The short answer is that no legitimate marketplace exists for selling CVV codes or full card data, in bitcoin or in any other currency. Trading stolen payment card numbers is a federal crime in the United States under 18 U.S.C. 1029, which prohibits trafficking in access devices, and it carries additional exposure under wire fraud and identity theft statutes. The sites and chat channels that advertise this trade are criminal operations, and a substantial share of them exist mainly to defraud the people who contact them. If your interest is protecting your own cards, the practical material is below: how card data leaks, which signals show up early, and what to do when a card is compromised.

What the phrase actually refers to

A CVV or CVC is the three or four digit verification code printed on a card, used to confirm that the person entering a card number physically holds the card. In criminal forums, card data is bundled in formats described as dumps, fullz, or logs, depending on whether the package includes track data, billing addresses, or account credentials. None of these categories has a lawful resale channel. Banks, card networks, and payment processors do not buy or broker them, and merchants are contractually barred from storing CVV data after a transaction is authorized precisely to keep it out of circulation.

The legal exposure in the US

Trafficking in access devices is punishable by up to 10 years in prison for a first offense involving a single device, with higher maximums for larger schemes, and courts stack related charges for wire fraud, bank fraud, and aggravated identity theft. Bitcoin does not change the analysis. Blockchain analysis firms routinely trace flows, and US exchanges collect identity documents, so converting proceeds to cash generally creates a stronger evidence trail than it hides.

How card data reaches criminal channels

  • Skimming devices placed on fuel pumps, ATMs, and self-checkout terminals that copy magnetic stripe data.
  • Phishing pages and fake checkout flows that capture card numbers and codes in real time.
  • Breaches at merchants and processors where cardholder data was stored without adequate encryption.
  • Malware on a home or office computer that records keystrokes during online purchases.
  • Card testing attacks, where automated scripts submit thousands of small guesses against a merchant gateway to validate stolen numbers.

Thresholds and signals worth acting on

Most cardholders learn about compromise from a statement line, so set your own tripwires.

  • A single unauthorized charge under 10 dollars. Small amounts are used to test whether a card is live before larger purchases.
  • Two or more authorizations in the same hour from different merchants. That pattern suggests automated testing.
  • Any charge in a state or country you have not visited in the past 30 days.
  • A change of address, new card request, or password reset you did not initiate.
  • A credit report inquiry from a lender you have never contacted.

What to do when a card is compromised

  1. Freeze or lock the card in your banking app, then call the number on the back of the card to report fraud.
  2. Request a new card number rather than a replacement of the same number, since the old number stays exposed otherwise.
  3. Change the password on the merchant account and enable two factor authentication.
  4. File a report at IdentityTheft.gov if your personal information, not just the card number, was involved.
  5. Pull a free credit report and dispute anything unfamiliar.

Pitfalls and misconceptions

  • Bitcoin is not untraceable. Public ledger records plus exchange identity checks usually defeat the assumption.
  • Sellers of card data are frequently targeted. Common patterns include demands for an upfront deposit, fake escrow accounts, and card data that has already been canceled.
  • Virtual card numbers reduce exposure at one merchant but do not help if the issuing bank or processor is breached.
  • Debit cards offer weaker dispute rights than credit cards, so use credit for online purchases when possible.
  • Checking whether your own data appears in a breach is reasonable. Attempting to buy or verify someone else's card data is not, and it creates its own criminal liability.

FAQ

Is it legal to sell CVV numbers?

No. Selling or transferring card data you do not own is a federal offense in the US, and comparable laws exist in most other countries.

Can bitcoin conceal a card data transaction?

Not reliably. Chain analysis, exchange identity requirements, and device forensics give investigators multiple routes to a person.

Why do those sites ask for deposits or test cards?

Because many are advance fee scams. The deposit is the actual product being sold, and no working card data is delivered.

My card number appeared in a breach notice. What now?

Treat the card as exposed. Review recent statements line by line, set transaction alerts, and replace the card if you see anything unfamiliar.

Does a security key or passkey protect my card?

It protects your account logins, which blocks a common path to stored card data. It does not stop a skimmer at a fuel pump.