· CRÉDIT (LE détroit)

1. What you are sold, and what actually exists

Type "no-KYC crypto card" into a search engine. You will find comparison sites, tutorials and promises: sign up with an email, deposit USDT, get a virtual Visa in five minutes, no ID required. Some sites advertise limits of $200,000 a day on nothing more than an email address.

The reality, documented by the more serious comparison sites in the sector, fits in one sentence: in 2026, a fully anonymous crypto card with bank-level limits no longer exists in any regulated market. Visa and Mastercard require identity verification on the issuer's side. A programme that does not comply loses its BIN sponsor and disappears. What the marketing calls "no KYC" actually covers four very different realities.

The nuance that matters. A site that claims "no KYC" without publishing a legal entity, an issuing bank, a BIN sponsor or a licence is not a privacy product. It is a product whose operator is unknown. For an analyst, the absence of information is itself the information.

Cardpilled's August 2026 guide flags a programme that publishes "no legal entity, issuing bank, BIN sponsor or licence" while presenting itself as a UK crypto service, with no FCA registration to be found, and whose advertised limits of $200,000 a day are "incompatible with any regulated prepaid programme". A February 2026 BitcoinKE case study on an African issuer concludes that these models "rely on legal loopholes and ambiguous issuing arrangements rather than genuine regulatory compliance".

2. The plumbing: who controls the taps

No fintech and no crypto startup issues a Visa or Mastercard itself. It rents a range of numbers, the BIN (Bank Identification Number), from a bank that is a member of the network. The OCC's Comptroller's Handbook, the US banking supervisor's manual, is unambiguous: "the bank that owns the BIN is also responsible for compliance with bank card association requirements, including for services provided by a third party." It is the bank, not the startup, that Visa and Mastercard sanction. That is the chokepoint of the whole system.

Why it is a chokepoint. The number of banks willing to sponsor crypto card programmes is small and concentrated in a few jurisdictions (the United States through fintech partner banks, Lithuania, Cyprus, Malta, the UAE, Singapore, Hong Kong). When one of them cuts off, dozens of "brands" vanish at once. The sudden shutdowns users experience are not accidents: they are the downstream consequences of a decision taken at the chokepoint.

Even without a selfie or a passport, the chain keeps a usable footprint. The issuer holds the email, the IP address, the history and the deposit wallet address. The network holds the merchant, the amount and the timestamp. The product sells anonymity towards the merchant. It does not sell anonymity towards the state.

3. The underestimated angle: the corporate-card loophole

The public debate is all about consumer cards. The real mechanism lies elsewhere, and it is disarmingly simple once you see it.

KYC and KYB do not verify the same thing

When an individual opens an account in the United States, Section 326 of the PATRIOT Act (the "Customer Identification Program") requires collecting their name, date of birth, address and an identification number. When a company opens an account, the requirements are functionally similar but apply to the entity: legal name, physical address, tax ID (EIN), formation documents. Since FinCEN's 2016 Customer Due Diligence rule, adopted after the Panama Papers, the beneficial owners, generally above 25% of the capital, and the controlling persons must also be identified.

Two details change everything. First, the obligation is to collect this information and form a "reasonable belief"; it does not require verifying each item against an independent source. Second, and this is the heart of the matter: once the company is a customer of a card programme, it can create cards for its "employees" or "contractors", generally without any further verification of those people or of the reality of their link to the company. The verified identity is the company's. The person paying at the till has never been identified by anyone.

Why this angle is underestimated

Because the vocabulary blurs the trail. We talk about "crypto" cards and "no KYC" as if it were a blockchain problem. It is not. The same mechanism works with dollars, without a single token. Crypto is merely the most convenient way to load the card: instant, cross-border, with no named bank account in between. The loophole itself sits in commercial-card law.

Because the corporate card is a legitimate, massive and useful product. Purchasing cards, fleet cards, single-use virtual cards for online advertising or bookings: businesses need them, and business neobanks (Slash, Brex, Ramp, Mercury in the United States, Qonto or Pliant in Europe) make them a selling point. A regime that blocked the issuance of "employee" cards without individual identification would break a normal use. That is precisely what makes the loophole durable: nobody wants to close it.

Because beneficial-ownership reporting has retreated. The Corporate Transparency Act of 2021 was meant to create a federal register of beneficial owners. In March 2025, a FinCEN interim final rule exempted domestic companies from the reporting obligation. Since a foreign national can set up a "domestic" LLC in Wyoming or Delaware in a few hours, the obligation has become, in Fintech Business Weekly's words, "functionally meaningless".

Because the risk hides at the seams. The bank that carries the liability outsources onboarding to the programme manager, which sometimes outsources to a reseller, which has its own customers. Each link runs "its" check. Nobody sees the chain. US regulators have a name for this: "Nth-party" risk. The banking agencies (Fed, FDIC, OCC) issued joint guidance on third-party risk management on 6 June 2023, explicitly aimed at fintech partnerships, and a wave of consent orders followed in 2023 and 2024.

The Slash case, or the legitimate architecture of the risk surface

The most emblematic case is not a shadowy operator, quite the opposite. Slash, a San Francisco business banking platform, became a unicorn in April 2026 after a $100m Series C. Its banking services are provided by Column N.A., an FDIC-insured bank. Slash reports more than 10,000 business customers, unlimited virtual cards with granular spend controls, native support for USDC and USDT, and a "digital-first" customer base ranging from affiliate marketing to e-commerce and the crypto industry. Its "Global Card" is presented as allowing "foreign business owners to access the US dollar without forming a US entity".

Editorial note. Slash is a regulated player backed by a US federal bank, and nothing in this report alleges any failing on its part. It is cited because it combines, in a perfectly legal and openly stated way, the three ingredients of the risk surface: remote onboarding, dollar access without a local entity, and unlimited card issuance. The question is not what Slash does. It is what a less scrupulous operator would do with the same architecture, and what the partner bank actually sees at the end of the chain. An independent survey in February 2026 did find Column BINs on "no-KYC" services: that is information about a banking-as-a-service bank's exposure to its many programmes, not about Slash, which is not mentioned anywhere in it.

4. A real chain, reconstructed

On 8 February 2026, the newsletter Fintech Business Weekly (Jason Mikula) published the only investigation we know of that relies on real test transactions and a full climb up the chain. The Paywithus case it documents is representative: five layers between the anonymous user and the regulated bank.

The cards lived less than two weeks and moved about $10,000. As soon as the journalist started asking questions, the BINs were cut and the site displayed "KYC now required", a check judged easy to bypass, since the service was offering cards from another US bank a few days later. A survey conducted in October 2025 and again in February 2026 found, on this type of service, BINs from five US issuers (Fifth Third Bank, The Central Trust Bank, Column, Regions Bank, Sutton Bank), from the card-issuing-as-a-service provider Rain (which says the card came from a verified user who resold it in breach of the terms), and, in Hong Kong, from Nium, Reap and Sunrate.

The most serious case involved a Ghana-based issuer whose sales page explicitly targeted users in Iran, explaining that its cards "work on international platforms where Iranian bank cards are declined because of sanctions". Its chief executive described the page as "a miscommunication by the content team".

What this says about the chokepoint. The bank never saw the end user. The programme manager never saw the reseller. The verified client was a shell whose cards were diverted. And the resale of a duly verified card (the Rain case) shows there is now a secondary market in validated identities: verification happens, then the card changes hands.

5. Anatomy of a scheme: how the laundering works

A generic reconstruction, assembled from FATF typologies and compliance-industry work. It describes no specific case. Its purpose is to show where a well-placed control breaks the chain.

The scale. According to TRM Labs, illicit entities received $141bn in stablecoins in 2025. According to Chainalysis, about $51bn was linked to fraud and scams in 2024. Cards are only one exit channel, but it is the one that touches retail commerce.

6. The regulatory wall, with dates

MiCA: the transition period is over

Regulation (EU) 2023/1114 requires crypto-asset service providers (CASPs) to verify identity at onboarding, monitor transactions continuously and screen permanently against sanctions lists. The transitional period for pre-existing providers expired on 1 July 2026.

AMLR: the ban, with a date

Regulation (EU) 2024/1624, adopted on 31 May 2024 and published on 19 June 2024, applies directly in all 27 member states from 10 July 2027. Its Chapter VIII, "measures to mitigate risks deriving from anonymous instruments", prohibits credit institutions, financial institutions and crypto-asset service providers from keeping anonymous accounts, and prohibits them from accepting payments made with anonymous prepaid cards issued outside the Union. Its Article 79 also covers accounts holding anonymity-enhanced crypto-assets. The recitals allow a possible exemption for certain low-value e-money products (gift cards), but "not from transaction monitoring". The European Anti-Money Laundering Authority (AMLA, Frankfurt) has been operational since 1 July 2025 and is publishing its technical standards throughout 2026.

Travel Rule: the global standard

Since 2019, the FATF has required providers to transmit originator and beneficiary information for virtual-asset transfers above a threshold (typically $1,000). Its seventh targeted update, published on 16 July 2026, finds that 83% of surveyed jurisdictions have enacted legislation, up from 73% in 2025, with eleven more in progress.

United States: the guidance exists, enforcement comes in waves

The interagency guidance of 6 June 2023 (Fed, FDIC, OCC) on third-party relationships covers the whole lifecycle of a partnership: planning, due diligence, contracting, ongoing monitoring, termination. OCC Bulletin 2011-27 governs prepaid access programmes. But the example of Sutton Bank, under a consent order since February 2024 and whose BINs were still circulating on "no-KYC" services two years later, shows that guidance is not enough without sanction.

7. What could be put in place

A ban is not enough: the AMLR prohibits the anonymous card, not the "employee" card of a verified company. The dominant mechanism stays open. Here, actor by actor, are the measures that would actually close the loophole. None requires new technology; all require a will that the current business model does not reward, since every link earns money on every transaction, licit or not.

The three measures that would change everything

1. Data flow-back to the bank. The cheapest and most effective measure. Today, the bank carrying the liability sees an entity and transactions; it does not see the cardholders. A contractual clause requiring transmission of each cardholder's identity to the BIN sponsor, with audit rights, would make the chain visible to the party responsible for it. The 2023 and 2024 consent orders already require this in substance; what is missing is generalisation.

2. The cards-to-headcount ratio. A trivial indicator, absent from most frameworks. A three-person company issuing fifty virtual cards is not necessarily fraudulent (an advertising agency may well do that), but it deserves a question. Programme managers have this data in real time.

3. Verification, not mere collection, of the beneficial owner. As long as US law is satisfied with a "reasonable belief" formed on documents supplied by the customer, the Wyoming shell will remain an entry point. This is the only point that falls to the legislator, and it is the one that retreated in March 2025.

What a good framework would do. It would not ask for one more selfie. It would cross-check three things that "no-KYC" cards make visible despite themselves: the on-chain origin of funds at deposit, the issuing and loading behaviour (ratio, velocity, fragmentation), and the destination of spending (merchant coherence). KYC verifies an identity once. KYT verifies a behaviour continuously. On this product, it is the latter that breaks the scheme.

8. A compliance analyst's grid

Customer-level signals (KYB / KYC)

  • Company registered in a jurisdiction with no public beneficial-ownership register, or in a low-transparency US state with a foreign beneficial owner

  • Declared beneficial owner with no apparent link to the business (nominee); the same people behind several same-named entities in several countries

  • Declared activity in a high-risk vertical (affiliate marketing, gambling, adult, gift-card resale)

  • Card issuance request disproportionate to headcount; API creation from day one

  • Account funded exclusively in stablecoins from a non-licensed processor

Transaction-level signals (KYT)

  • Deposit wallet within three hops of a mixer, a darknet market or a sanctioned address

  • Loads split just below thresholds, repeatedly; abnormal velocity

  • The programme's own BINs appearing on a resale site

  • Spending concentrated at one or two merchants, outside sectoral coherence; MCC inconsistent with the declared activity

  • Usage geolocated in countries where the programme is not meant to operate, or under sanctions

The three-question reasoning

Who holds the ledger? If the fintech and the partner bank each keep a register, which one prevails? The Synapse precedent shows the answer is not always clear.

Who carries the obligation? The BIN sponsor carries network liability; the CASP carries MiCA liability; the institution carries AMLR liability. When these three entities differ, blind spots arise at the seams.

Where is the exit point? Crypto exits at a merchant, an OTC broker or a bank. The most effective control is often the acquiring bank's, not the issuer's.

9. Voices worth listening to

REVENIRn!!!!!

10. Open questions and blind spots

1. A ban displaces, it does not remove. On 10 July 2027, the anonymous prepaid card issued outside the EU can no longer be accepted in Europe. But the complicit merchant can be outside the EU, and the "employee" card of a verified company is not anonymous within the meaning of the text. The dominant mechanism survives the ban.

2. The secondary market in verified identities. The Rain case shows a duly verified card resold to a stranger. KYC happened; it no longer protects anything. It is a sign that one-off verification has reached its limit and that only continuous behavioural monitoring can keep up.

3. Bank stablecoins will reshuffle the cards. Twenty-one banks announced on 1 September 2026 their own stablecoin for 2027. A token issued by Citi or Deutsche Bank will be freezable, traceable, and probably unusable for loading an offshore card. What share of the market migrates to regulated stablecoins, and what share takes refuge in the "freeze-resistant" stablecoins the FATF has seen emerge?

4. The chokepoint is not where you expect it. Everyone tries to regulate the card issuer. The most effective control point is the BIN sponsor upstream and the acquiring bank downstream. Two low-visibility, concentrated actors, with every interest in cooperating to keep their network access.

5. Legitimate privacy exists, and it has a cost. Some users of these cards launder nothing: journalists, dissidents, people living under authoritarian regimes, citizens who refuse to multiply the databases holding their passport. Any honest reflection on proportionality has to say so.

6. KYC is a photograph; crime is a film. Verification happens once. Laundering unfolds over time. Blockchain analytics and behavioural monitoring are the skills compliance teams lack most in 2026.

KRAKEN

The end of US

  1. 11 septtwin tower
  2. 15 sept Operation
  3. 21 Financial crash

MATHEW

Read on Substack
8%Danger
4%Life
9%pizza(Margarita)

Source: Reuters