What the Phrase Refers To

A CVV is the 3-digit code printed on the back of a Visa, Mastercard, or Discover card. American Express prints a 4-digit code on the front. The issuer uses that code to confirm the person typing a card number holds the physical card.

related article

Searches for cheap CVV data sold for bitcoin point to card-not-present fraud markets. Those markets trade stolen card numbers, expiry dates, cardholder names, and billing addresses. The activity is illegal in the United States and in every country that signed the Budapest Convention on Cybercrime.

How to Sell CVV for Bitcoin Fast

Advice First

No legitimate seller sells CVV data. A bank issues the code to one cardholder for one card. A listing that offers card records at a low price is either a stolen-data sale or a scam that takes the buyer's bitcoin and returns nothing. Both outcomes carry cost. The first brings criminal charges. The second brings a total loss with no recourse, because the buyer cannot report a fraud purchase to police without admitting to the purchase.

sell cvv for bitcoin price

Buyers in these markets publish wallet addresses, handles, and forum posts. Investigators use that trail. The FBI and the U.S. Secret Service run carding cases that start with forum activity and payment flows.

sell cvv for bitcoin price

What Federal Law Says

18 U.S.C. § 1029 covers fraud and related activity in connection with access devices. Trafficking in card numbers can bring up to 15 years in prison and a fine. One count can cover hundreds of card records. Prosecutors do not need to show that the card was used.

How Card-Not-Present Checks Work

Merchants run a set of checks on each order:

  • Address Verification System: compares the billing street number and ZIP code against issuer records.
  • CVV match: the issuer returns a match, no match, or not processed.
  • 3-D Secure: the issuer asks the cardholder for a password or a push approval in an app.
  • Velocity checks: order count per card, per IP address, and per device.
  • Geolocation: billing country against IP country and shipping country.

Pitfalls for Shoppers and Merchants

PCI DSS requires merchants to protect stored cardholder data, and it forbids storage of the CVV2 value after authorization. A merchant that keeps CVV2 in a database fails the audit and carries liability for a breach.

Shoppers should treat any request for a CVV over email, chat, or phone as fraud. Legitimate processors collect that code on a payment page. A caller who asks for the card number, the code, and a one-time passcode in the same call is running a scam.

If a card number leaks, the issuer reissues the card and the old number stops working. Losses from card-not-present fraud land on the merchant or the issuer, not the cardholder, when the charge is reported. Reporting time matters. Federal law caps cardholder liability for unauthorized credit card charges at $50, and most issuers waive that amount. A cardholder who never reports the charge can lose the right to dispute it.