The short answer

There is no legitimate way to sell a CVV online. The three or four digit code printed on a payment card is not a product, and no licensed business brokers it. When a site claims to be a "legit CVV shop" with verified sellers, escrow, or refund guarantees, you are looking at one of two things: a scam that pockets the buyer's money, or a storefront moving stolen card data. Both are federal crimes in the United States under access device fraud and identity theft statutes, and both leave a payment trail that investigators can follow.

If you came here hoping to find a vetted marketplace, the honest answer is that the thing you are searching for does not exist. If you came here because someone offered to sell you CVVs, or because a charge showed up that you do not recognize, the sections below are the useful part.

What a CVV actually is

Card verification value goes by several names depending on the network. Visa calls it CVV2, Mastercard uses CVC2, American Express uses CID, and Discover uses a card identification number. Functionally they are the same idea: a short numeric value derived from the card number, expiration date, and a secret key held by the issuer, printed on the card but not encoded in the magnetic stripe or the chip.

That last detail explains the whole point. In a card-not-present transaction, a merchant cannot inspect the physical card, so the CVV acts as proof that whoever is typing the number is holding the plastic. It is an authentication signal, not a commodity.

Why the word "legit" falls apart

  • Nobody has a legal supply. Only the issuing bank can generate a valid CVV for a card. There is no wholesale channel, no distributor, no licensed reseller.
  • Merchants are barred from keeping them. PCI DSS treats the CVV as sensitive authentication data that must not be stored after a transaction is authorized. Any list of them in bulk came from theft, not a warehouse.
  • Escrow and guarantees are theater. In most of these operations the "seller" and the shop operator are the same person or the same small crew, and cardholders dispute fraudulent charges, which means the value evaporates.

I have read a lot of these pitch pages while researching card security, and they all lean on the same vocabulary: fresh, verified, high balance, non-VBV, checker included. That language exists to sound like a supply chain. It is not one.

How the offers reach people

Card data ends up for sale through phishing pages, skimmers on fuel pumps and ATMs, breaches at merchants that mishandled data, and social engineering aimed at people who will read a code over the phone. A stolen CVV is worth very little on its own, so it gets bundled with a card number into a package that looks tidy to a buyer. The people absorbing the damage are ordinary: a cardholder waiting on a replacement card, a small merchant eating a chargeback and the associated fee, and occasionally a buyer who paid in crypto for data that was already dead.

Red flags when someone pitches you

  • Contact only through Telegram, Discord, or a throwaway email, with no verifiable business identity.
  • Payment accepted only in cryptocurrency, gift cards, or a peer-to-peer transfer with no recourse.
  • Free sample CVVs offered to "prove" the shop works. Samples are bait, and they are often generated or already burned.
  • Claims of specific balances or of cards that bypass verification, which is a tell that the pitch is aimed at someone who does not understand how authorization works.
  • Constant availability and 24/7 support, which is a sales tactic rather than a sign of a real business.

Protecting your own CVV

Most of what keeps that code out of circulation is boring and effective.

  • Never read the code to an inbound caller, even one who claims to be from your bank's fraud department. Banks do not ask for it.
  • Use tokenized wallets and virtual card numbers when shopping online. The merchant receives a substitute number, and your real CVV stays with you.
  • Cover the keypad and the card when using an ATM or fuel pump, and check the card slot for loose or bulky hardware.
  • Turn on transaction alerts and review statements on a schedule rather than once a month.
  • Enable multi-factor authentication on retail and banking accounts so a stolen card number alone does not open a door.
  • Do not photograph your card and send the image to anyone, including a landlord, a marketplace buyer, or a "verification" service.

If your card data is already exposed

  1. Call the issuer, report the unauthorized charges, and ask for a replacement card with a new number. You are generally not liable for fraudulent charges on a credit card when you report them promptly.
  2. File a report at IdentityTheft.gov if your personal information was involved. It produces a recovery plan and the paperwork that creditors and police accept.
  3. Report online fraud to the FBI's Internet Crime Complaint Center so it enters the law enforcement dataset.
  4. Consider a fraud alert or a credit freeze with the major bureaus if the exposure went beyond a single card number.

Questions people ask

Is selling CVVs legal in any country?

No jurisdiction licenses the sale of payment card verification values. Penalties differ, legality does not. In the United States it falls under access device fraud and identity theft law.

What if a shop looks like a normal e-commerce site?

Presentation is cheap. A clean template and a support chat do not change where the inventory came from. If the product is card verification data, the inventory is stolen.

I want to sell the CVV from my own card to make money. Is that different?

It is still access device fraud, and it puts your account and your identity in the hands of someone who already demonstrated they will take what is not theirs. The usual outcome is a drained account and a fraud investigation that starts with you.

Where should I report a seller?

Your card issuer first, then IdentityTheft.gov and the FBI's IC3 portal. If you have an active listing or message thread, keep it, since it helps investigators connect cases.