Setting Up Crypto Purchase via Bank Card
Many crypto startups want to add card on-ramp, but face fraud and chargebacks. This is the toughest unit on any crypto exchange. It's not just plugging in Stripe — you need a combination of 3DS2, velocity checks, device fingerprinting, and aggressive chargeback management. A mistake at any step leads to merchant account suspension and losses. Let's break down a production solution we implemented for an unnamed exchange, which keeps the chargeback rate below 0.5%. Proper setup minimizes risks and boosts payment conversion. Contact us for an assessment of your project — we'll calculate an individual architecture.
How to Choose an On-Ramp Provider?
Choosing a payment processor is key. All three leaders work for crypto, but with nuances:
| Provider | Crypto Specifics | Fee (approximate) | Chargeback Protection |
|---|---|---|---|
| Stripe | Ready-made tools, Radar for fraud | 2.9% + $0.30 | Built-in dispute management |
| Adyen | Flexible rules, own acquiring | 2.5% + $0.20 + individual | Advanced custom rules |
| Checkout.com | Best rates for high volume | from 1.8% + $0.20 | Dedicated fraud analyst team |
For a start, we recommend Stripe — fast integration, but when you reach high monthly turnover, move to Adyen or Checkout.com. More about MCC can be read on Wikipedia.
Why 3DS2 Is Not an Option, but a Necessity?
3D Secure version 2 is mandatory in the EU (PSD2 SCA) and de facto standard for reducing chargeback risks. Stripe automatically shows a popup if authentication is required. Here's an example of client-side code using Stripe Elements:
// Stripe Elements + 3DS2
import { loadStripe } from '@stripe/stripe-js';
const stripe = await loadStripe(process.env.STRIPE_PUBLIC_KEY);
async function handleCardPayment(cardElement, amount, currency, walletAddress) {
// Create PaymentIntent on server
const { clientSecret } = await fetch('/api/create-payment-intent', {
method: 'POST',
body: JSON.stringify({ amount, currency, walletAddress })
}).then(r => r.json());
// Confirm payment with 3DS if required
const { paymentIntent, error } = await stripe.confirmCardPayment(clientSecret, {
payment_method: {
card: cardElement
}
});
if (error) {
return { success: false, error: error.message };
}
if (paymentIntent.status === 'requires_action') {
// 3DS challenge — Stripe automatically shows popup
// After completion Stripe returns updated paymentIntent
}
if (paymentIntent.status === 'succeeded') {
return { success: true, paymentIntentId: paymentIntent.id };
}
}Server side: creating PaymentIntent with metadata for tracking and forced 3DS:
Server-side code example
import stripe
stripe.api_key = settings.STRIPE_SECRET_KEY
@app.post("/api/create-payment-intent")
async def create_payment_intent(request: PaymentRequest, user: User = Depends(get_current_user)):
# Validation
if request.amount < 10:
raise HTTPException(400, "Minimum amount is 10")
if request.amount > user.daily_limit_remaining:
raise HTTPException(400, "Daily limit exceeded")
# Create PaymentIntent with metadata
intent = stripe.PaymentIntent.create(
amount=int(request.amount * 100), # in cents
currency=request.fiat_currency.lower(),
metadata={
"user_id": str(user.id),
"crypto_currency": request.crypto_currency,
"wallet_address": request.wallet_address,
"order_id": str(uuid.uuid4()),
},
# Mandatory for SCA compliance in EU
payment_method_options={
"card": {"request_three_d_secure": "automatic"}
}
)
return {"clientSecret": intent.client_secret}According to Stripe Docs, 3DS2 reduces chargebacks by 50% compared to the first version. You can see details in the Stripe documentation.
How to Build a Fraud Prevention Pipeline?
Crypto card transactions have high fraud risk. Our standard pipeline includes several layers:
| Layer | Technology | Example Rule |
|---|---|---|
| Velocity | Limits per card, IP, account | No more than 3 transactions from a card within 24h, no more than 5 cards from one IP per week |
| Fingerprinting | Device ID, browser fingerprint | One device, different accounts — flag |
| AVS | Address verification | Compare billing address with bank |
| Email/phone | Contact confirmation | First purchase only after verification |
| Delayed delivery | Delayed payout | First 1-3 transactions delayed 24-48 hours |
Stripe Radar for Automatic Fraud Filtering
# Custom rules in Stripe Radar via metadata
intent = stripe.PaymentIntent.create(
...
metadata={
"account_age_days": str((datetime.now() - user.created_at).days),
"total_purchases": str(user.total_purchases_count),
"kyc_verified": str(user.is_kyc_verified),
}
)
# In Stripe Dashboard add Radar rules:
# BLOCK if account_age_days < 3 AND amount > 200
# REVIEW if total_purchases < 2 AND amount > 500
Stripe Radar reduces chargebacks by 30% more effectively than standard rules. The fee savings can be significant at high turnover.
How to Manage Chargebacks for Crypto Payments
When a card chargeback occurs, our engineers with 5+ years of experience in crypto payments follow this protocol:
- Automatically block the user's account
- Freeze crypto transfers if not yet delivered
- Gather evidence for dispute: IP logs, KYC data, blockchain confirmation
- Submit representment through the payment processor
Stripe provides a tool for evidence collection. Winning disputes require: KYC verification screenshot, IP match with geolocation, blockchain proof of crypto delivery, and wallet ownership confirmation via signature. Average chargeback rate for crypto payments: 0.5–2%. For Stripe, this means risk of losing the account if it exceeds 1%. Therefore, aggressive fraud filtering is more important than conversion. Get a consultation on dispute management setup.
What's Included in Setting Up Crypto Purchase via Card
- Integration of payment processor (Stripe/Adyen/Checkout.com) with PCI DSS compliance
- 3DS2 and SCA rule configuration
- Development of fraud prevention pipeline with velocity, fingerprinting, AVS
- Connection of KYC service (Onfido, Jumio)
- Implementation of delayed delivery for new users
- Chargeback monitoring and dispute management setup
- API documentation and team training
- Testing of each stage in Staging and Production
We guarantee the chargeback rate will not exceed 1% after setup. Order integration today and get a detailed implementation plan.







