Crypto Cards: Where Your Card Balance Really Sits and What the August 28 Solana Exploit Reveals About It
An attack on a card balance contract on Solana took the loaded balance from 1,685 users while their wallets stayed untouched. The case shows why it matters whether your crypto card holds funds as e-money at a licensed institution or in a smart contract.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
When you pay with a crypto card, the money backing that card frequently does not sit in your own wallet. It sits in a separate container operated by the card platform and filled by you when you top up. On August 28, 2026 an attack on exactly such a container showed what that means when things go wrong: users' self-custodied wallets were left untouched, and the loaded card balance was gone.
The provider concerned is not available in Germany. The construction behind it, however, is. This piece places the incident in context, explains the terms and shows you how to tell which custody model your own card uses and who would be responsible in the event of a loss.
What happened in Avici's Solana card contract on August 28, 2026
Avici is a so-called neobank on the Solana blockchain: an app that attaches a Visa card to an on-chain account of its own. On August 28, 2026 the provider disclosed that there was a problem with card payouts. According to the reconstruction by crypto.news, the first malicious transaction occurred at 16:49:48 UTC, and reporting began in the early evening.
On the provider's account, what was affected was neither the Solana network nor the users' app wallet, but a single smart contract in which the backing for the cards is held. Anyone who left their funds in the app without loading them onto the card stood outside the attack. Anyone who had topped up stood inside it.
How the attack worked technically
On the account given by Cryptopolitan, the attacker exploited the payout logic of the program written in Rust by calling the functions SubmitSignatures, AddCollateralAdmin and WithdrawCollateralAsset one after another. The middle step is the decisive one: with it the attacker entered himself as an authorised administrator of the collateral and could then withdraw what had been deposited through the regular route.
The episode was not a single grab. According to the breakdown Avici published later, the attack series comprised 14,672 transactions, of which 2,344 failed. That points to an automated script working through the contract systematically over hours rather than to a one-off strike.
Card balance contract: what it is and why it is not your wallet
A card balance contract is a standalone program on a blockchain into which you transfer funds so that a payment card can draw on them. As soon as you top up, the money leaves your wallet and sits in that contract until a card payment is settled or you pull it back.
The difference from a wallet is practical rather than theoretical. Your wallet is protected by a key only you hold. The card contract has an access logic of its own, usually with roles for the operator so that settlement works at all. Whoever defeats that role management reaches the balances of every user without knowing a single private key.
That is exactly what happened at Avici. The app's self-custodied Solana and EVM wallets were left untouched according to the provider. What was attacked was solely the separate contract into which users had transferred funds for the card. The widespread notion that a self-custodial product is automatically self-custodial as a whole does not hold at this point.
How large the damage was: why $500,000 and $1.07 million can both be right
Two orders of magnitude are circulating about the scale, and both rest on a traceable basis. On the day of the incident crypto.news counted an outflow of 10,005.03 SOL plus around $11,600 in USDC and USDT, together roughly $1.07 million at the price of the time. Avici itself named 1,685 affected users and $500,859.22 in card balances after its internal reconciliation.
The range of roughly $0.5 million to $1.07 million resolves once you look at the reference quantity. The higher figure measures what flowed out of the contract in assets. The lower one measures how much of that could be assigned to individual customer accounts as card balance. Both figures come from different ways of counting, and neither is the "correct" one in the sense of the other.
For you as a reader the lesson matters more than the exact sum: in the first hours of an incident like this, on-chain estimates and the provider's later reconciliation stand side by side, and they rarely coincide. Anyone making decisions in that phase should know which of the two figures they are looking at.

Rain as card issuer: the role the infrastructure in the background plays
The name on the card is the app's. Issuing and technical operation are as a rule handled by a specialised card issuer in the background. At Avici that is the firm Rain, which supplies card programmes for companies and maintains contracts of its own on several blockchains for the purpose.
According to the companies involved, Rain located the fault itself and traced it to an outdated version of its Solana contracts, used besides Avici by a small number of other programmes. The company says all deployments still running on that version were subsequently updated and external forensic specialists brought in. Which other programmes were affected, and whether damage arose there, has not been named publicly.
Avici has undertaken to reimburse all affected card balances in full and says it has filed a report with the FBI's Internet Crime Complaint Center. Whether and when reimbursements have actually been made cannot be verified from outside; the undertaking is an announcement by the company rather than an accomplished fact.
Crypto Credit Cards at a GlanceWhy Jupiter halted card payouts as a precaution
On the same day the card programme of the Solana trading platform Jupiter also briefly paused payouts of card balances. The platform explained this as a precautionary measure while its card partner completed security checks of its own, and stated that its own users' accounts and funds had at no point been affected. Payouts then resumed as normal.
This episode is more instructive than it first appears. The brief halt shows that a fault in a shared contract version reaches several card programmes at once, including ones from which nothing ultimately flows out. The card in your hand can come from a provider whose software you never chose.
What a precautionary payout halt means for you
Such a halt amounts in effect to a temporary block on your card balance. The money is not lost, but it is unavailable for the duration of the check. Anyone parking a whole month's spending on a crypto card notices the difference from a current account in exactly this situation.
Which crypto cards use this model and where Rain issues at all
For German readers the availability question is the first filter, and it comes out clearly for the two programmes named. Avici's documentation lists 47 territories in which the card can be used, among them countries in Latin America, Africa and Asia and individual US states. Europe, the European Economic Area and Germany appear in neither the permitted nor the prohibited list. The Jupiter card, issued by Rain or by DCS depending on country of residence, likewise does not list the EEA among its supported regions.
The model itself is nevertheless available in Germany. The card from ether.fi, for instance, is also issued through Rain, holds the balance in a smart contract vault controlled by the user, and settles on the Ethereum layer 2 Scroll. The provider's help page lists twenty unsupported countries, among them Estonia, Finland, the Netherlands and Hungary; Germany is not on it. Because this programme does not settle on Solana, it falls outside the contract version at issue in the Avici case.
Anyone looking around this product group finds cards with quite different mechanics side by side. Which models exist and how fees and cashback differ is set out in the overview of crypto credit cards. The custody question is only one of several there, but it is the one that decides responsibility when something goes wrong.
MiCA and the e-money licence: which rules apply to a card balance in Europe
In the EU a payment card with a loaded balance is normally an e-money product. The issuer needs authorisation as an e-money institution for it, must separate customer funds from its own assets and hold them at a bank or in safe investments. Where crypto enters the picture, authorisation as a crypto-asset service provider has been added since the MiCA transition period ended on July 1, 2026.
The difference from deposit protection matters: segregated custody means that customer funds do not fall into the estate if the provider becomes insolvent. It does not mean that a state guarantee scheme steps in for losses, as it does for bank deposits up to 100,000 euros. Advertising for payment cards regularly conflates the two.
If your card balance sits in an on-chain contract instead, this framework does not apply in that form. There is then no custodied customer money at an institution, but assets in a program whose security depends on the code and on its role management. Reimbursement in that case is a matter of goodwill and of the provider's contractual undertaking, as the Avici case shows, and not a matter of supervisory law.

Custodied account or on-chain contract: the two models at a glance
Under the first model you top up a card, your crypto is sold either at top-up or at payment, and what sits on the card is electronic money at a licensed issuer. The provider keeps an account for you, the supervisor watches over the separation of customer funds, and in a dispute you have a named contractual partner holding authorisation.
Under the second model you transfer crypto into a contract that serves as collateral or as the balance for the card. The appeal lies in keeping control for longer and not having to sell assets in order to be able to pay. The price lies in the security of that contract becoming your risk, regardless of how well you look after your own keys.
Hybrid forms exist. Some providers hold the balance in fiat at an institution and additionally let you post crypto as collateral. Others convert only at the moment of payment. Which variant applies is stated in the terms, and reading those repays the effort more than the product description on the home page.
Crypto Wallets ComparedTax when paying by crypto card: why every payment can be a disposal
Regardless of the custody model, paying with crypto in Germany has a tax dimension that many discover only at the tax return. If crypto is exchanged into euros at the card payment or at top-up, that is a disposal in the sense of private assets. Whether a taxable gain results depends on the holding period, the acquisition costs and the exemption threshold.
In practice that means a card converting a small amount at every purchase generates many individual events that want documenting. Anyone not recording them continuously faces a reconstruction from bank statements and blockchain data at the end of the year. Models in which you pay against posted collateral instead of selling behave differently for tax purposes; here an assessment of the individual case repays the effort, because it turns on the specific contractual arrangement.
Checked in ten minutes: how to find out which model your card uses
You answer the following questions for your own card from the provider's documents rather than from memory.
First: who issues the card? The terms name an institution with a registered office and an authorisation. If an EEA e-money institution is named there, that points to the first model. If an infrastructure provider without any stated authorisation is named, read on.
Second: what happens when you top up? If your crypto is converted into euros or dollars and carried as a balance, e-money is involved. If it stays as crypto and is described as collateral, you are working with an on-chain contract.
Third: do the terms name a contract with an address? Providers of the second model give the contract address or a vault. That is a reliable identifying mark.
Fourth: how is reimbursement handled when things go wrong? Search the terms for the words liability, reimbursement and exclusion. A provider expressly excluding losses from faults in smart contracts is telling you where your risk lies.
Fifth: how much is on the card at all? A card balance is cash in your jacket pocket and not a portfolio. Loading only the next few weeks' needs limits the possible damage to an amount you can absorb.
If this check brings you up against approvals and signatures you are asked to confirm, read carefully first what you are approving. How to recognise an abusive approval is set out at length in our guide to wallet drainers and signature approvals.
Crypto cards and card balances: what to take away
The August 28 incident does not concern you directly as a German card user, because the two programmes named are not available here. The construction that made the damage possible in the first place, however, is also found in cards you can obtain in this country. Three steps take you further:
- Determine your card model. Take your card's terms and answer the five questions from the previous section. If you find in the process that the card does not suit the way you use it, the alternatives are in the overview of crypto credit cards.
- Separate balance from custody. Hold on the card only what you will spend in the coming weeks, and leave the rest where you control the keys. Which wallet is suited to that is shown by the comparison of software wallets.
- Record payments for tax as you go. Capture top-ups and conversions continuously rather than once a year. Which tools handle that automatically is set out in the overview of crypto tax tools and portfolio trackers.
(As of August 30, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- USDT cashback and 7 percent on stablecoins: what the MiCA interest ban means for you
- SoFi Settles Card Payments in Stablecoin: What Cardholders Should Check
- Bitget Withdrawals Resume on September 28: What to Check on a Residual Balance Now
- Deutsche Bank to Custody Bitcoin and Ether: Why Retail Clients Are Missing and What to Check in Your Own Custody
- Wallet App Without BaFin Authorisation: When Holding Crypto-Assets Requires a Licence
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 29, 2026 7:12 PM

MEXC Refunds $340,000: The Attacker's API Key Survived the Account Freeze
During an account takeover at MEXC, an attacker created an API key with withdrawal rights that the exchange did not revoke when it restored the account. Twenty-seven minutes after the withdrawal freeze expired, roughly $340,000 was gone.
August 15, 2026 9:31 PM

Crypto Exchange Shutting Down: What to Do Before the Deadline Passes
Binance, BitMart, Luno and Revolut have ended or cut back their European business within seven weeks. This guide shows which deadline expires first, how a forced sale is treated for tax, and what to secure before the account closes.
September 29, 2026 10:14 AM

387.5 million dollars at Bitget: the attack ran through a bought-in security product, what to watch now
Bitget has disclosed how the attackers reached its withdrawal systems on September 24: through a previously unknown flaw in a security product it had bought in. The second stage of the withdrawal schedule opens today at 08:00 UTC, and for the balance you keep on any exchange the case changes the arithmetic.
August 19, 2026 4:15 PM

Tether Audit by KPMG: What the Unqualified Opinion Means for USDT in the EU
Tether reported the first full audit of its financial statements by KPMG on August 13, 2026, with an unqualified audit opinion for the 2025 financial year. That changes nothing about whether USDT can be traded at authorised providers in the EU, because Article 48 MiCA decides that question.
October 2, 2026 4:32 AM

NEAR Intents halts withdrawals after a $3.8 million exploit: here are the reasons
NEAR Intents confirms an exploit of more than $3.8 million and holds deposits and withdrawals on eleven networks. Reimbursement is promised, a date for it is not.
September 26, 2026 7:14 AM

Cardano Before the RealFi Launch on October 1: What ADA Holders Should Check on USDr, MiCA and Tax
On October 1, 2026 the stablecoin platform RealFi goes live on the Cardano mainnet, and ADA has gained 14.67 percent in a week. What is documented about the yield-bearing dollar token USDr, and what investors should settle beforehand.
September 4, 2026 10:17 AM

Cypher Shutdown on September 6: What Users Should Know Now the Withdrawal Deadline Has Passed
Recap as of September 27, 2026: Cypher had announced it would take its app, dApp and withdrawal window offline on September 6, 2026 and end the token protocol. This article describes the situation before the deadline, how the payout worked and what our own measurement showed at the time about what was left of the CYPR token.
August 19, 2026 7:27 AM

Blockchain Rollback After an Exploit: What Happens to Your Tokens When a Chain Is Reset
At Harmony, roughly four billion ONE were minted without authorisation, and a rollback of the chain has been on the table ever since. This piece explains what a blockchain rollback means technically, when it can still succeed, and what it triggers for your holding period.
August 21, 2026 4:17 PM

Crypto Withdrawals to Your Own Wallet: Why Exchanges Demand Proof of Address Ownership Above €1,000
Above €1,000 your provider has to establish whether the destination address really belongs to you. Article 14(5) of the transfer of funds regulation, five permitted methods, and the reason a withdrawal stalls without this step.
September 22, 2026 10:15 PM

Stablecoin Reserves: Why the ECB Wants the Bank Deposit Rule Scrapped
The European System of Central Banks filed its response to the MiCA review on September 22 and calls in it for an end to the requirement to hold 30 to 60 percent of stablecoin reserves as a bank deposit. What lies behind it, and what you can check on your own token.
August 6, 2026 6:01 PM

X Is Building a Bank Without Crypto — and Now Its Product Chief Is Leaving
Nikita Bier is stepping down as X's head of product. His exit lands in the weeks X Money launched in the US — with Visa and 6 percent yield, but not a single crypto capability.
September 23, 2026 10:11 AM

Kraken: 45 coins are on cancel only, 21 were announced – what to check when trading pairs are blocked
On September 23, 2026 we counted the public market directories of three trading venues. At Kraken, 82 of 1,450 trading pairs are listed as cancel only, a state in which an order can only be cancelled and no longer executed. The 45 underlying assets affected include just 21 that appear in the delisting notice we reported on September 3.
August 19, 2026 7:17 PM

MiCA Register of Stablecoin Issuers: 23 Authorised Firms, 43 White Papers and Two Dead Links
The official ESMA register lists 23 authorised issuers of e-money tokens and 43 notified white papers. We called up every document address stored there ourselves and show where the record leads nowhere.
October 1, 2026 2:16 PM

Open USD is live but absent from the EU register: what matters now for investors in Europe
The dollar stablecoin Open USD launched on September 30, 2026, backed by Coinbase, Mastercard, Shopify, Stripe and Visa. On October 1, 2026 the token was not notified in the MiCA register, and that decides what you can do with it in Europe.
September 30, 2026 4:15 PM

Zcash today: 2,746 ZEC from the Bitget hack vanish into the Ironwood pool
Wallets from the Bitget break-in pushed 2,746 ZEC into Zcash's Ironwood pool on Wednesday morning, roughly $3.9 million. What the shielding means for tracing, and what applies to your exchange account from July 2027.
September 29, 2026 10:28 PM

Customers Pull $463 Million From Bitget: The Consequences for Reserves and Custody
After the attack of September 24, customers pulled around $463 million out of Bitget within a day, the largest single-day outflow since DefiLlama began tracking reserves. The user protection fund fell from $464 million to below $200 million in the process.
September 27, 2026 4:32 AM

Hester Peirce Leaves the SEC: What Now Applies to Your Custody in Germany
The most crypto-friendly voice at the US securities regulator goes on October 2, 2026, and the commission shrinks to two members. For investors in Germany it is still the European rulebook that decides, and there a deadline falls in July 2027.
September 26, 2026 4:11 AM

Shielded Bitcoin: what the privacy proposal means for your Bitcoin addresses
Three researchers published a draft for encrypted Bitcoin transfers without a soft fork on September 24, 2026. What Shielded Bitcoin hides, what stays public and which points you can check on your own wallet today.
September 25, 2026 10:22 AM

Fed Rules for Stablecoins: What to Check on Backing and the Redemption Right
The Federal Reserve put forward two proposed rules on backing, capital and redemption of payment stablecoins on September 24, 2026. For your holdings in Germany, however, MiCA is what counts, and different checks follow from it.
September 17, 2026 4:14 PM

D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?
September 7, 2026 7:26 PM

Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Compromised private keys overtook smart contract code flaws as the most common attack route for the first time in 2026. What sits behind the shift, and how to check your own setup for its single point of failure.
September 4, 2026 10:26 PM

Pocket Bitcoin Data Breach: When Name, Home Address and Bitcoin Address Circulate Together
The Swiss Bitcoin service Pocket Bitcoin closed its investigation on September 3, 2026: 5,411 people affected, and for 291 of them the Bitcoin addresses they used along with copies of identity documents. Why this one data pairing has lasting effect, and what you should check with your own provider.
September 4, 2026 10:15 PM

Trezor Data Breach: Am I Affected and What Should I Do Now?
Trezor widened the ShipMonk data breach on September 4, 2026: around 67,000 further people affected, just over 80,000 in total, from orders placed between November 2019 and August 2021. How to check in two minutes whether you are among them, and what an exposed home address means for self-custody.
September 3, 2026 4:41 AM

Kraken Delists 21 Tokens: Trading End on September 11 Has Passed, Withdrawals Run Until December 10
As of September 27, 2026: Kraken had set the end of trading and deposits for 21 cryptocurrencies for September 11, 2026 at 14:00 UTC, and that date has passed. According to the exchange, withdrawals remain possible until December 10, 2026 at 15:00 UTC. Our September 3 survey showed that none of these tokens could be deposited at Bitvavo, Coinbase or Bitstamp.
August 27, 2026 1:12 AM

Revolut Launches the EURR Euro Stablecoin: Why Germany Is Not in the First Wave
Revolut launched the EURR euro stablecoin on August 26, 2026, starting in Denmark, Poland and Portugal. For German customers a different date matters for now: the USDT deadline ends on August 31.
August 23, 2026 4:25 AM

Crypto Exchange Closure: What Happens to Your Residual Balance and When the Fee Starts
When a crypto exchange stops operating, trading ends on a set date but the account does not. Anyone leaving a residual balance behind now pays a monthly fee at the wind-downs currently under way.
August 20, 2026 4:20 AM

Crypto Exchange Delisting: What Happens to Your Tokens When Trading and Withdrawals Close
A delisting runs in four stages, and only one of them is genuinely dangerous: the end of the withdrawal deadline. Using two live OKX dates as the example, we show what happens at each stage and how to tell whether it affects you.
More from CryptoTicker
