Selling CVV means offering stolen credit card numbers, expiration dates, and security codes to buyers on dark web shops or private messaging apps. It is a federal crime in the United States, and the seller rarely collects a dime before the account is flagged, the buyer disappears, or a law-enforcement officer answers the ad.
The CVV trade is not a quiet side hustle. It is a chain of stolen data that starts with a hacked merchant or a phishing victim, and every person who touches that data is building a federal case file.
The term CVV stands for card verification value. It is the three-digit code on most cards and the four-digit code on American Express, and it exists so the cardholder can prove they are holding the physical card.
Sellers in this space do not just offer the CVV. They package the full magnetic stripe or chip data, the cardholder name, the billing address, and sometimes the date of birth.
That bundle has a name in carding forums: a fullz. The more personal information attached to the number, the more a seller can ask, and the more serious the resulting charge of aggravated identity theft.
The person sending money is not usually the person who stole the card. Buyers are fraudsters who want to buy prepaid gift cards, designer goods, airline tickets, or cryptocurrency before the real cardholder sees the charge.
Sellers set prices by card type, country, and available balance. A typical U.S. card with CVV sells for $2 to $15. A fullz with detailed identity documents sells for $20 to $100, and premium corporate card data can go higher.
None of those numbers make sense when you measure the risk. A single sale can produce 30 years of federal exposure, but it pays about the same as a pizza delivery shift.
Sellers gather on dark web carding shops, Telegram channels, and forums that require an invitation or a vouch from an existing member. These marketplaces change domain names often and take a cut of each transaction.
No shop selling CVV is legitimate. The product itself is stolen, so there is no contract you can enforce, no customer service to complain to, and no legal way to settle a dispute.
Most sellers assume the Tor browser and Bitcoin make them invisible. They forget the details that betray them.
Marketplaces log server activity, and a single forgotten login without protection exposes an IP address. Withdrawal from a crypto exchange usually requires identification, and a seller who wants cash has to go through an automated teller or payment app that captures their face on camera.
Even before the money reaches a wallet, a buyer of stolen card data will often report fraud to their own bank or exchange to flip the loss. That report becomes a police file that names the seller's account.
Agents do not raid a dark web shop on day one. They let it operate while they gather transaction logs, seller usernames, and cryptocurrency addresses.
Undercover agents buy CVV data directly and record the seller's instructions for using it. They also monitor the seller's writing style, PGP key, and behavior across forums until the same pattern appears on a social media account with a real name.
When they move, teams often execute search warrants at the seller's home at the same moment the seller is logging in online. Devices seized in the raid contain chat histories, wallet files, and the card data used to prove the crime.
Prosecutors have wide latitude when they build a carding case. The most common charges come from access device fraud, wire fraud, and identity theft statutes found in Title 18 of the U.S. Code.
Access device fraud covers the possession, transfer, and use of unauthorized credit card data. Wire fraud applies every time the seller sends the stolen data through the internet, and aggravated identity theft carries a mandatory two-year addition if the seller used a real victim's identity information.
These charges stack. A seller who is indicted on ten counts of access device fraud and ten counts of wire fraud can face a sentence that makes parole a distant thought, even if the actual dollar loss is small.
First offense does not mean first warning. Federal district courts sentence sellers based on the loss amount, the number of victims, the sophistication of the scheme, and the seller's role in the group.
A reseller who only moved cards from a larger ring can still be held responsible for the entire loss that the stolen cards caused. Guideline calculations often treat the total projected loss from each card, not just the amount the seller personally pocketed.
Judges also order restitution to credit card issuers and victims. By the time asset forfeiture and legal fees are added, selling CVV can cost a person their savings, their vehicle, and their home before the prison sentence starts.
Real earnings are small and irregular. A seller moving cards at $10 each needs to complete hundreds of sales to earn anything close to a normal wage, and most sellers see their payment account frozen after the first few transactions.
No. Law enforcement has access to forum backups, crypto exchange compliance records, Telegram metadata, and victims who complain. The anonymity that sellers rely on disappears at the first cash withdrawal.
Access device fraud alone carries up to 10 years in federal prison for a basic conviction, and repeat offenses or crimes that involve financial institutions can bring up to 30 years. Wire fraud and identity theft are added when the facts fit, so actual sentences often exceed the minimum.
Compare the money with the outcome. A few hundred dollars in stolen card sales can produce a multi-count federal indictment, years in prison, and permanent criminal history that blocks housing and employment. The trade is not worth any price.
You will receive the digital voucher immediately.
All your data is transmitted with unbreakable SSL-RSA encryption.
You can give away, resell or keep the vouchers.
We are available for you 24 hours a day.
Be informed as soon as new vouchers are added or when there are discounts.