Crypto Cards 2026: Who Holds the Money Before the Swipe

Nick Sawinyh on 10 Sep 2026

At 16:49:48 UTC on Friday, August 28, 2026, a Solana wallet funded three hours earlier with 1.79 SOL, bought with about $190 of USDC bridged from Ethereum, began emptying card-balance accounts belonging to users of Avici, a Solana neobank. Avici’s card terms, last updated June 23, 2025, say that “Avici and Issuer will not, in any circumstance, be holding custody of your Collateral.” That sentence was true in the sense the lawyers meant it. It did not stop the drain. By Avici’s own reconciliation, posted at 20:44 UTC, 1,685 users lost $500,859.22 from a “Solana card contract used by Avici and a small number of other programs.” The contract belonged to Rain, the card-issuing company behind Avici and most of the self-custodial card market. Avici says Rain covered every refund, and Avici and Tria, the second program hit, each added 10% on top.

Nobody’s keys were stolen. Nobody’s wallet was touched. The money that went missing was sitting in the one place a “non-custodial” card has to put it: a contract the user funds, the program manager wrote, and the program manager could upgrade with a single plain signing key.

Our 2025 guide to non-custodial cards covered the first Safe-based designs. Since the spring, the volume has nearly doubled, two cards have been drained, one large issuer has collapsed, an electronic money institution has lost its licence, and the loudest fight in the category was over a paragraph in a terms-of-service document. This piece starts from the paragraph. We read the terms and cardholder agreements of 18 programs, pulled Paymentscan’s full dataset, and worked through two X threads that made the rounds this summer: @OG_Branxi’s price list of no-KYC cards and @0xSammy’s note that “if a team is using a nuanced loophole to circumvent client account regulations then that’s a huge red flag.”

Everything below reflects documents and dashboards as read on September 10, 2026. Terms change: KAST rewrote its custody clause on July 7 and Ether.fi’s terms carry a September 9 modification date.

Crypto Card Volume in 2026: $1.1 Billion a Month, and What Is Inside It

Monthly crypto card volume tracked by Paymentscan from December 2024 to August 2026, rising from $153M to $1.116B, with RedotPay's self-reported spend and Rain-issued program settlement shown as stacked segments from February 2026. Source: paymentscan.xyz, read 2026-09-10.

Paymentscan put August 2026 crypto card volume at $1.116 billion across 11.0 million transactions and 287,640 active addresses, the second month above a billion after July’s $1.038 billion. Cumulative volume since March 2023 stands at $11.61 billion.

Anyone comparing those numbers with figures published in the spring needs two caveats. First, the series has been restated. In April, Paymentscan’s March 2026 figure was $607 million; the same month now reads $735.3 million, because the tracker since added ten programs and unattributed issuer flow, and swapped RedotPay’s onchain top-ups for RedotPay’s own spend figure. Rebuilt on April’s basis, growth from March to August is about 32%, against 48% on the headline series. Second, the biggest bar in the chart is a number the tracker cannot see. Paymentscan’s RedotPay page states that “spend metrics are self-reported by the RedotPay team, while top-ups are tracked onchain,” and RedotPay’s August spend of $403.6 million is 36% of the headline. KAST and Karta have no spend feed at all; Paymentscan proxies them with their settlement batches to Rain.

The strictest number available is spend observed on chain, which excludes RedotPay’s reported figure: about $545 million in August, up 55% since March. Ether.fi Cash is the largest program whose every purchase is visible on chain, at $109.5 million in August across 1.45 million transactions and 45,096 active addresses, and Ether.fi says the card passed 10 million transactions on August 31.

The number that organizes the rest of this piece is the orange segment. Paymentscan’s issuer view attributes $468 million of August’s $1.116 billion, about 42%, to programs settling through Rain. Add RedotPay and two companies carry roughly 78% of tracked crypto card volume.

Crypto Card Custody Models: Five Places Your Money Can Be

Every crypto card asks you to move value into something before you can spend it. The terms of the 18 programs we read describe five different somethings. The order below runs from the weakest claim a user holds to the strongest.

1. Sold to the Operator: KAST’s Terms of Service

This is the KAST model, and it is the paragraph the summer’s argument was about. It has existed in three versions.

KAST’s terms dated July 23, 2025, archived in the Wayback Machine, described ordinary third-party custody: “The Virtual Assets deposited in our Platform, will be held in our Partner Custodian Wallet solution. You recognize that the Company will manage the Custodian Wallet on your behalf,” with assets in “a separate, centralized omnibus account (‘Pooled Account’), distinct from the Company’s own accounts.”

The revision dated December 1, 2025 replaced that section with a sale:

“When a user transfers Virtual Assets (such as cryptocurrencies or stablecoins) into KAST, the transfer is treated as a sale of the Virtual Asset to KAST. For clarity, once a user sells their Virtual Assets to KAST, the user no longer retains any ownership interest in those Virtual Assets. Ownership of the Virtual Assets transfers to KAST, and the assets are thereafter managed at the KAST corporate treasury level. […] The KAST app records a USD-denominated ledger entry calculated at the prevailing market rate at the time of sale, which serves as a transactional reference for subsequent card spending and does not constitute an account balance, deposit, or stored monetary value.”

That is the screenshot Ether.fi’s CEO Mike Silagadze posted on July 6 under the caption “Kasthole scammer,” the day after a side-by-side purchase test by @0xVishnya had put KAST last of five cards on the same grocery run and KAST’s CEO had needled Ether.fi about its token price. Silagadze’s follow-up made the claim that matters: “if Kast goes bankrupt then account holders are in line with other creditors and behind senior debt. […] Correct me if I’m wrong and I’ll take this down.” We are not aware that he has taken it down.

KAST amended the terms on July 7, the next day. The sale framing survives verbatim in the live document: “any remittance of Virtual Assets to KAST constitutes a transfer of ownership of such assets to KAST, in exchange for which KAST incurs a legally binding and enforceable payment obligation to you,” and the ledger entry “represents a defined, enforceable debt claim against KAST and does not constitute an account balance, a deposit, or stored fiat monetary value.” What was added is a redemption right: “you retain an affirmative right to redeem or withdraw the unspent balance of the resulting payment obligation at any time, subject to our standard withdrawal procedures, compliance and fraud checks, minimum limits, and applicable fees.” The custodian, the terms say, holds “on behalf of KAST (not for the users).” The only custodian named in the document is BitGo. The Defiant reported KAST CEO Raagulan Pathy’s response that funds are held with BitGo and Fireblocks, that customers hold a binding payment obligation, and that the terms were updated “to make this very clear.”

The rest of the document is consistent with a debt claim and nothing more. The contracting entity is “KAST Tech, Reg No. 16223, incorporated in Anjouan, Comoros.” Total liability “shall be limited to maximum USD 500.” A “Partner Disclaimer” states that KAST’s partners “Do not act as your trustee, an escrow agent or stakeholder” and “Do not have a contractual obligation or duty to keep the funds in the designated Account segregated from the Company other accounts.” And under “Funds”: “In case of failure, bankruptcy or liquidation by us, you won’t be protected by the Consumer Act in your local jurisdiction, thus, there is a risk you won’t recover your money or cryptocurrency paid to us.”

None of this is hidden. It is also not unique. Baanx, the infrastructure company behind the self-custody-marketed MetaMask Card, carries a clause in its generic CL Platform terms under which “possession and ownership of that cryptocurrency passes to Us” for deposits into a Baanx wallet; we could not confirm that document governs the MetaMask Card’s allowance flow, so treat it as a Baanx house term rather than a MetaMask one. The point is that the sale-to-operator construction is a template in this industry, and KAST is simply the program whose version got read aloud.

The data since the argument cuts both ways. Paymentscan’s onchain count of KAST top-ups fell from $219.6 million in July to $94.4 million in August, while KAST’s settlement batches to Rain rose from $89.6 million to $104.8 million. Top-ups are not spend, and we cannot tell from outside whether users pulled back or KAST changed how deposits route. It is a signal, not a conclusion, and the settlement series hit a record in August after the fight.

2. Held in Custody for You: RedotPay, Revolut and Coinbase

RedotPay, the largest card by volume, is custodial and its terms (last updated July 9, 2026) say so plainly: a “Debit Account” is “the debit account opened by a user with the Custodian, including a cryptocurrency wallet hosted by the Custodian.” The custodian is Red Dot Trust, a RedotPay group company, so this is affiliate custody rather than independent custody. The terms carry a general lien over “any or all of your property which (for any reason) is in or comes into our possession or control,” and a user becoming “Insolvent” is an event of default. No bank or BIN sponsor is named in the general terms; a February 2025 release names StraitsX as the Singapore Visa BIN sponsor.

Revolut’s crypto terms use the cleanest version of this language: “You appoint us as your ’nominee’ for the purpose of holding your cryptoassets. This means we hold the legal title to, and you are the beneficial owner of, the amount of cryptoassets we hold on your behalf.” Coinbase’s US user agreement goes furthest toward the user: “Title to Supported Digital Assets shall at all times remain with you and shall not transfer to Coinbase. […] All interests in Digital Assets we hold for Digital Asset Wallets are held for customers, are not property of Coinbase, and are not subject to claims of Coinbase’s creditors.” Whether a bankruptcy court agrees with that sentence is a question nobody has had to test at Coinbase.

3. Converted to Fiat at a Licensed Issuer: Crypto.com, Krak and Bybit

The exchange cards mostly do not hold crypto on the card at all. Crypto.com’s US cardholder agreement, effective September 1, 2026, states that “No cryptocurrency debits, credits or balances will take place on the CRYPTO.COM Prepaid Visa Card or be held on the Card. Only US Dollars (USD) are held,” with Community Federal Savings Bank as issuer. Kraken’s new US Krak Card, issued by Lead Bank with Stripe as program manager, is more explicit still: “The Account holds only Fiat Currency. The Account and Card do not hold any Digital Assets,” and “Lead Bank is not involved with the movement, custody, purchase, or sale of any Digital Assets.” Your crypto stays in Kraken’s exchange custody until the moment of sale. Bybit’s card terms, dated January 16, 2026, disclaim the fiat leg entirely: “we do not at any time receive, hold, or safeguard any Fiat funds, and all such funds are received, held, and managed by the relevant authorised payment service provider.”

In the EU and UK this is the e-money regime, and it is the only bucket with a statutory answer to the insolvency question. Directive 2009/110/EC requires issuers to safeguard “funds that have been received in exchange for electronic money that has been issued,” and the referenced Payment Services Directive rule says those funds “shall not be commingled at any time with the funds of any natural or legal person other than payment service users” and “shall be insulated […] against the claims of other creditors of the payment institution, in particular in the event of insolvency.” The UK’s Electronic Money Regulations 2011 mirror this. Monavate, the Lithuanian and UK EMI that issues Gnosis Pay’s and MetaMask’s European cards, puts it in its footer: “safeguarded funds should not be available to Monavate’s creditors and are intended to be returned to customers, subject to the insolvency process.” Crypto.com’s EU document is blunter about the residual risk: “In the unlikely event that the Issuer becomes insolvent, your funds may become valueless and unusable.”

Safeguarding is a real protection, and it covers exactly one thing: fiat that has been issued as e-money. It does not cover the crypto you hold before conversion, and, as the next two buckets show, it does not cover value in a smart contract either.

4. Your Own Contract in the Card Program’s Pool: Avici, Tria and Rain

This is where the August 28 money was. Rain, which issues or program-manages most of the self-custodial cards in the market, describes the arrangement on its own site: “In a Rain-Managed setup, we handle the smart contract and daily settlements with your users. A dedicated smart contract is created when a user opens a card, and they fund and manage it from their own wallet. Rain maintains the ongoing ledger and manages settlement with cardholders, while also handling liquidation to settle with Visa.” The alternative, “Partner-Managed,” is for brands that want “maximum control over treasury, collateral types, and customer settlement logic,” and in it the partner “maintain[s] the reserve balance” while “Rain powers the Visa connectivity and handles liquidation to settle with Visa.” The user’s terms do not say which option the brand chose.

Under this design the user’s terms can say, truthfully, that neither the brand nor the issuer holds custody. Avici’s say it. Tria’s card terms say “The Collateral will be owned by you at all times and held in your custody within one or more smart contracts on the Supported Blockchains.” Payy’s cardholder agreement uses the identical sentence, and in the copy we read still contains the placeholder “[Partner Name] Card” and a reference to Rain in its indemnity clause, which tells you these agreements come off one shelf. What the sentence does not say is who wrote the contract, who holds its upgrade authority, and what happens if the authorization logic is wrong.

Solayer’s Emerald card is the sharpest example of the gap between the word and the mechanism. Solayer’s site sells “a crypto-native Visa card that lets you spend stablecoins globally, while staying fully on-chain.” Its own security documentation describes something else: “the majority of your assets live in cold storage,” in wallets that are “Completely offline, Protected by multi-signature access controls, Stored on hardware-separated systems.” Cold storage with multisig access is custody. Fully on-chain is a description of where the ledger lives, not of who controls the keys.

5. Your Own Vault, Debited at Authorization: Gnosis Pay, Ether.fi Cash and Bleap

The strongest position a cardholder can hold is a wallet or smart account the operator cannot move, with a spend permission scoped to the card. It is documented well enough to check at four programs.

Gnosis Pay is the only program whose contract pattern is fully named in its own terms: a “Safe” is “a self-custodial smart contract-based wallet deployed to Gnosis Chain that is solely owned and controlled by you via your Signing Wallet,” and “Gnosis Pay does not offer a crypto-asset wallet or take possession, control or custody of your crypto-assets or Supported Funds at any time.” A Roles module lets the card’s spender move funds to a settlement Safe owned by Monavate; a Delay module puts a three-minute cooldown on the user’s own outbound transactions, so the user, not the card, waits. Monavate’s EEA cardholder terms add the sentence that closes the loop with bucket 3: “The Safe is not an e-money account or payment account.” Value in the Safe is outside safeguarding in both directions. On June 1 a signature-verification flaw in the Delay module let an attacker queue transactions across many Safes at once; reported losses were around $265,000, Gnosis covered them, and every Gnosis Pay Safe was replaced.

Ether.fi Cash publishes the most useful artifact in this whole exercise. Its CashModule contract on Optimism, at 0x7Ca0b75E67E33c0014325B739A8d019C4FE445F0, exposes a spend function whose parameters include a binSponsor field documented as “Identifier of the bin sponsor (Rain or Reap),” with separate SettlementDispatcherRain and SettlementDispatcherReap contracts deployed beside it. In Direct Pay mode “tokens are transferred directly from the Vault to the settlement dispatcher”; in Borrow Mode they are borrowed against the vault’s collateral from an Ether.fi-managed Aave V4 instance that Ether.fi says carries $22 million of active borrowing for about 70,000 cardholders. The custody nuance is in the vault docs: the vault owner is a Turnkey signer inside an AWS Nitro enclave, not a seed phrase the user holds, and the default recovery set includes “An EtherFi corporate signer.” That is self-custody with an operator-shaped backstop, and Ether.fi discloses it.

Bridge, Stripe’s stablecoin arm, documents just-in-time debit for its non-custodial mode: “At the time of each card authorization, Bridge pulls the exact spend amount onchain from the linked wallet,” against a token approval to published contracts on Tempo, Solana, Base, World Chain and Linea. MetaMask Card runs on the same primitive, an ERC-20 spending cap on the user’s own address that “the card will never go over” and that the user can revoke.

Bleap, a Latvian program on a Cypriot EMI, is the only document in the set that answers the insolvency question inside the custody clause: “Your Card is non-custodial and can be funded only from your Bleap Wallet (which you control). Neither Bleap nor Unlimit holds your wallet assets. If either Bleap or Unlimit becomes insolvent, your Bleap Wallet assets remain unaffected.” Compare that sentence with KAST’s, and you have the whole spectrum in two paragraphs.

Crypto Card Custody Terms Compared: 18 Programs

Program Where your value sits after top-up Issuer named in the terms Terms date
KAST Sold to KAST; you hold a USD debt claim, $500 liability cap Third National Jul 7, 2026
RedotPay Custody at Red Dot Trust, a group affiliate; general lien Not named (StraitsX for Singapore, per release) Jul 9, 2026
Revolut Nominee custody, Revolut holds legal title Lead Bank (US prepaid) undated
Coinbase Card Title stays with you, creditor-remote wording; sold at the swipe Pathward (US), Paysafe (UK) Jul 22, 2026
Crypto.com USD only on the card; e-money in the EU Community Federal Savings Bank (US), Foris MT (Malta) Sep 1, 2026
Krak Card (US) Fiat only at Lead Bank; crypto in Kraken custody Lead Bank Aug 3, 2026
Bybit Bybit sells as agent, disclaims holding fiat Harmoniie SAS with Moorwand Jan 16, 2026
Avici Your collateral in a Rain-run contract Third National Jun 23, 2025
Tria Your collateral in a smart contract Third National / Nimbus LLC Jan 9, 2026
Payy Your collateral in a smart contract (Rain template) Third National Feb 12, 2024
Solayer Emerald “Fully on-chain” marketing; security docs describe cold storage multisig Third National Apr 11, 2025
Plasma One Non-custodial Privy wallet, keys in a TEE Third National, also stated as Rain Feb 26, 2026
Ether.fi Cash Your vault on Optimism, Turnkey signer, corporate recovery signer Third National Sep 9, 2026
Gnosis Pay Your Safe on Gnosis Chain, Roles and Delay modules Monavate Nov 18, 2025
MetaMask Card ERC-20 spending cap on your own address Monavate; Cross River Bank (US) read Sep 10, 2026
Bleap Your smart account, direct debit mandate Unlimit EU (Cyprus EMI) Jun 28, 2026
Holyheld Your wallet until conversion at an unnamed partner Not named Jul 1, 2026
Wirex Fiat as safeguarded e-money Transact Payments Malta undated

On paper, eight of the 18 sit in the two self-custodial buckets, and seven of the 18 name the same issuer. That is the next problem.

Third National: The Card Issuer Behind Seven Crypto Cards Is Not a Bank

KAST, Avici, Ether.fi Cash, Plasma One, Solayer, Payy and Tria, seven programs in the table, name “Third National” as their card issuer. Tria’s international terms point to legal.raincards.xyz for the issuer’s privacy notice. Rain’s privacy policy, last updated July 16, 2026, defines the group: “‘Rain’ refers to Signify Holdings, Inc. and its affiliates, successors, assigns, and subsidiaries, including without limitation Nimbus LLC, doing business as Third National and Third National LLC, Rain Liquidity LLC, Rain Payments Services, Inc., and Rain Products, Inc.” Third National’s own site describes itself as “an issuer on the Visa Network” and states that “Nimbus LLC dba Third National is licensed as a Money Transmitter by the Commissioner of Financial Institutions of Puerto Rico,” NMLS #2612780. Plasma One’s page says both that “the issuer for this card program is Third National” and that the card “is issued by Rain, a Visa Principal Member.” Those are the same company.

So the issuer behind a large share of self-custodial crypto cards is a Puerto Rico money transmitter inside a group that holds Visa principal membership, not a chartered bank and not an EMI. Rain’s footer states that “Rain and its affiliates are not banks, exchanges, or asset custodians. Rain does not provide FDIC insurance or hold deposits.” Rain’s May 2025 release with Visa explains how settlement actually happens: “Rain works with a network of capital partners - borrowing stablecoins to facilitate network settlement for credit card receivables.” When you tap, Visa settles with the merchant’s acquirer as normal, Rain pays Visa from borrowed stablecoins, and Rain is repaid from your contract. Your “non-custodial” card is a charge card that Rain has already financed.

That model is scaling fast. Rain raised $250 million at a $1.95 billion valuation in January. Western Union’s Stablecard launched on Rain in August, Ethena Pay on September 1 with Third National as issuer, and MoneyGram’s card on September 10. Paymentscan’s issuer map puts Avalanche Card, Avici, Cypher, Ether.fi’s settlement leg, Exa, Hyperbeat, Karta, KAST, Kolo, Plasma One, Solayer, Tria, Tuyo and Ethena Pay on Rain. On September 8, Visa said its stablecoin settlement volume had passed a $20 billion annualized run rate, that more than 160 stablecoin-linked card programs run on its network, and that it is sharing VisaNet settlement data with onchain lenders, Credit Coop among them, so that card programs can borrow working capital against it. Every Visa figure is an annualized run rate, not a cumulative total.

Concentration is not the same as fragility, and every affected cardholder was made whole within a day in August. But the drain reached Avici and Tria users at the same time through one Rain codebase, Blockaid named Solayer Pay as a third affected program, Jupiter’s mobile card paused balance withdrawals as a precaution, and the reason Ether.fi was not touched, as @Nikitont argued and Ether.fi’s published contract layout supports, is that its users’ funds sit in their own vaults rather than in Rain-administered collateral accounts. Ether.fi itself issued no statement; Rain’s said only that “other programs were not impacted.” Programs with the same issuer and the same “non-custodial” sentence in their terms had different outcomes because of where the money physically was.

The Rain Solana Card Contract Exploit of August 28, 2026

We traced the incident on both chains, and the shape is clearer than the coverage suggested. The attacker’s wallet, FVNFzqAny8spWdPmYw6RQ9TkYa29ueFFiqCFD1gQnCEj, received 1.79 SOL at 13:40:41 UTC through a deBridge order that had converted 189.99 USDC sent from an Ethereum address funded twenty minutes earlier. It then sat idle for 189 minutes. The first exploit transaction landed at 16:49:48 UTC and the last at 19:18:52 UTC, a window of 2 hours 29 minutes that matches what Blockaid reported. In between, the wallet sent 21,405 transactions, of which about 17,500 succeeded.

Each successful one followed the same three steps against a Rain-controlled Solana program: a SubmitSignatures call paired with the native Ed25519 signature-verification instruction, then AddCollateralAdmin, then WithdrawCollateralAsset. The program required two signed approvals to add an admin. The attacker’s second verification instruction pointed its signature, key and message offsets back at the first, so one signature satisfied a two-signature check, exactly as @0xVishnya read it from the chain while the drain was still running. That made the attacker a collateral admin on well over a thousand individual accounts, and an admin can withdraw. The median account lost about $24; the largest in Vishnya’s sample about $5,268. This was an authorization bug, not a stolen key and not a malicious upgrade. It is also not, strictly, a “shared pool”: the money sat in per-user collateral accounts, but under one program and one admin authority, which for the purpose of a sweep is the same thing.

Our own trace adds three things to the coverage we checked. First, the exploit transactions call three distinct Rain program IDs, 3zVB27Gap6fbxpAcV2hsBBUcV3vRjkCikBXREiyBzDuc, CWgkFB7ngUc9cGD1LryyhP7h6xYWtwrAjhSKKCoR1gkz and 26DkA98jjctzPkBEteUsN935CR4dsKx3XvjrtE7MeL4a, identical binaries deployed once per card program; press accounts counted two. Second, at the time of the attack all three had the same upgrade authority, the plain keypair EfQ2zvc1xQfscTxCPb1om4s1CetncrfVFSt5zwiUR99J, signing upgrades directly rather than through a multisig. Third, Rain’s first patch, to the worst-hit program, was written at 19:18:37 UTC, fifteen seconds before the attacker’s last transaction anywhere. The other two were patched at 19:41:08 and 19:43:42 UTC. On September 5, between 00:40 and 01:17 UTC, Rain moved the upgrade authority on all three programs to a Squads multisig vault, 7MoSDo66QknjsyE8yX9VnsrbGj4cQTDYVjo2JHLt5RSL. That is a real remediation, and Rain has not announced it anywhere we could find: its status page’s incident log stops on June 25, and Rain’s, Avici’s and Tria’s statements about the incident exist only as X posts. We read the current authority from Solana mainnet on September 10 and it is the Squads vault on all three programs.

The money left fast. At 19:03:18 UTC, while the drain was still running, a deBridge order moved 1,021,152.75 USDC from Solana to Ethereum for 418.11 ETH; two smaller orders, a 1,018 USDC test hop before it and a 90,925 USDC sweep after the leftover 886.94 SOL had been swapped through Jupiter, bring the total bridged out to 1,113,096.76 USDC. All three orders paid the same Ethereum address, 0x2cE21E4921d3Eb116526c3651Dac0257657338D5, which between 19:20:11 and 19:49:23 UTC made 23 deposits into the Tornado Cash router totalling exactly 455.9 ETH: four of 100 ETH, five of 10, five of 1 and nine of 0.1, the standard ladder for emptying a wallet to dust. The first 100 ETH entered the mixer before the SOL sweep on Solana had even happened. Nothing was recovered. The refunds came from company balance sheets: Avici’s $500,859.22 across 1,685 users, funded by Rain according to Avici, and Tria’s $431,945 across 636 customers as reported by CoinDesk. The gap between those two figures and the $1.1 million total is not publicly attributed. The $AVICI token fell roughly 49% on the day.

Avici’s second statement drew the boundary honestly: “This was limited to card contracts on Solana holding balances added through Avici’s Top Up flow,” while “Your regular Avici Solana and EVM wallets were never affected.” It also made the case for its own design: “We made a very deliberate choice to keep your Avici wallet separate from your card balance. It’s why you have to manually Top Up before spending.” Rain’s statement at 20:26 UTC described “a vulnerability impacting a small number of programs using an outdated version of our Solana contracts,” said all such programs had been upgraded, and promised that “all affected users will be made whole.” Its follow-up the next evening said every impacted cardholder had been repaid in full and that “these funds are in users’ smart contracts, all of which were successfully upgraded yesterday.” Rain’s own blog says it uses Sherlock for pre-deployment audits with a fresh audit “every time we add support for a new chain.” The drained code was an outdated deployed version, which is the case an audit-at-deploy process does not cover. All three programs were still live and transacting on September 10, on patched code, with card balances still held in Rain-administered collateral accounts. A full post-mortem was promised and had not been published at the time of writing.

“Self-custody failed” is the wrong lesson. In a cardholder agreement, “non-custodial” describes who cannot move your funds under normal operation. It says nothing about who wrote the contract, whether the deployed version is the audited one, or who holds the upgrade key. Avici’s users held their own keys and still lost the balances they had moved into the card layer, and the reason they got the money back is that a private company with $338 million of venture funding decided to pay. That is the same recourse a KAST user would have, dressed in different language.

No-KYC Crypto Cards: Fees, Issuers and Shutdowns, Checked Against the Sites

The other thread that circulated this summer was @OG_Branxi’s August 5 price list of no-KYC cards, drawn from the TODEY directory: opening costs, monthly fees, “typical loading fees 2-5% on most cards,” and the honest closing notes that “almost all are virtual-only” and “many teams still unverified.” It is a useful map. It is also, like every list of these cards, out of date by the time it is read, and the replies to it are more informative than the post. Replies from two users said Mpay’s “free” card costs $4.99 to activate. One posted a screenshot of Bit.Store’s March card shutdown with the caption “This is going to happened to you if you ever parked your money in any card on this lists.” Branxi’s own conclusion, two days in: “feels more like a niche product or step 1 before getting a KYC card.”

We went to each card’s own site where it would load, and where it was bot-blocked or Telegram-only (Laso, SolCard, OffGrid, KardPay, Pintopay, MaxSwap, Privacy Gateway) to the detail pages at CryptoCardHub, TODEY and Monetiro, and compared. A summary:

Card To open Monthly Load fee Issuer named? What the list left out
Laso Finance $0 (US/CAD) $0 0% US/CAD, 3.8% international No Non-reloadable, $1,000 per card, 14% fee to refund unused balance
Freedomia $0 $5 Founder tier (launch price); $9.99 to $17.99 tiers “coming soon” 1.3% No Domain registered October 2025
SolCard $10 $0 5% on the no-KYC tier, 0% with KYC No (operator SC Payments Ltd, Hong Kong) No-KYC tier is Mastercard only; Trustpilot 2.3/5 with frozen-balance complaints
Trocador $2 + 3% $2.50 after month two (international) included No (aggregator) Collects name, phone and address at checkout
Bing Exclusive $25 $1 per review sites 1% No (operator Queensland FX, per review site) Listed under “zero monthly fees”; review sites show a $1 monthly fee we could not confirm on Bing’s own page
XHYPE not separately stated $9 to $20 ($108 to $240 a year) 2.3% to 4.5% No (“licensed financial partners”) List said $25 plus $108 to $588 a year; site shows no $588 tier
OffGrid $0 $49 to $197 a year, fourth tier undisclosed 1.5% flat since August No (TODEY marks the entity “not disclosed”) Invite-only; domain registered December 2025
KardPay $29 to $299 $0 3% to 5% No (operator Rosscapital US LLC) Most detailed review says full KYC is required
Pintopay $35 $0 2.5% Yes: Sunrate Solutions (HK) KYC “when required by the issuer”; clustered frozen-fund complaints on Trustpilot since April
MaxSwap $50 + $25 minimum balance $0 4.5% No Telegram bot; claims $2M monthly limits on email-only onboarding
Privacy Gateway not stated $5 promo, $10 regular 3.5% No One-way conversion: loaded crypto cannot be withdrawn

Neither of the two names volunteered in the replies belongs on a no-KYC list at all. Revuto’s card is issued by Paynovate SA, an e-money issuer regulated by the National Bank of Belgium, and its terms say users “may not use the Wallet or withdraw any cryptocurrencies until the KYC process is successfully completed”; the KYC-lite tier caps out at $250. Payy requires government ID before issuing a card; its privacy is on-chain privacy, with balances hidden from block explorers, not identity privacy. Where the fees above conflict with what the list said, the operator’s own page won, and where the operator’s page was bot-blocked we have said so.

The issuer column is the finding. Of eleven cards, one names its issuer. Every other one describes “licensed partners” or nothing. The loading fee is the price of a BIN nobody will identify.

How that BIN exists is documented. FinanceFeeds reported on August 7 that the mechanism is the gap between business verification and customer verification: “A company completes Know Your Business verification, a process that, under the Bank Secrecy Act, requires only the entity’s name, principal place of business, and tax identification number. […] Once the company entity clears that bar, cards can be issued to individual employees, contractors, or ‘authorised spenders’ without any additional identity verification.” The article identified BINs from Fifth Third Bank, The Central Trust Bank, Column, Regions Bank and Sutton Bank on the no-KYC services it reviewed, noted that Sutton has operated under an FDIC consent order since February 2024, and named CinCin, a Marshall Islands operation offering $2 million monthly limits on USDT-over-Tron top-ups, and PayWithUs, which “fraudulently obtained 53 cards” and processed about $10,000 in under two weeks before it was shut. It also reported that Off Grid uses the international issuer Sunrate and that Uncash continued using Sutton Bank BINs. This is the corporate card program repackaged as a consumer card, with names attached.

The way these cards die has not changed since 2018, when BitPay wrote that “our European BitPay Card issuer Wave Crest Holdings, Ltd. received direction from Visa to immediately close all accounts of its prepaid Visa debit card programs” and that cardholders “can no longer use cards for further payments or withdrawals.” This year’s version is Bit.Store. Its March 9 notice explains that “according to a public notice issued by the Bank of Lithuania on 6 March 2026, the Electronic Money Institution licence of Paytend Europe UAB has been revoked. The regulator stated that, as of 3 March 2026, the institution is no longer authorised to provide financial services,” and that “customers holding funds in accounts opened with Paytend Europe UAB must apply directly to the institution for the return of funds.” Bit.Store was not the issuer and could not refund anyone; it could only post two Paytend email addresses. The shutdown decision in every case we found, Bit.Store in March, the Kulipa collapse below, and SolCard’s loss of its no-KYC Visa tier in 2025 as reported by review sites, was made by the sponsor or the network, not by the brand the customer had a relationship with.

The regulatory horizon is now dated. The EU’s Anti-Money Laundering Regulation, Regulation (EU) 2024/1624, applies from July 10, 2027. Its Article 19(7) allows supervisors to exempt low-risk e-money from customer due diligence only where “the payment instrument is not reloadable, and the amount stored electronically does not exceed EUR 150,” and “the payment instrument is not linked to a payment account and it does not permit any stored amount to be exchanged for cash or for crypto-assets.” Article 79 prohibits credit institutions, financial institutions and crypto-asset service providers from keeping “anonymous crypto-asset accounts as well as any account otherwise allowing for the anonymisation of the customer account holder,” and bars EU acquirers from accepting “payments carried out with anonymous prepaid cards issued in third countries” unless technical standards carve out a proven low risk. In other words, from mid-2027 an anonymous card loaded from crypto is outside the exemption by construction, and an offshore anonymous prepaid card may be refused at the EU merchant’s terminal rather than at the issuer. As @Nikitont put it in a September 4 tier list of the same cards: “no-KYC ≠ safe and ≠ forever. BIN freezes, partner changes and sudden KYC still happen.”

Crypto Card Infrastructure Failures in 2026: Kulipa, Paytend, Cypher, Fiat24 and Gnosis Pay

The August drain was the loud failure. The quiet ones did more damage to cardholders, and none of them involved a hack.

Kulipa, the Paris card-issuing infrastructure that had raised a $6.2 million seed in April, halted operations on July 28, sixteen weeks later, taking the Ready (formerly Argent) card, Solflare’s card, and programs for Flutterwave and nSave down with it. Its CEO disputed the word “insolvent.” The cards stopped regardless. Because both consumer programs were self-custodial, no balances were lost; users simply had a dead card and a wallet they could still access. That is the self-custodial model working as designed, and it is worth noticing that “working as designed” still meant the product ended without notice.

Nium acquired Cypher on July 8; Cypher closed all active cards on August 8 and shut its platform on September 6, which in turn ended the Moonwell Card built on it. Fiat24, the Swiss banking backend behind the SafePal, Bitget Wallet and imToken cards, paused all new registrations and crypto deposits from July 14, according to reports we could not match to a Fiat24 notice, citing growth outpacing its risk and compliance capacity; Bitget Wallet’s tracked card spend fell from $4.4 million in June to $0.9 million in August, and SafePal’s from $2.7 million to $0.6 million.

And Gnosis Pay, the program whose Safe architecture the whole self-custodial category copied, told its users on September 4 that it is winding down its own consumer interface. Web app signups closed that day, the $GNO cashback program ends September 30, no new cards will be issued on existing accounts after September 30, and the web app is to be deprecated by the end of 2026, with cardholders steered to partner apps such as Rebind. The help article says “Is Gnosis Pay shutting down? No.” Paymentscan’s data says its volume peaked at $12.05 million in October 2025 and was $8.3 million in August. The Safe, the Delay module and the Monavate issuing relationship survive as a white-label platform. The consumer card that proved the model does not.

Crypto Card Cashback and Rewards, a Year On

@0xSammy’s original October 2025 table, which his July post revisited, compared eight cards on cashback and perks. Almost every cell has moved, and the direction is consistent: the self-custodial programs kept or raised rewards and added credit, the exchange programs cut.

Ether.fi pays cashback by membership tier, lets cardholders borrow against the whole portfolio through its dedicated Aave V4 deployment, and said on September 10 that 36 cars were bought through the card in August, the most expensive over $120,000. KAST’s base tiers pay 1.5%, 2% and 3% with periodic promotions on top, and its points program now converts to tokenized equity rather than a token, the July 2 decision that started the argument. Crypto.com renamed its tiers and put rewards behind $CRO lockups or subscriptions, with free no-stake cashback gone. Coinbase added a USDC security-deposit option to its Amex credit card in June, so a crypto balance can collateralize a real credit line. MetaMask Card launched in the US in February on Cross River Bank; its tracked spend fell from $5.3 million in April to $2.9 million in August anyway. Gnosis Pay’s $GNO cashback ends this month. Plasma One, which was a waitlist in the original table, grew from $765,600 of tracked spend in April to $19.9 million in August. And Ethena Pay, which did not exist, launched September 1 with 4% to 5% cashback paid in $AVAX and up to 6% on balances, on Third National and Rain.

@0xVishnya’s receipt tests are the right way to read any of these numbers. On the same EUR 11.17 purchase in the same minute, seven cards charged between $12.92 and $13.09, a 1.3% spread that was entirely FX, and one card’s app showed a different purchase amount from the paper receipt while printing “Fees $0.00.” Cashback is what the card advertises. The exchange rate at the terminal is what it charges.

What to Check Before You Top Up a Crypto Card

The point of reading 18 sets of terms was to find out which questions actually separate these products. There are five, and the marketing answers none of them.

Which of the five buckets is this? If the terms say “sale,” “transfer of ownership,” or “payment obligation,” you are a creditor. If they say “custodian” or “nominee,” someone holds title or possession on your behalf and the insolvency answer depends on the jurisdiction and the drafting. If they say e-money, safeguarding applies to the fiat and nothing else. If they say “smart contract” and “collateral,” find out whose contract.

Who is the issuer, by legal name? “Licensed partners” is not an answer. Of eleven no-KYC cards, one named its issuer. Of the mainstream programs, six named a Puerto Rico money transmitter owned by their program manager. The name matters because the issuer is the party whose regulator, sponsor bank or network can end the program overnight, as Paytend’s did in March and WaveCrest’s did in 2018.

What does the document say about insolvency? Bleap answers it in one sentence in the user’s favor. KAST answers it in one sentence against. Coinbase answers it with a title clause a court has not tested. Most of the rest do not answer it.

Who can upgrade the contract? For anything in bucket 4 or 5, the operator’s inability to move your funds today is worth less than the operator’s ability to change the code tomorrow. Rain’s docs are behind a login. Ether.fi’s and Gnosis Pay’s are public, with addresses. That difference is itself information.

Is the volume you are reading real? RedotPay’s $403.6 million is RedotPay’s number. KAST’s and Karta’s are settlement proxies. Ether.fi’s and Gnosis Pay’s are on chain. A leaderboard that mixes the three is not a leaderboard.

In August 2026, $468 million of $1.116 billion in tracked crypto card volume settled through one company, whose issuing affiliate is a money transmitter, whose technical documentation is behind a login, whose settlement is financed with borrowed stablecoins, and whose August response to a bug in its own code was to refund 1,685 people in full within 24 hours. Most cardholders will remember the second half of that sentence. The first half is what the terms are for.

DeFi is coming. Don't get left behind

About the author
Nick Sawinyh founded DeFiprime in 2019 and has edited it ever since. His current editorial focus is stablecoin infrastructure, real-world assets on-chain, DeFi yield and risk, and crypto regulation. Based on the East Coast, US. He holds small positions across a range of crypto assets; nothing he publishes is investment advice.

More from the blog