Sign up
Subscribe
Home / news / Korea’s crypto card boom runs into smart contract risk after Tria and Avici hacks
news

Korea’s crypto card boom runs into smart contract risk after Tria and Avici hacks

Korea’s crypto card boom runs into smart contract risk after Tria and Avici hacks

South Korea is seeing more debit card users pay with virtual assets, and the latest Tria and Avici incidents are a clean reminder of where the risk sits: not always at the issuer, but in the payment stack underneath it. On Aug. 29, unauthorized withdrawals hit both cards, with losses of $430,000 at Tria and $500,000 at Avici.

  1. According to the virtual asset industry, the two incidents affected about 2,300 people in total. Both cards can be issued in Korea, and Korean victims were not counted separately, so the local exposure is part of a wider user base rather than a neatly ring-fenced domestic case.
  2. Tria and Avici are blockchain-based virtual asset neo-bank platforms that let users load virtual assets onto a payment card for everyday payments and remittances. In practice, the payment base is dollar stablecoins such as USDC and USDT deposited on the platform.
  3. The hack exploited a vulnerability in a smart contract system. When a user loads stablecoins onto a crypto card, the coins are held in a third-party smart contract; on Solana, funds are withdrawn from that smart contract at payment time. The attacker used a security flaw left in an old version of the Solana smart contract to siphon off the stablecoins.
  4. Tria and Avici use a crypto-card payment infrastructure called Rain. The attacker exploited signature and permission verification flaws in the Solana smart contract designed by Rain, registered as an administrator on each user’s collateral account, and withdrew balances. Rain updated all programs running the old version on the day of the incident.
  5. Both companies moved fast on reimbursement: Tria promised full reimbursement, while Avici completed full reimbursement the next day and additionally paid 10% of the amount stolen by the hacker. For card programs, that is the part operators and PSPs care about first: whether the incident stops at the protocol layer, or turns into a customer-balance event.

CoinGecko’s 2026 Crypto Security Status Report, released on Aug. 27, says that over the 19 months from Jan. last year to July this year, $3.633 billion was siphoned off in 245 hacking and security incidents across virtual asset platforms.

Weekly high-risk digest

Regulation, sanctions and payment news across your verticals — once a week, free.

Please check your inbox and click the link to confirm your subscription.

Please enter a valid email address!