In Korea, as the number of debit card users who pay based on virtual asset increases, there are warnings to be cautious because hacking incidents occur frequently.
On the 1st, according to the virtual asset industry, on Aug. 29, funds of users of the Blockchain-based virtual asset neo-bank platforms Tria and Avici's Crypto Card were withdrawn without authorization. The losses totaled $430,000 (about 590 million won) at Tria and $500,000 (about 685 million won) at Avici, affecting about 2,300 people. Both cards can be issued in Korea, and Korean victims were not counted separately.
Tria and Avici are Blockchain-based virtual asset neo-bank platforms that let individuals load virtual asset held by them onto a payment card for use in everyday payments and remittances. A neo-bank refers to a digital-only bank that offers financial services exclusively through a mobile application (app) or the internet without offline branches. The payment base is dollar stablecoins such as "USDC" and "USDT" deposited on the platform.
The hacking this time exploited a vulnerability in the Smart Contract system. A smart contract is a program that automatically executes an agreement when preset conditions are met on a Blockchain network.
When a Crypto Card user loads stablecoins onto their own card, the coins are held in a third-party smart contract. Stablecoins on Solana that the user loads onto the card are held in a Solana smart contract, and at the time of payment, funds are withdrawn from that smart contract. The hacker siphoned off the stablecoins by exploiting a security flaw left in an old version of the Solana smart contract.
Tria and Avici Crypto Cards use a virtual asset card-dedicated payment infrastructure called "Rain." The hacker exploited signature and permission verification flaws in the Solana smart contract designed by Rain, registered themself as an administrator on each user's collateral account, and withdrew the balances. Rather than an issue with Tria and Avici themselves, the primary cause was a code flaw in Rain. Rain updated all programs that were running the old version on the day of the incident.
Tria promised full reimbursement, and Avici completed full reimbursement the next day and additionally paid 10% of the amount stolen by the hacker.
This hacking case is being evaluated as an example that shows the vulnerability of virtual asset-based payment card systems. That is because once an old-version smart contract of Rain was hacked, it was confirmed that crypto card projects linked to the Rain ecosystem saw funds leak and functions grind to a halt.
According to the "2026 Crypto Security Status Report" that virtual asset market platform CoinGecko released on Aug. 27, over the 19 months from Jan. last year to July this year, $3.633 billion (about 5 trillion won) was siphoned off in 245 hacking and security incidents that occurred on virtual asset platforms. Of this, the cumulative global hacking damage caused by smart contract security flaws and vulnerabilities was estimated at a minimum of $1 billion (about 1.37 trillion won).
Funds loaded onto virtual asset-based payment cards are remitted to a smart contract rather than a bank account, and the issuer is not a bank, so there are no safeguards such as deposit protection. These cards are not licensed financial services in Korea, so if a problem arises, they cannot be protected by Korean law.
Kakao Pay(377300) and Naver Pay, among other domestic prepaid cards, have been required since Sept. 2024 to manage 100% of loaded funds separately (trust, escrow, or payment guarantee insurance) under the Electronic Financial Transactions Act.
Overseas virtual asset exchanges such as Binance Holdings Ltd., OKX, and Crypto.com are also issuing their own payment cards and expanding their business scope in markets worldwide, including Korea, evolving into comprehensive financial platforms. In August alone, payments made via crypto cards worldwide totaled 1.45 trillion won, more than tripling in a year.