Buy now

A crypto card feels like the least exotic thing in this industry. You load a balance, you tap it at a coffee shop, and the whole point is that nothing about the transaction requires you to think about blockchains. Then on 30 August 2026 three different card programs lost money at the same moment, for the same reason, and none of their users had done anything wrong.

We make a hardware wallet, so our interest here is not neutral. It is still worth walking through what broke, because the answer has less to do with cards than with a question most people never ask about the balance sitting on one.

What happened

An attacker exploited an authorization flaw in an older version of Rain's Solana contract, the infrastructure several consumer card programs were built on. As crypto.news reported, the flaw let the attacker add itself as an administrator on card collateral accounts, granting itself withdrawal permissions, then repeat that across individual users until their balances were gone. Blockaid put the total at roughly 1.1 million USD.

The breakdown by brand tells you something the total does not. Avici reported 500,859 USD drained from 1,685 users, and Tria identified 431,945 USD affecting 636 customers, with Blockonomi noting that other Rain-supported programs were exposed as well. Jupiter's card partner paused card-balance withdrawals as a precaution while it ran checks, then restored them. The attacker swapped the stolen stablecoins into SOL, bridged to Ethereum, and pushed the proceeds through Tornado Cash, where they stayed.

Why three brands broke on the same afternoon

Here is the part worth sitting with. Avici, Tria and the others are separate companies with separate apps, separate branding and separate signup flows. A customer who compared them would have found different fee structures and different rewards. What that customer could not see from the outside is that the card balance in each app was being held under the same contract code from the same issuing partner, so a defect in one version of that code reached across every brand running it.

You chose a card. The layer that held your money sat underneath, selected by the company whose logo was on the app, running a version you were never told about and could not audit. Rain has since upgraded every program still on the vulnerable contract and reported no further unauthorized activity.

Where a crypto card balance sits

The mental model most people carry is that a crypto card spends from their wallet, the way a debit card draws on a checking account. That is rarely how these products are built. Loading the card usually moves your assets into a collateral account controlled by a smart contract, which the card issuer draws against when you tap. Your app shows a number, and the number is a claim on funds held somewhere you do not control.

This is the same shape as leaving coins on an exchange, dressed in a nicer interface. The balance is an entry in someone else's ledger, and the security of that entry depends on code written by a company you have probably never heard of. When it works, and it usually does, the experience is good enough that the question never comes up. When the authorization logic has a hole in it, 2,321 people find out on the same day that the number in the app was a promise.

The refunds are the tell

Avici refunded every affected customer in full and added 10% cashback on top. Tria reimbursed each affected customer as well. Both companies handled this about as well as anyone could, and the users got their money back, which is the outcome you want.

Notice what made that possible. The funds were recoverable because a company chose to make its customers whole out of its own balance sheet, not because anything about the system returned them: the attacker's proceeds went into a mixer and stayed there. A refund is a business decision, and business decisions depend on whether the company is solvent, well capitalized and still in operation when the thing goes wrong. Plenty of platforms in 2026 were none of those.

What a crypto card is good for, and what it is not

None of this means crypto cards are a bad product. Spending crypto without manually selling it first removes a step people find tedious, and the companies above shipped a fix and paid people back within days. Treat the card balance as spending money, and it is a reasonable tool.

The mistake is treating a card balance as storage. Whatever you load onto a card has left self-custody the moment it goes into that collateral account, and everything you gain in convenience you pay for in counterparty exposure. The sensible split is the same one people use with cash: a small working balance you can afford to lose while the rest stays somewhere only you can reach.

Keeping the rest of it out of reach, including your backup

The portion you are not spending belongs on a device that holds its own keys. On Ryder One, private keys are generated inside an EAL6+ certified Infineon SLC38 secure element and never leave the chip, communication is NFC-only with no USB or Bluetooth radio to attack, and every transaction appears in full on the 1.6-inch AMOLED touchscreen before you approve it. There is no administrator role anywhere in that design, because there is no account for an administrator to be added to.

That covers the coins. Your recovery is the other half, and the standard answer has the same concentration problem the Rain contract did: write the seed phrase on paper, then upgrade to stamped metal once the amount justifies it. Metal survives water and heat, which is a proper improvement over a sheet of paper in a drawer, and your entire recovery still depends on one object nobody is watching. TapSafe Recovery splits it instead: a Recovery Tag carries 50%, your paired phone carries the other 50% stored encrypted in your iCloud or Google Drive rather than on the handset, and optional Recovery Contacts hold 25% each while seeing nothing about your wallet. It runs on a custom implementation of Shamir's Secret Sharing, and the BIP-39 seed phrase stays available on the device as a last resort, so you are never tied to our hardware.

If you use a crypto card right now

Keep using it if it suits you, with a few adjustments. Hold only what you plan to spend in the next few weeks on the card itself, and move the rest into self-custody where no contract upgrade can reach it. Find out who issues the card behind the brand, since that is the company whose code your balance depends on. Turn on every notification the app offers, because the users who noticed the Rain drain early were the ones watching their balance rather than checking it monthly.

Convenience is worth paying for. Just be clear about what you are paying with, and keep the size of that payment small.

Ready to move the rest somewhere a contract upgrade cannot touch it? Get your Ryder One for 149 USD.


Meta description: Is a crypto card safe? The Rain contract exploit drained 1.1M USD from three card brands at once. Where your card balance sits, and what to keep off it.

Target keyword: is a crypto card safe

Meet Ryder One

Meet Ryder One
Meet Ryder One

The only crypto wallet you can install on a crowded subway.
Set it up in less than 60 seconds and just tap your phone to send, swap, and recover.

Learn More