Why "Buy a CVV" Is the Wrong Question
A CVV is the three digit code on the back of your card, or the four digit one on the front of an American Express. It exists for one reason: to show the person typing the number is holding the physical card. That makes it a security feature, not a product. Nobody manufactures, licenses, or wholesales CVVs. So when a search engine hands back "shops" claiming to sell them, what's actually on offer is someone else's stolen card data, or nothing at all.
I treat that distinction as the starting point, not a technicality. It changes what a careful buyer should do. There is no vendor to vet, no price comparison to run, and no recourse if what you paid for turns out to be garbage. There is only a crime and a scam, often both in the same transaction.
What the Underground Market Actually Looks Like
Card data moves through forums, chat channels, and automated storefronts that take crypto. Vendors advertise "bins," "fullz," or "dumps," and the pitch never changes: cheap data, high balance, instant delivery. The reality is worse than the pitch.
- Much of the inventory is already dead. Cards get cancelled the moment the real owner or the issuer notices a stray charge.
- A large share of these storefronts are exit scams that vanish after a few dozen orders.
- Some are phishing operations that harvest your crypto, your email, and sometimes your own identity documents.
- Even working data leaves a trail: blockchain records, chat logs, shipping addresses.
Prosecutors don't need to catch you mid-purchase. Possessing or using a stolen access device is enough on its own.
Legal Exposure in the US
Buying or selling card numbers falls under access device fraud, 18 U.S.C. 1029. A first offense can carry up to 10 years, and aggravated cases run to 15. Stack wire fraud, identity theft, and money laundering on top and the sentencing math turns brutal. Reselling your own card details is not a loophole either. Card network rules prohibit it, and using another person's account is still fraud.
How to Protect Your Own CVV Instead
This is the part of the topic worth your attention. If you shop online, your CVV is the last barrier between your card and a stranger.
- Never store the code in a browser field, a password manager note, or a screenshot. Nothing legitimate needs to keep it.
- Use virtual card numbers when your issuer offers them. They spin up a fresh number and code per merchant.
- Favor merchants that tokenize. Once a card is tokenized, the real CVV never touches their servers.
- Watch for skimmers and cloned checkout pages. If the deal looks impossible and the domain is three weeks old, close the tab.
- Turn on transaction alerts for every charge, not just the big ones.
If your card data does leak, the law limits the damage. Liability for unauthorized credit card charges is capped at $50 under the Fair Credit Billing Act, and most issuers waive even that. Report it the same day, get a new number, and file a report with the FTC if identity theft is involved.
What I'd Actually Look For
Not a vendor list. The signals that matter sit on the defensive side: an issuer with instant card freezing, real-time alerts, virtual numbers, and a human on the phone within a couple of minutes. Those features decide whether a bad charge costs you one phone call or a month of cleanup.
Anyone selling you a CVV is selling a felony or a lesson. Usually both at once.