident serves as a stark reminder of the "upgrade authority" risk. In the world of smart contracts, the code is only as secure as the key that governs its updates. Even when a platform correctly implements decentralized custody, if the contract can be upgraded by a single private keypair, the platform remains effectively custodial.
The shift toward multisig governance—as evidenced by Rain’s move to a Squads multisig vault following the breach—is a necessary evolution. However, it does not mitigate the fundamental reliance on the issuer’s technical competency. As the industry matures, cardholders are increasingly forced to look past the marketing of "non-custodial" assets and interrogate the underlying infrastructure: who writes the code, who holds the upgrade keys, and what happens if the issuer’s corporate entity faces insolvency?
As of September 2026, the sector continues to grow, fueled by $250 million in venture capital and increasing institutional integration with traditional networks like Visa. Yet, the events of August confirm that in the crypto card space, the gap between a "non-custodial" promise and a "non-custodial" reality is often defined by a single line of smart contract code. Users who rely on these products are advised to treat their card balances not as long-term savings, but as transient funds for daily commerce, acknowledging that the ultimate safeguard remains the willingness of the issuer to step in when the code fails.
With $1.1 billion in monthly volume, the crypto card industry is no longer a niche experiment. It is a vital, if fragile, bridge between decentralized finance and global retail payments. Whether that bridge remains stable depends on the industry’s ability to transition from "trust-me" models toward transparent, audit-ready, and truly immutable infrastructure. Until then, the risks associated with program managers, shared contract pools, and opaque issuing partners will remain a defining characteristic of the landscape.
