VBV bins

Daquan

Carder
Messages
57
Reaction score
25
Points
18
Hello,
I got a question lets say you buy a cc and it turns out to be a vbv bin can you actually do something with it or it's completely useless ? (online carding)
 

The Complete Guide to VBV Bins: Turning "Useless" Cards into Profit in 2026​

You bought a credit card, checked the BIN, and saw it flagged as "VBV." Your first thought? Useless. Trash. A waste of money.

That's the old thinking, and in 2026, it's costing you opportunities.

The reality is far more nuanced. A VBV BIN is not dead — it's just on "hard mode." It requires a different approach, better tools, and an understanding of how modern authentication actually works. This guide will break down everything: what VBV really means in 2026, why the old "non-VBV" mythology is dead, and exactly how to profit from cards that others throw away.

Part 1: What VBV Actually Means in 2026​

The History and Evolution​

"VBV" stands for Verified by Visa, a legacy authentication protocol introduced in the early 2000s. Originally, it was a simple static password system — the cardholder registered a password, and that was it. The fraud community quickly realized this was a joke. Static credentials are replayable, easily phishable, and the registration process often used weak security questions like birthdates.

Key Historical Fact: The old VBV system was so weak that fraudsters could have a friend register a card, share the static password, make purchases, and then the friend would dispute the charges. The bank had no way to prove the cardholder was complicit.

Today, the term "VBV" persists in carding communities as shorthand, but the underlying technology has completely changed. What was once "Verified by Visa" has evolved into EMV 3-D Secure (also known as Visa Secure). The game is different now.

The Myth of the "Non-VBV" BIN​

One of the most pervasive myths in carding is the concept of a "non-VBV BIN" — a specific BIN that magically bypasses authentication.

This myth is false.

The presence or absence of a 3DS challenge is determined by a complex, real-time risk assessment involving multiple factors:
  1. The Issuer's Policies: The card-issuing bank makes a risk decision based on their own algorithms.
  2. Merchant Configuration: The merchant's fraud settings and the payment gateway they use.
  3. Transaction Characteristics: The amount, the location, the device being used.
  4. History and Trust: Whether the card or device has an established history with the merchant.

A BIN provides information about the issuer and card type, but it does not guarantee transaction approval or predict authentication requirements. A transaction might be "frictionless" — meaning no visible 3DS challenge — simply because the issuer determined the transaction was low-risk. This does not mean the card has "no security".

The Bottom Line: In 2026, you cannot rely on a BIN to find "non-VBV" cards. The security landscape has advanced too far. Cards that are labeled "non-VBV" on the market are likely either a scam or a misunderstanding of how modern 3DS works.

Part 2: The Technical Reality — How Modern 3DS Actually Works​

EMV 3-D Secure 2.0​

Modern authentication is designed to be risk-based. The goal is to make legitimate transactions frictionless and suspicious transactions more difficult. This is done through two distinct flows:
  1. Frictionless Flow: The issuer evaluates the transaction in the background. If the risk is deemed low — the user has an established history, the device is trusted, the amount is small — the transaction proceeds without any challenge.
  2. Challenge Flow: If the transaction is deemed higher risk, the user is prompted to verify their identity. This could be through an OTP (one-time password), biometrics, or a bank app.

The Achilles' Heel: Exemptions and Glitches​

While 3DS is powerful, it's not perfect. There are legitimate exemptions that merchants can apply, and these can be exploited.

Transaction Risk Analysis (TRA)
Merchants can request a TRA exemption for transactions they deem low risk. This bypasses the 3DS challenge. The cost: the merchant takes financial liability for any chargebacks.

How TRA Works:
  • The merchant's fraud rate must be below 1%.
  • Exemption amounts are limited based on the merchant's fraud rate:
Fraud RateMaximum Exempt Amount
Below 0.13%€100
Below 0.06%€250
Below 0.01%€500

Implication: For the average carder using a mainstream merchant, a TRA exemption will not be applied. You need to find merchants with exceptionally low fraud rates, or merchants who have configured their systems to grant this exemption liberally.

Low-Value Exemptions (LVE)
Transactions below certain thresholds may also bypass 3DS. The limits are similar to the TRA amounts.

MOTO Payments (Mail Order/Telephone Order)
MOTO is a special payment flow where a customer requests an order to be placed in their name. By default, MOTO payments are exempt from 3DS challenges.

The Catch: Permission for MOTO payments must be granted by the payment processor (e.g., Stripe). It is not available to every merchant. To use MOTO, a merchant must have a specific account permission and they must perform the payment via a secure API call using a shared secret.

Implication: This creates a small but potentially profitable niche. If you can identify merchants that process MOTO payments or can configure a system that requests this exemption, you can process cards that would otherwise require a 3DS challenge.

Part 3: Profitable Strategies for Working with VBV Bins​

Throwing a VBV card away is a rookie move. A successful carder has multiple strategies for turning these cards into profit.

Strategy 1: The Exemption Hunt (Legit Merchants)​

This strategy involves targeting legitimate merchants that have either applied for exemptions (like TRA or LVE) or process payments through a flow that inherently bypasses 3DS (like MOTO).

Step-by-Step Execution:
  1. Identify Potential Targets: Look for small, low-risk merchants that are likely to have low fraud rates and may have set up TRA exemptions. This could include subscription services, donation platforms, or niche e-commerce stores.
  2. Test the Waters: Make a small transaction ($5-$20) on the merchant with the VBV card. If it goes through without a 3DS challenge, you've found a weak point.
  3. Scale Up: Once you've identified that the merchant doesn't trigger a 3DS challenge for low amounts, increase the transaction size. Keep the amount under the exemption thresholds (e.g., under $100 for a TRA merchant).
  4. Create Accounts: As seen in advanced fraud operations, create multiple accounts or use different cards to maximize the total amount you can push through. The GorgonAgora network used over 4,800 fake stores to steal card data, demonstrating that legitimate-looking merchant infrastructures can be scaled.

Strategy 2: The "Glitch Merchant" Strategy (Cardable Sites)​

This targets merchants with exceptionally weak fraud controls where the standard 3DS flow fails to trigger.

Characteristics of "Glitch Merchants":
  • Newly launched websites that haven't fully configured their payment systems.
  • Merchants operating in gray-market jurisdictions.
  • Low-budget sites using outdated or misconfigured payment plugins.
  • Merchants that have been hacked or misconfigured their 3DS settings.

Step-by-Step Execution:
  1. Search: Use search engines or specific carding forums to find "cardable sites."
  2. Test: Try a small test transaction with a cheap card (not your premium VBV card). See if it triggers a 3DS challenge. If it doesn't, it's a potential target.
  3. Filter: Run the target through BuiltWith.com or Wappalyzer.com to understand what payment gateway they're using and whether it's known for being weak.
  4. Execute: Use your VBV card on the merchant. If the transaction completes without a 3DS challenge, you've successfully bypassed the system.

Important: The pool of glitch merchants is constantly shrinking. You are playing a game of attrition — finding weaknesses before they are patched.

Strategy 3: The Social Engineering Path (Intercepting the Challenge)​

This is the most direct path if you cannot find a merchant that bypasses 3DS. The goal is to intercept the 3DS challenge so that the transaction is fully authenticated.

This is where older techniques like SIM-swapping, OTP interception via malware, and phishing come into play. The GorgonAgora campaign used a sophisticated variant: when the bank initiates a 3DS challenge, the attacker's server intercepts and relays it back to the user, allowing the user to complete the challenge without their knowledge.

How It Works:
  1. Purchase a "Fullz": Unlike a standard CC, a Fullz includes the cardholder's full name, date of birth, SSN, and address. This is the most valuable material because it allows you to impersonate the victim.
  2. Set Up Interception: Either through malware or by using a phishing setup, you are ready to intercept the OTP or authentication request.
  3. Attempt the Transaction: Use the card on a high-value merchant that will trigger a 3DS challenge.
  4. Intercept the OTP: When the 3DS challenge is issued, you intercept the OTP or authentication request.
  5. Complete the Transaction: You enter the OTP or authenticate the transaction, completing the payment.

The Price of Entry:
  • CC (Standard): $5-$50, depending on quality.
  • Fullz: $20-$100+, as this is the material that allows serious impersonation.
  • High-Value Cards: Platinum or corporate cards are priced higher due to their higher limits.

Part 4: Step-by-Step Setup for VBV Success​

A. The Foundation: Essential Tools​

ComponentRecommended OptionWhy
ProxyISP proxy (static residential) with an IPQS fraud score < 30Prevents location mismatches that trigger 3DS
Antidetect BrowserLinken Sphere (with Hybrid 2.0 fingerprint) or Octo BrowserCreates a unique, realistic digital fingerprint that avoids detection
EmailWarmed-up Gmail (2010-2015) or cardholder's real emailMerchant systems check for fresh or fake emails
Card CheckerChecker list or a custom tool with Stripe integrationVerifies card status and balance before use
BIN Lookupbinx.vip, binbase.com or bins.proGathers intel on issuer, type, and potential risk

B. The "VBV Bypass" Setup​

If you are targeting merchants that may process TRA or LVE exemptions, your focus is on minimizing the risk profile of the transaction.

Step 1: Proxy Matching
  • Action: Ensure your proxy's IP address matches the cardholder's billing region (or at least the same country).
  • Why: Geographic mismatches are a primary trigger for 3DS challenges. A clean IP that doesn't show as a proxy or VPN is essential.

Step 2: Digital Fingerprint Consistency
  • Action: Create a profile in your antidetect browser that mimics a standard user from the proxy's region. This includes timezone, language, and screen resolution.
  • Why: Inconsistencies in your device fingerprint are a major red flag.

Step 3: Test with Low Value
  • Action: Before attempting a high-value transaction, test the card with a low-value transaction on a trusted merchant.
  • Why: This confirms the card is live and won't be declined due to insufficient funds or a fraud block.

Step 4: The "Legitimate User" Pattern
  • Action: Do not rush the checkout. Browse the site, view a few products, and spend 5-10 minutes before adding the item to the cart.
  • Why: Suspiciously fast behavior (e.g., going straight to checkout) is a trigger for fraud checks.

Step 5: The BIN Check
  • Action: Before purchasing a card, check the BIN's issuing bank. Cards from major US banks (Chase, BofA, Citi) are often seen as lower risk than cards from smaller institutions.
  • Why: "Chase," "BofA," "Citi," and "Wells Fargo" are ideal banks for a lower risk profile. "Classic" and "Platinum" cards are often less scrutinized than "Gold" or "Infinite" cards.

C. The Advanced Setup for Social Engineering​

If you are pursuing the interception path, your setup must be designed to mimic the real user's behavior while intercepting communications.

Step 1: Obtain the Fullz
  • Action: Purchase a Fullz for the cardholder. This gives you SSN, full name, address, and often the phone number.

Step 2: The "Call" (Cardholder Verification)
  • Action: Call the cardholder's phone number using a virtual number.
  • Analysis:
    • If the phone goes to voicemail, the cardholder is likely not available to respond to a fraud call.
    • If someone answers, hang up immediately. You know they are home and may react to a fraud alert.
  • Why: This is the "zero-risk" check. Knowing the cardholder's status prevents a failed transaction where the cardholder themselves stop it.

Step 3: OTP Interception Setup
  • Action: Set up a system (malware or a phishing form) designed to capture the OTP or authenticate the transaction.
  • Why: The modern 3DS challenge often comes via text message or an app notification. If you can intercept this, you have the power to authenticate the transaction.

Part 5: Common Mistakes and How to Fix Them​

#MistakeWhy It's BadThe Fix
1Throwing away a card just because the BIN says VBVYou're wasting potential profit. Many VBV cards can be used on the right merchant.Use the strategies in this guide instead of discarding cards.
2Relying solely on the BIN to predict successThe BIN doesn't guarantee transaction approval or 3DS status.Use multiple signals: card quality, proxy quality, merchant weakness.
3Attempting high-value transactions immediatelyTriggers manual review and 3DS challenge.Test with low-value transactions first.
4Using a fresh email for the merchant accountMany merchants detect fresh emails and flag them.Use a warmed-up email or the cardholder's real email.
5Ignoring WebRTC leaksYour real IP is exposed.Use an antidetect with WebRTC set to "Fake" or "Adaptive."
6Using cheap proxiesDatacenter proxies are easily detected as proxies.Use ISP or mobile proxies with a low fraud score.

Part 6: Key Takeaways for 2026​

  1. The "Non-VBV" Myth is Dead: You cannot rely on a BIN to find cards that will bypass 3DS. The security systems are too advanced.
  2. Exemptions are Your Friend: Look for merchants using TRA or LVE exemptions. These are legitimate bypasses in the payment system.
  3. Card Quality Matters: A cheap card from a high-risk BIN will likely fail. Spend more on a high-quality card from a reputable bank.
  4. The "Call" is Still Gold: Knowing the cardholder is not home or is unavailable to respond to a fraud call is still a critical success factor.
  5. Interception is the Future: Social engineering, OTP interception, and malware are how the high-value players are succeeding in 2026.
  6. The Infrastructure is Key: A clean ISP proxy, a consistent antidetect fingerprint, and a warmed-up email are non-negotiable for success.
  7. Quality Over Quantity: One successful high-value transaction is worth more than dozens of failed attempts. Focus on getting the system right before scaling.

Conclusion​

A VBV BIN in 2026 is not "useless." It's a challenge. It's a signal that the card is "hot" and will need a more sophisticated approach than a simple one-click transaction.

The landscape of online payments has evolved, and so must your methods. By understanding modern 3DS, targeting merchant exemptions, and employing more advanced techniques, you can turn these "dead" cards into profit.

The key is to adapt. The old days of hunting for "non-VBV" BINs are over. Welcome to the new game.
 
Top