Ads that offer to "sell CVV cheap with high balance" are advertising stolen card data. Buying or selling that data is a federal crime in the US under 18 U.S.C. § 1029, and the listings themselves are almost always fake. Sellers take crypto, hand over numbers that fail or get declined, then disappear, and the buyer cannot complain to anyone because the purchase was illegal from the start.
There is no legitimate discount market for working card codes. Banks, card networks, and processors spend millions to keep those codes out of circulation. A "high balance" claim also cannot be checked before use, so a seller who makes it is asking for trust with no proof.
What is a CVV or CVC code?
A CVV, CVC, or CVV2 is the 3-digit code printed on the back of most credit and debit cards. American Express prints a 4-digit code on the front. The code proves that whoever is typing the number has the physical card in hand.
Card networks require that code for card-not-present transactions, which covers most online purchases. That single requirement is why a stolen card number on its own has limited value to a thief.
- CVV2 / CVC2: the printed code, never written to the magnetic stripe or the chip.
- CVV1 / CVC1: encoded in the stripe data and read at a terminal.
- iCVV: generated by the chip for contact and contactless payments.
PCI DSS Requirement 3.2 bars merchants from storing the printed code after an authorization. Any checkout that asks you to "confirm the CVV" saved in your profile is doing something it should not.
How stolen card data reaches the market
Card numbers leak through skimmers on fuel pumps and ATMs, breaches at merchants and payment processors, phishing pages, and fake checkout forms. Thieves bundle the records into files that carding forums call "bases" or "fullz."
Prices inside those files run from cents per number to a few dollars, and the same file gets sold to many buyers. That is why a cheap CVV ad is a warning sign rather than a bargain: the data has been sold before, and often tested to death before you see it.
Some listings mix real numbers with invented ones to pad the count. Others sell a working card to a dozen people at once, then let the buyers fight over who the card belongs to when it gets shut off.
Red flags in any "high balance" card listing
Every pitch in this market follows the same script. The details change, the traps do not.
- Unverifiable balance claims. No seller can show a balance without the account holder noticing the check.
- Crypto-only payment. There is no chargeback path, and that is the point.
- Fabricated reviews and escrow. The same people run the shop, the escrow service, and the review threads.
- Free samples. A sample that works is bait, and it also shows the seller has no fear of law enforcement.
- Bulk discounts. Volume pricing means the data is stale, recycled, or invented outright.
Legal risk falls on buyers, not just sellers
18 U.S.C. § 1029 covers trafficking in access devices, and that includes buying card numbers and codes. A first trafficking offense carries a maximum of 10 years in prison plus fines, and the statute also reaches attempts and possession with intent to use.
Banks and card issuers sue as well. One declined test charge can tie a person to an IP address, a device fingerprint, and a crypto payment trail that investigators can follow back to a name.
Some buyers assume a small test charge is harmless. It is not. Card testing is the fastest route to a frozen account and an open case file.
Do banks or card networks ever sell card codes?
No. Issuers, networks, and processors have no secondary market for CVV data, at any price. A card code has value only to the account holder and to the merchant processing that one transaction.
Any site claiming a wholesale source, a bank insider, or a "fresh base" from a processor is inventing a supply chain. There is no such pipe, so there is nothing on the other end of the payment.
How to protect your own card code
- Never read the code aloud on a call you did not start.
- Use virtual card numbers or a payment token (Apple Pay, Google Pay) on unfamiliar sites.
- Turn on transaction alerts for every charge above a small amount.
- Check statements once a week rather than once a month.
- Freeze the card through your bank app if a checkout page acts odd.
What merchants can do about card-testing fraud
Most card-testing attacks show up as a burst of small authorizations from one IP range or one bank identification number. Blocking those patterns costs far less than the chargebacks they create.
- Require CVV and address verification on every card-not-present order.
- Set velocity limits per card, per IP, and per email address.
- Apply 3-D Secure for high-risk BINs and first-time customers.
- Log and review declines instead of ignoring them.
What to do if your card code leaks
- Call the number on the back of your card and ask for a replacement number.
- Dispute any charge you do not recognize instead of waiting for the statement cycle.
- Change the password on the merchant account where you entered the code.
- Watch for phishing that references the exact amount of the fake charge.
Where to report a card-data listing or a stolen code
Report the listing to the FBI Internet Crime Complaint Center at ic3.gov, and report the fraud to the FTC at ReportFraud.ftc.gov. Tell your card issuer as well, and ask for a new number if you typed your code into a suspicious page.
A card network and the issuing bank can act on a reported merchant or forum faster than any individual can. Reporting takes about ten minutes and puts the case in front of the people who can shut the operation down.