Short answer
No legal marketplace sells CVV data for bitcoin. A CVV belongs to one cardholder and one card. Selling it is a federal crime in the United States. Listings on dark web forums that claim to sell CVVs are either criminal exchanges or scams that keep the bitcoin and send nothing. The FBI and the FTC both treat these listings as fraud operations, not storefronts.
What a CVV is
The card verification value is a short number printed on a payment card. Visa, Mastercard, and Discover print three digits on the back. American Express prints four digits on the front. The number does not live on the magnetic stripe or the EMV chip. PCI DSS rules bar merchants from storing it after a transaction finishes.
Why bitcoin shows up in these listings
Bitcoin moves across borders, settles in minutes, and can be reversed only if the receiver sends funds back. Those traits appeal to criminal sellers. The same traits cut the other way. The blockchain keeps a public record of every transfer, and US law enforcement has traced and seized funds from carding operations. Buyers who send bitcoin to an unknown seller have no chargeback right.
Legal exposure
18 U.S.C. 1029 covers fraud and related activity with access devices. Trafficking in card account numbers carries up to 10 years in prison for a first offense and up to 15 or 20 years for repeat or aggravated cases, plus fines. A conviction also blocks work in banking, payments, and many IT roles.
How cardholders protect themselves
- Keep the card in sight when paying at a counter.
- Use a virtual card number for online checkouts.
- Turn on transaction alerts in the card issuer's app.
- Do not read the CVV aloud on a call you did not place.
- Read statements each month and dispute unknown charges.
If card data leaks
- Freeze the card in the issuer's app or call the number on the back.
- Request a new card number, not just a new card.
- File a report at IdentityTheft.gov.
- Report the incident to the FBI Internet Crime Complaint Center.
Merchants have a separate duty. They should tokenize card data, drop the CVV after authorization, and run address verification on every order. Any system that stores a CVV after a sale fails PCI DSS and carries fines from the card networks.