Selling CVV numbers for bitcoin is carding

The phrase refers to the sale of stolen card data for cryptocurrency. A CVV is the 3 or 4 digit code printed on a payment card or generated for a digital wallet. Card networks use it as one factor that proves the person paying holds the card. Selling that code, or buying it, is a federal crime in the United States. In 2024 card networks, banks, and law enforcement treat these listings as organized fraud, not as a gray market.

sell cvv cheap bitcoin payment

What the codes mean

Each network uses its own name for the same idea.

sell cvv cheap bitcoin payment

  • Visa: CVV2, 3 digits on the back.
  • Mastercard: CVC2, 3 digits on the back.
  • American Express: CID, 4 digits on the front.
  • Discover: CID, 3 digits on the back.

The printed code is separate from the code encoded in the magnetic stripe. Payment Card Industry rules bar merchants from storing the printed code after a transaction is authorized. The rule exists because the code is the part of card data that cannot be replaced without reissuing the card.

more on this topic

Why bitcoin appears in these searches

Cryptocurrency transfers settle in minutes and cannot be reversed by a card issuer. That removes the chargeback, which is the main tool banks use to recover stolen funds. The tradeoff for sellers is that public blockchains keep a permanent ledger. The Department of Justice and IRS Criminal Investigation have traced and seized crypto tied to card fraud. Chain analysis firms sell tracing tools to banks and police. Anonymity on these networks is partial, not total.

read more

Legal exposure

18 U.S.C. § 1029 covers fraud and related activity in connection with access devices. Trafficking in card numbers carries a statutory maximum of 10 years in prison. Aggravated counts, including cases tied to financial institutions or repeat offenses, carry higher maximums of 15 to 20 years. Related charges in these cases include wire fraud and money laundering. Sentences include restitution to issuers and forfeiture of accounts, devices, and crypto.

How card data gets stolen

  • Skimming hardware attached to fuel pumps and ATMs.
  • Breaches at a merchant that stored card data outside PCI rules.
  • Phishing pages that copy a checkout screen.
  • Malware on a personal computer that reads saved card data.
  • Data sold by insiders at call centers and hotels.

Steps for cardholders

  1. Turn on transaction alerts in the bank app. Set the threshold at $1.
  2. Use virtual card numbers at merchants you do not know. Most large US issuers offer them.
  3. Check statements every week. Test charges of $1 to $3 often come first.
  4. Freeze the card from the app when a charge looks wrong. A freeze is faster than a phone call.
  5. Report the charge to the issuer. Federal law caps credit card liability at $50, and most issuers set it at $0.
  6. File a report at IdentityTheft.gov if the card data was used with your name or address.

Steps for merchants

  1. Do not store CVC, CVV2, or CID after authorization. PCI DSS Requirement 3.2 prohibits it.
  2. Tokenize card numbers so the real number never enters your database.
  3. Enable 3-D Secure for high-risk orders. It shifts chargeback liability to the issuer in many cases.
  4. Watch for BIN attacks: hundreds of small authorizations from one IP range in a short window.
  5. Check address verification and cardholder name on every order above your average ticket.

If you find card data for sale

Do not buy it, and do not test it. Testing a stolen card number is itself a violation of § 1029. Report the listing to the FBI Internet Crime Complaint Center, the FTC, and the card issuer whose BIN appears in the listing. Issuers can block a range before more cards are used.