The short answer
No legitimate business sells CVV or CVC codes for PayPal. The phrase describes criminal carding marketplaces, and the people behind most listings are running a scam inside a scam. If someone offered to sell you a card code so you could fund a PayPal account or push money through one, they want your crypto, your account, or both. Walk away and report it.
If you landed here because you want to protect your own card, the useful part starts two sections down. The mechanics of these listings are worth understanding first, because they explain why the whole market is a losing bet for everyone who touches it.
What those listings actually are
A CVV is a three or four digit code printed on a card. It exists so a merchant can prove the person checking out is holding the physical card. That makes it valuable to a thief and useless to a legitimate buyer. Nobody can resell it without committing a crime, which means every shop promising bulk codes is operating outside the law from its first transaction.
Common patterns in these listings:
- Storefronts that take crypto or gift cards and vanish after payment
- "Checkers" and balance tools that return random errors and blame the card
- Escrow accounts run by the same person selling the data
- Test charges against your own payment method, which then gets flagged
The buyers get burned as often as the cardholders. Read through any fraud forum long enough and the loudest thread is always someone who paid and got nothing.
The legal picture in the US
Buying or selling stolen payment credentials is not a gray area. Federal prosecutors charge it as access device fraud, wire fraud, and identity theft, and those charges stack. Sentences in carding cases routinely include prison time plus restitution, and the restitution follows you after release. PayPal's Acceptable Use Policy bans transactions tied to stolen financial instruments. Accounts get limited, balances get held, and the activity gets reported.
There is also a quieter cost. Law enforcement watches these marketplaces, and so do the card networks. Being a customer of one puts your name in a data set you did not choose to join.
How PayPal and the card networks block this
Payments at scale are not secured by the CVV alone. Tokenization swaps the real card number for a one-time or merchant-specific token, so a breach at one store does not hand over anything reusable. 3-D Secure adds a step-up check on risky orders. When you pay with a PayPal balance or a linked bank, the merchant never sees your full card data at all.
The card industry's own rules reinforce this. PCI DSS forbids storing the CVV after a transaction is authorized, which is why a stolen code has a short shelf life and merchants that keep it are the ones that get fined.
Keeping your own CVV out of these lists
- Never type the code into a site you reached from an ad, a text, or a DM
- Cover the back of the card when taking photos of it for any reason
- Use virtual card numbers for subscriptions and unfamiliar merchants
- Turn on transaction alerts so a test charge shows up the same minute
- Skip saving cards in browser autofill on shared devices
Small habits matter more than any single tool. Most card data ends up exposed through a skimmed terminal, a fake checkout page, or a screenshot someone forgot about, not through a sophisticated attack.
If your card number is already out there
Call the number on the back of your card and ask for a replacement with a new number. You are not liable for fraudulent charges on a credit card in the US, and debit card protections apply too, though the clock matters. Then file a report with the FTC and the FBI's Internet Crime Complaint Center. Both feed data that investigators actually use.
One last point about the search that brought you here. If you were looking for a supplier, the honest answer is that the market does not work the way the ads claim. There is no reliable vendor, no protection, and no exit that does not involve a fraud charge. If you were looking for protection, the checklist above is the whole game.