Crypto Cards: Where Your Card Balance Really Sits and What the August 28 Solana Exploit Reveals About It
An attack on a card balance contract on Solana took the loaded balance from 1,685 users while their wallets stayed untouched. The case shows why it matters whether your crypto card holds funds as e-money at a licensed institution or in a smart contract.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
When you pay with a crypto card, the money backing that card frequently does not sit in your own wallet. It sits in a separate container operated by the card platform and filled by you when you top up. On August 28, 2026 an attack on exactly such a container showed what that means when things go wrong: users' self-custodied wallets were left untouched, and the loaded card balance was gone.
The provider concerned is not available in Germany. The construction behind it, however, is. This piece places the incident in context, explains the terms and shows you how to tell which custody model your own card uses and who would be responsible in the event of a loss.
What happened in Avici's Solana card contract on August 28, 2026
Avici is a so-called neobank on the Solana blockchain: an app that attaches a Visa card to an on-chain account of its own. On August 28, 2026 the provider disclosed that there was a problem with card payouts. According to the reconstruction by crypto.news, the first malicious transaction occurred at 16:49:48 UTC, and reporting began in the early evening.
On the provider's account, what was affected was neither the Solana network nor the users' app wallet, but a single smart contract in which the backing for the cards is held. Anyone who left their funds in the app without loading them onto the card stood outside the attack. Anyone who had topped up stood inside it.
How the attack worked technically
On the account given by Cryptopolitan, the attacker exploited the payout logic of the program written in Rust by calling the functions SubmitSignatures, AddCollateralAdmin and WithdrawCollateralAsset one after another. The middle step is the decisive one: with it the attacker entered himself as an authorised administrator of the collateral and could then withdraw what had been deposited through the regular route.
The episode was not a single grab. According to the breakdown Avici published later, the attack series comprised 14,672 transactions, of which 2,344 failed. That points to an automated script working through the contract systematically over hours rather than to a one-off strike.
Card balance contract: what it is and why it is not your wallet
A card balance contract is a standalone program on a blockchain into which you transfer funds so that a payment card can draw on them. As soon as you top up, the money leaves your wallet and sits in that contract until a card payment is settled or you pull it back.
The difference from a wallet is practical rather than theoretical. Your wallet is protected by a key only you hold. The card contract has an access logic of its own, usually with roles for the operator so that settlement works at all. Whoever defeats that role management reaches the balances of every user without knowing a single private key.
That is exactly what happened at Avici. The app's self-custodied Solana and EVM wallets were left untouched according to the provider. What was attacked was solely the separate contract into which users had transferred funds for the card. The widespread notion that a self-custodial product is automatically self-custodial as a whole does not hold at this point.
How large the damage was: why $500,000 and $1.07 million can both be right
Two orders of magnitude are circulating about the scale, and both rest on a traceable basis. On the day of the incident crypto.news counted an outflow of 10,005.03 SOL plus around $11,600 in USDC and USDT, together roughly $1.07 million at the price of the time. Avici itself named 1,685 affected users and $500,859.22 in card balances after its internal reconciliation.
The range of roughly $0.5 million to $1.07 million resolves once you look at the reference quantity. The higher figure measures what flowed out of the contract in assets. The lower one measures how much of that could be assigned to individual customer accounts as card balance. Both figures come from different ways of counting, and neither is the "correct" one in the sense of the other.
For you as a reader the lesson matters more than the exact sum: in the first hours of an incident like this, on-chain estimates and the provider's later reconciliation stand side by side, and they rarely coincide. Anyone making decisions in that phase should know which of the two figures they are looking at.

Rain as card issuer: the role the infrastructure in the background plays
The name on the card is the app's. Issuing and technical operation are as a rule handled by a specialised card issuer in the background. At Avici that is the firm Rain, which supplies card programmes for companies and maintains contracts of its own on several blockchains for the purpose.
According to the companies involved, Rain located the fault itself and traced it to an outdated version of its Solana contracts, used besides Avici by a small number of other programmes. The company says all deployments still running on that version were subsequently updated and external forensic specialists brought in. Which other programmes were affected, and whether damage arose there, has not been named publicly.
Avici has undertaken to reimburse all affected card balances in full and says it has filed a report with the FBI's Internet Crime Complaint Center. Whether and when reimbursements have actually been made cannot be verified from outside; the undertaking is an announcement by the company rather than an accomplished fact.
Crypto Credit Cards at a GlanceWhy Jupiter halted card payouts as a precaution
On the same day the card programme of the Solana trading platform Jupiter also briefly paused payouts of card balances. The platform explained this as a precautionary measure while its card partner completed security checks of its own, and stated that its own users' accounts and funds had at no point been affected. Payouts then resumed as normal.
This episode is more instructive than it first appears. The brief halt shows that a fault in a shared contract version reaches several card programmes at once, including ones from which nothing ultimately flows out. The card in your hand can come from a provider whose software you never chose.
What a precautionary payout halt means for you
Such a halt amounts in effect to a temporary block on your card balance. The money is not lost, but it is unavailable for the duration of the check. Anyone parking a whole month's spending on a crypto card notices the difference from a current account in exactly this situation.
Which crypto cards use this model and where Rain issues at all
For German readers the availability question is the first filter, and it comes out clearly for the two programmes named. Avici's documentation lists 47 territories in which the card can be used, among them countries in Latin America, Africa and Asia and individual US states. Europe, the European Economic Area and Germany appear in neither the permitted nor the prohibited list. The Jupiter card, issued by Rain or by DCS depending on country of residence, likewise does not list the EEA among its supported regions.
The model itself is nevertheless available in Germany. The card from ether.fi, for instance, is also issued through Rain, holds the balance in a smart contract vault controlled by the user, and settles on the Ethereum layer 2 Scroll. The provider's help page lists twenty unsupported countries, among them Estonia, Finland, the Netherlands and Hungary; Germany is not on it. Because this programme does not settle on Solana, it falls outside the contract version at issue in the Avici case.
Anyone looking around this product group finds cards with quite different mechanics side by side. Which models exist and how fees and cashback differ is set out in the overview of crypto credit cards. The custody question is only one of several there, but it is the one that decides responsibility when something goes wrong.
MiCA and the e-money licence: which rules apply to a card balance in Europe
In the EU a payment card with a loaded balance is normally an e-money product. The issuer needs authorisation as an e-money institution for it, must separate customer funds from its own assets and hold them at a bank or in safe investments. Where crypto enters the picture, authorisation as a crypto-asset service provider has been added since the MiCA transition period ended on July 1, 2026.
The difference from deposit protection matters: segregated custody means that customer funds do not fall into the estate if the provider becomes insolvent. It does not mean that a state guarantee scheme steps in for losses, as it does for bank deposits up to 100,000 euros. Advertising for payment cards regularly conflates the two.
If your card balance sits in an on-chain contract instead, this framework does not apply in that form. There is then no custodied customer money at an institution, but assets in a program whose security depends on the code and on its role management. Reimbursement in that case is a matter of goodwill and of the provider's contractual undertaking, as the Avici case shows, and not a matter of supervisory law.

Custodied account or on-chain contract: the two models at a glance
Under the first model you top up a card, your crypto is sold either at top-up or at payment, and what sits on the card is electronic money at a licensed issuer. The provider keeps an account for you, the supervisor watches over the separation of customer funds, and in a dispute you have a named contractual partner holding authorisation.
Under the second model you transfer crypto into a contract that serves as collateral or as the balance for the card. The appeal lies in keeping control for longer and not having to sell assets in order to be able to pay. The price lies in the security of that contract becoming your risk, regardless of how well you look after your own keys.
Hybrid forms exist. Some providers hold the balance in fiat at an institution and additionally let you post crypto as collateral. Others convert only at the moment of payment. Which variant applies is stated in the terms, and reading those repays the effort more than the product description on the home page.
Crypto Wallets ComparedTax when paying by crypto card: why every payment can be a disposal
Regardless of the custody model, paying with crypto in Germany has a tax dimension that many discover only at the tax return. If crypto is exchanged into euros at the card payment or at top-up, that is a disposal in the sense of private assets. Whether a taxable gain results depends on the holding period, the acquisition costs and the exemption threshold.
In practice that means a card converting a small amount at every purchase generates many individual events that want documenting. Anyone not recording them continuously faces a reconstruction from bank statements and blockchain data at the end of the year. Models in which you pay against posted collateral instead of selling behave differently for tax purposes; here an assessment of the individual case repays the effort, because it turns on the specific contractual arrangement.
Checked in ten minutes: how to find out which model your card uses
You answer the following questions for your own card from the provider's documents rather than from memory.
First: who issues the card? The terms name an institution with a registered office and an authorisation. If an EEA e-money institution is named there, that points to the first model. If an infrastructure provider without any stated authorisation is named, read on.
Second: what happens when you top up? If your crypto is converted into euros or dollars and carried as a balance, e-money is involved. If it stays as crypto and is described as collateral, you are working with an on-chain contract.
Third: do the terms name a contract with an address? Providers of the second model give the contract address or a vault. That is a reliable identifying mark.
Fourth: how is reimbursement handled when things go wrong? Search the terms for the words liability, reimbursement and exclusion. A provider expressly excluding losses from faults in smart contracts is telling you where your risk lies.
Fifth: how much is on the card at all? A card balance is cash in your jacket pocket and not a portfolio. Loading only the next few weeks' needs limits the possible damage to an amount you can absorb.
If this check brings you up against approvals and signatures you are asked to confirm, read carefully first what you are approving. How to recognise an abusive approval is set out at length in our guide to wallet drainers and signature approvals.
Crypto cards and card balances: what to take away
The August 28 incident does not concern you directly as a German card user, because the two programmes named are not available here. The construction that made the damage possible in the first place, however, is also found in cards you can obtain in this country. Three steps take you further:
- Determine your card model. Take your card's terms and answer the five questions from the previous section. If you find in the process that the card does not suit the way you use it, the alternatives are in the overview of crypto credit cards.
- Separate balance from custody. Hold on the card only what you will spend in the coming weeks, and leave the rest where you control the keys. Which wallet is suited to that is shown by the comparison of software wallets.
- Record payments for tax as you go. Capture top-ups and conversions continuously rather than once a year. Which tools handle that automatically is set out in the overview of crypto tax tools and portfolio trackers.
(As of August 30, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Section: All crypto hacks and scams at a glance
More on Solana: All Solana news at a glance
Related articles
- USDT cashback and 7 percent on stablecoins: what the MiCA interest ban means for you
- SoFi Settles Card Payments in Stablecoin: What Cardholders Should Check
- Bitget Withdrawals Resume on September 28: What to Check on a Residual Balance Now
- Deutsche Bank to Custody Bitcoin and Ether: Why Retail Clients Are Missing and What to Check in Your Own Custody
- Wallet App Without BaFin Authorisation: When Holding Crypto-Assets Requires a Licence
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 29, 2026 7:12 PM

MEXC Refunds $340,000: The Attacker's API Key Survived the Account Freeze
During an account takeover at MEXC, an attacker created an API key with withdrawal rights that the exchange did not revoke when it restored the account. Twenty-seven minutes after the withdrawal freeze expired, roughly $340,000 was gone.
August 15, 2026 9:31 PM

Crypto Exchange Shutting Down: What to Do Before the Deadline Passes
Binance, BitMart, Luno and Revolut have ended or cut back their European business within seven weeks. This guide shows which deadline expires first, how a forced sale is treated for tax, and what to secure before the account closes.
September 29, 2026 10:14 AM

387.5 million dollars at Bitget: the attack ran through a bought-in security product, what to watch now
Bitget has disclosed how the attackers reached its withdrawal systems on September 24: through a previously unknown flaw in a security product it had bought in. The second stage of the withdrawal schedule opens today at 08:00 UTC, and for the balance you keep on any exchange the case changes the arithmetic.
August 19, 2026 4:15 PM

Tether Audit by KPMG: What the Unqualified Opinion Means for USDT in the EU
Tether reported the first full audit of its financial statements by KPMG on August 13, 2026, with an unqualified audit opinion for the 2025 financial year. That changes nothing about whether USDT can be traded at authorised providers in the EU, because Article 48 MiCA decides that question.
October 11, 2026 1:24 AM

Three Mistakes When Setting Up Trust Wallet: The Twelve Words Never Belong on the Phone
Trust Wallet is set up in five minutes, yet three mistakes in those minutes regularly cost the entire balance. This guide covers the six steps, the real cost of a swap, and what applies in Germany on the holding period and supervision.
October 6, 2026 10:32 AM

FinCEN drops the reporting duty for withdrawals to private wallets: what matters now for European investors
The US anti-money-laundering agency FinCEN withdrew two proposals on October 5, 2026 covering the reporting duty for self-custodied wallets and for mixers. In the EU the development runs in exactly the opposite direction: proof of ownership from 1,000 euros today, a ban on anonymous accounts from July 2027.
October 2, 2026 4:32 AM

NEAR Intents halts withdrawals after a $3.8 million exploit: here are the reasons
NEAR Intents confirms an exploit of more than $3.8 million and holds deposits and withdrawals on eleven networks. Reimbursement is promised, a date for it is not.
September 26, 2026 7:14 AM

Cardano Before the RealFi Launch on October 1: What ADA Holders Should Check on USDr, MiCA and Tax
On October 1, 2026 the stablecoin platform RealFi goes live on the Cardano mainnet, and ADA has gained 14.67 percent in a week. What is documented about the yield-bearing dollar token USDr, and what investors should settle beforehand.
September 4, 2026 10:17 AM

Cypher Shutdown on September 6: What Users Should Know Now the Withdrawal Deadline Has Passed
Recap as of September 27, 2026: Cypher had announced it would take its app, dApp and withdrawal window offline on September 6, 2026 and end the token protocol. This article describes the situation before the deadline, how the payout worked and what our own measurement showed at the time about what was left of the CYPR token.
August 19, 2026 7:27 AM

Blockchain Rollback After an Exploit: What Happens to Your Tokens When a Chain Is Reset
At Harmony, roughly four billion ONE were minted without authorisation, and a rollback of the chain has been on the table ever since. This piece explains what a blockchain rollback means technically, when it can still succeed, and what it triggers for your holding period.
October 8, 2026 7:30 AM

Guilty Verdict over a $53.3 Million DeFi Exploit: What Investors in Germany Need to Know
A Manhattan jury has treated the exploitation of a smart contract flaw as computer fraud, throwing out the “Code is Law” defence after a little over two hours. For holders in Germany, what counts above all is that MiCA does not cover decentralised pools and that nobody is liable when something goes wrong.
August 21, 2026 4:17 PM

Crypto Withdrawals to Your Own Wallet: Why Exchanges Demand Proof of Address Ownership Above €1,000
Above €1,000 your provider has to establish whether the destination address really belongs to you. Article 14(5) of the transfer of funds regulation, five permitted methods, and the reason a withdrawal stalls without this step.
September 22, 2026 10:15 PM

Stablecoin Reserves: Why the ECB Wants the Bank Deposit Rule Scrapped
The European System of Central Banks filed its response to the MiCA review on September 22 and calls in it for an end to the requirement to hold 30 to 60 percent of stablecoin reserves as a bank deposit. What lies behind it, and what you can check on your own token.
August 6, 2026 6:01 PM

X Is Building a Bank Without Crypto — and Now Its Product Chief Is Leaving
Nikita Bier is stepping down as X's head of product. His exit lands in the weeks X Money launched in the US — with Visa and 6 percent yield, but not a single crypto capability.
October 9, 2026 7:29 AM

Exodus Wallet: 71.5 percent of revenue comes from swaps, the spread vs the exchange fee
The Exodus Wallet is free to download, yet 71.5 percent of the provider's revenue in the second quarter of 2026 came from swaps inside the app. What the spread costs, how custody works and from what point a device of your own pays off.
September 23, 2026 10:11 AM

Kraken: 45 coins are on cancel only, 21 were announced – what to check when trading pairs are blocked
On September 23, 2026 we counted the public market directories of three trading venues. At Kraken, 82 of 1,450 trading pairs are listed as cancel only, a state in which an order can only be cancelled and no longer executed. The 45 underlying assets affected include just 21 that appear in the delisting notice we reported on September 3.
October 8, 2026 10:14 PM

ESMA stablecoin deadline of January 8, 2027: what you can do with USDT now
ESMA decided on October 8, 2026 that authorised EU platforms should no longer offer services for stablecoins that do not comply with MiCA. For USDT, only selling, swapping, transferring and withdrawing remain until January 8, 2027.
August 19, 2026 7:17 PM

MiCA Register of Stablecoin Issuers: 23 Authorised Firms, 43 White Papers and Two Dead Links
The official ESMA register lists 23 authorised issuers of e-money tokens and 43 notified white papers. We called up every document address stored there ourselves and show where the record leads nowhere.
October 9, 2026 7:35 AM

Polkadot launches dotUSD without an issuer: why MiCA demands one
Polkadot launched its own stablecoin dotUSD on the mainnet on October 8, 2026, with no issuer and steered by DOT holders. On the same day ESMA requires regulated service providers to wind down non-MiCA-compliant stablecoins within three months.
October 1, 2026 2:16 PM

Open USD is live but absent from the EU register: what matters now for investors in Europe
The dollar stablecoin Open USD launched on September 30, 2026, backed by Coinbase, Mastercard, Shopify, Stripe and Visa. On October 1, 2026 the token was not notified in the MiCA register, and that decides what you can do with it in Europe.
September 30, 2026 4:15 PM

Zcash today: 2,746 ZEC from the Bitget hack vanish into the Ironwood pool
Wallets from the Bitget break-in pushed 2,746 ZEC into Zcash's Ironwood pool on Wednesday morning, roughly $3.9 million. What the shielding means for tracing, and what applies to your exchange account from July 2027.
September 29, 2026 10:28 PM

Customers Pull $463 Million From Bitget: The Consequences for Reserves and Custody
After the attack of September 24, customers pulled around $463 million out of Bitget within a day, the largest single-day outflow since DefiLlama began tracking reserves. The user protection fund fell from $464 million to below $200 million in the process.
September 27, 2026 4:32 AM

Hester Peirce Leaves the SEC: What Now Applies to Your Custody in Germany
The most crypto-friendly voice at the US securities regulator goes on October 2, 2026, and the commission shrinks to two members. For investors in Germany it is still the European rulebook that decides, and there a deadline falls in July 2027.
September 26, 2026 4:11 AM

Shielded Bitcoin: what the privacy proposal means for your Bitcoin addresses
Three researchers published a draft for encrypted Bitcoin transfers without a soft fork on September 24, 2026. What Shielded Bitcoin hides, what stays public and which points you can check on your own wallet today.
September 25, 2026 10:22 AM

Fed Rules for Stablecoins: What to Check on Backing and the Redemption Right
The Federal Reserve put forward two proposed rules on backing, capital and redemption of payment stablecoins on September 24, 2026. For your holdings in Germany, however, MiCA is what counts, and different checks follow from it.
September 17, 2026 4:14 PM

D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?
September 7, 2026 7:26 PM

Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Compromised private keys overtook smart contract code flaws as the most common attack route for the first time in 2026. What sits behind the shift, and how to check your own setup for its single point of failure.
More from CryptoTicker
