My stories and experiences operating a no KYC crypto card business.
Working directly with issuers, watching programs get shut down, dealing with frozen funds, and exposing the real truth behind how these products actually work.
No KYC cards have been getting a lot of attention recently, especially after Off Grid started trending on the timeline. Credit where it’s due: their marketing is excellent, and it’s what pushed this topic into the mainstream.
Just look at some of the visuals and marketing graphics they’ve put out. From a branding and distribution standpoint, it’s easily A-tier. I genuinely wish them success.
That said, most of the discourse completely ignores how these products actually work, why they keep failing, and who ultimately bears the risk. I ran a no KYC card business. I dealt directly with issuers, program managers, compliance escalations, and frozen funds. What looks simple from the outside is anything but.
1. Why People Use No KYC Cards
The demand for no KYC cards is real, and it’s not just ideological. For many people, it’s about access. Russia is one example. Because of sanctions, a lot of everyday users are cut off from the global banking system. They can earn money and hold funds, but still can’t spend it abroad. In many cases, these users are willing to complete KYC, yet are turned away anyway. At that point, it becomes a dead end. No KYC cards turn into a temporary way to keep paying for everyday expenses.
Another reason is trust. A growing number of people simply don’t want to hand over their identity again. Between recent breaches at major providers like Coinbase, Ledger, Sumsub, and others, users have seen how often sensitive data leaks. Even people who are fully compliant are increasingly cautious about where their documents end up. For them, avoiding KYC isn’t about hiding. It’s about reducing exposure.
2. The Darker Side of Who These Programs Attract
A large share of high spenders on these no KYC card programs are fraudsters. No KYC is appealing because it’s often the only way to move crypto into the real world and spend it. This includes professional rug pullers, outright scammers, and organized criminal activity, much of it coordinated through Telegram. When a payment rail has weak identity rules, these users naturally gravitate there.
When I ran my no KYC card business, I had very different expectations at first. I assumed most of the demand would come from people trying to avoid paying high taxes on off-ramps. People earning in crypto who didn’t want to hand over fifty or sixty percent of their income just to use their own money. That felt understandable, and at the time, even respectable.
The reality was very different. A meaningful portion of the demand came from users who were clearly involved in scams or outright fraud. You start to see patterns quickly. The types of questions they ask. How they move funds. How aggressively they push limits. It became clear to me that I wasn't just helping regular people spend their money, rather helping bad actors do bad things.
That realization played a big role in why I ultimately shut the program down. I wasn’t comfortable servicing that kind of clientele. Not just from a legal perspective, but from a moral one. Even if you try to stay neutral, at some point you have to accept what kind of activity your product is actually enabling.
3. The Hard Constraint Everyone Ignores
Visa and Mastercard are regulated payment networks. They operate through licensed issuing banks bound by strict rules around identity, traceability, and liability. Every card that works globally is tied to an issuing bank. Every issuing bank must know who ultimately controls the account. There is no technical workaround for this. No app layer abstraction changes it. If a card works everywhere, it exists inside this system by definition. The rule is simple:
If you didn’t do KYC, someone else did, and whoever did the KYC owns the account.
4. How No-KYC Cards Actually Work
Most no KYC cards rely on corporate card programs. A company completes KYB with an issuer and becomes the customer on record. From there, it can issue cards to employees or authorized users without individual KYC checks. On paper, this is meant for legitimate business expenses. In practice, end users are quietly treated as “employees,” even though the product is marketed publicly as a consumer card. That’s the loophole. These are not consumer cards. They are business cards being resold. Unlike prepaid cards, corporate cards can hold large balances and have high limits. They are not designed to custody third party funds. They are fragile by nature and only survive until visibility increases.
5. My Experience Running One
Finding issuers was the hardest part of the business. Even fully regular KYC issuers would back out the moment the word "crypto" came up. Adding “no KYC” ended most conversations immediately. At one point, both my company and @solcardcc were using the same issuer, Interlace. At the time, Interlace was one of the largest providers powering no KYC card programs. Then their Visa program was temporarily paused. When that happens, everything breaks at once. APIs get shut off. Cards stop working. But the worst part is what happens to user funds. In our case, about $50,000 in user balances were frozen for six months. No warning. No clear timeline. No leverage. Users woke up unable to spend their money, and there was very little we could do besides escalate through compliance channels that move painfully slowly. From the user’s perspective, they were just stuck.
6. Why This Isn’t Really About Privacy
No KYC cards often get grouped into the broader privacy narrative. I don’t think that’s accurate. In practice, a large share of demand comes from users who are blocked elsewhere. If someone is willing to pay five percent just to off-ramp, it’s usually because they have no other option. That’s not ideology. That’s constraint. Real privacy infrastructure doesn’t require misclassifying users, abusing issuer structures, or hoping enforcement doesn’t arrive.
7. The Predictable Lifecycle
These programs don’t fail randomly. They tend to follow the same path every time. They launch quietly, early users report success, screenshots start circulating, and attention builds. Limits get raised, volume grows, and eventually visibility brings scrutiny. That’s when issuers or networks take a closer look, the BIN gets flagged, and the gap between how the card is marketed and how it’s actually allowed to operate becomes impossible to ignore.
I saw this play out firsthand. One issuer I worked with, which I won’t name out of respect for the people still working there, sent an email to all of their buyers and resellers asking them to stop marketing the card as “no KYC.” The reason was that their banking partner was starting to ask questions.
That moment genuinely shocked me. These were large fintech companies I had assumed were professional and compliant. Instead, they were openly enabling no KYC usage, while quietly asking partners to change the messaging so the scheme could last a little longer. It became clear that for some people, this wasn’t about innovation or privacy. It was a short-term cash grab that knowingly facilitated fraud and money laundering until enforcement arrived.
At that point, once a program is flagged, the ending is predictable. Either users are forced into KYC overnight, which breaks the original promise entirely, or the program is shut down. Cards stop working, balances are frozen, and support goes quiet while operators scramble behind the scenes. Users are left waiting with no clear timeline and no real recourse. In most cases, those funds are effectively gone. I was one of the few who got lucky. When my program was shut down with roughly $50,000 in user funds frozen, it took six months before the issuer refunded the balances. During that time, I took the heat from users, and it permanently damaged trust. Even when funds are eventually returned, the reputational cost doesn’t go away.
When users deposit funds into these systems, ownership often changes in a way most people don’t realize. Because these are usually corporate card programs, the user is never the legal owner of the account. The KYB verified company is. Users have no direct relationship with the issuing bank, no deposit protection, and no standing with Visa or Mastercard. When a program shuts down, operators can simply walk away. Legally, the funds were never the user’s to begin with. And many of the users affected are involved in activity they can’t openly defend, so there’s no realistic path to recovery. This is the core risk that almost never gets explained up front, and it’s why these shutdowns so often end with users permanently losing access to their money.
8. Why This Business Has No Long-Term Value
From an entrepreneur's standpoint, this is one of the hardest fintech businesses to run. Issuer churn is constant. Compliance risk is inevitable. Scale makes the product weaker, not stronger. From an investor’s standpoint, it’s even worse. No serious investor wants exposure to a business that can lose its rails overnight and freeze user funds through no fault of its own. There is no durable moat. No defensible distribution. No enterprise value.
As long as Visa and Mastercard sit underneath these products, unlimited no KYC spending is not possible. No amount of branding, clever messaging, or “privacy” framing changes how card networks operate or what issuers are required to enforce.
No KYC cards are easy to sell and hard to run. The gap between how they’re marketed and how they actually function is where most users get hurt. I’m sharing this because I’ve lived through it. If people are going to use these products, they should at least understand the risks before learning the hard way.
9. A Potential Path to Real No KYC Cards
There is one emerging approach that may actually enable no KYC spending in a structurally honest way. It’s being built by @colossuspay, founded by @josephdelong and it takes a fundamentally different path than existing crypto cards.
The system is still in development, with a launch expected later this year. Unlike traditional crypto cards, it does not rely on Visa or Mastercard rails. As @milianstx likes to put it, it breaks the "duopoly" of Visa and MC instead of pretending to work around it. The key difference is the integration point.
Rather than issuing cards through a bank and routing payments through card networks, Colossus integrates directly at the acquirer layer. There are only a small number of major acquirers globally, and they are embedded directly into merchant point of sale infrastructure. In this model, when a user taps a stablecoin card, the payment bypasses card networks entirely.
Stablecoins are sent straight to the acquirer, which converts them into whatever currency the merchant prefers. Settlement happens without issuing banks or the usual stack of intermediaries.
That structural change is what makes this approach different. It doesn’t depend on loopholes, misclassification, or delayed enforcement. By removing Visa and Mastercard from the flow, the usual KYC requirements tied to card issuance no longer apply in the same way.
It’s still early, and there are real challenges ahead, particularly around merchant distribution and integration. But conceptually, this is one of the first attempts at a no KYC payment instrument that isn’t fragile by design. If it works at scale, it represents a genuinely new category of crypto payments.
10. Shoutouts and Credits
Shoutout to @milianstx. He pushed me to write my first article on X and helped shape how I think about what real privacy actually looks like.
Check out his team at @Arcium, which focuses on building privacy at the protocol level rather than hacking around existing systems. That distinction matters more than most people realize.
A few more notable articles on this topic were also written by @mikulaja and @matveevp - highly recommend to give them a read as well!
I hope you were able to take something away from me sharing my experiences and lessons from running a no KYC card business. Thank you!