Working with cards without AVS: where to look and how to use

Good Carder

Professional
Messages
1,014
Reaction score
692
Points
113
From carder to carders. AVS (Address Verification System) is the main barrier for carders in the US. The system checks the billing address you enter against the address stored by the issuing bank. If the ZIP code or house number doesn't match, the payment fails with an avs_failure or zip_code_mismatch error. But not all cards pass AVS. Some BINs don't verify the address at all because the issuing bank doesn't support this system, or the gateway disables it.

In this article, I'll explain which BINs don't verify the address, where AVS is disabled or only works pro forma, how to select a ZIP code to bypass it, and provide a practical list of BINs that don't use AVS for 2026–2027. No fluff — just what really works.

Part 1: Why AVS Doesn't Check Some Cards​

AVS works by comparing the numeric portion of the address (house number) with the ZIP code. If both match, the answer is Y (payment is processed). If not, the answer is N (rejected). However, AVS is an American system. It doesn't work with cards issued in countries without ZIP codes or where banks don't submit address data to processing.

There are three reasons why AVS doesn't check a card:
  1. The issuing bank does not support AVS. Many banks outside the US (especially in Europe, Asia, and Latin America) do not participate in the AVS system. For them, address verification simply does not exist.
  2. The card is prepaid or virtual. Prepaid cards (Vanilla, Netspend, Green Dot) and virtual cards (Privacy.com, Revolut, RedotPay) are often not linked to a physical address. The issuing bank does not store the cardholder's address, so AVS returns a U (unavailable) or G (non-US issuer) response.
  3. The gateway disables AVS for certain BINs. Some merchants and payment gateways disable AVS for cards of certain countries or types to avoid losing customers.

For the carder, this means: if you use a card without AVS, you don't need to know the cardholder's exact billing address. You can enter any ZIP code (or even leave the field blank), and the payment will still go through.

Part 2. Which BINs don't check the address?​

Based on an analysis of BIN ranges, success/failure logs, and data from closed sources, here are the BIN categories where AVS either doesn't work or only works in a rudimentary manner.

2.1. Non-US BIN (cards issued outside the US)​

AVS is a US-based system. For cards issued in Europe (UK, Germany, France), Asia (Japan, China, India), Latin America, and other regions, AVS is either not supported or returns a G response (non-US issuer). In most cases, the payment gateway simply ignores AVS for such cards.

Working BINs for 2026–2027:
PageBIN (first 6 digits)Bank/IssuerType
United Kingdom414910, 414919BarclaysCredit
United Kingdom539101, 539102HSBCCredit
Germany440768, 440657North German State Bank / Savings BanksCredit
Germany437871Deutsche Card ServicesCredit
Canada450601, 450602Royal Bank of CanadaCredit
Australia431830, 431831Commonwealth BankCredit
France497790, 497791BNP ParibasCredit

These cards pass through American sites without address verification because AVS is either unavailable for them or returns a response that the gateway ignores.

2.2. Prepaid и Gift Cards (Vanilla, Netspend, Green Dot)​

Prepaid cards are often not linked to an address. The issuing bank doesn't store the cardholder's billing address, so AVS returns "U" (unavailable) or "N" (no match). Many gateways by default process such cards without AVS verification.

BINs for prepaid cards without AVS:
TypeBIN (first 6 digits)Issuer
Vanilla Visa451568, 476485, 482192Incomm Payments
Vanilla Mastercard528703, 528704, 528727Incomm Payments
Netspend View533251, 533252MetaBank
Green Dot Visa530690, 530691Green Dot Bank
Amex Gift Card374328, 374345, 376824American Express

Important: Prepaid BINs are often blocked at the gateway level (Stripe Radar blocks prepaid by default). However, if you use a gateway where prepaid isn't blocked, AVS won't work for these cards.

2.3. Virtual Cards (VCC) — Privacy.com, Revolut, RedotPay​

Virtual cards are often not linked to an address. You can enter any ZIP code — the system won't check it.

BINs for virtual cards without AVS (valid for 2026–2027):
ServiceBIN (first 6 digits)Type
Privacy.com485911, 485912, 485913Visa Debit
Revolut (EU)413781, 413782, 413783Visa Debit
Revolut (UK)461811, 461812, 461813Visa Debit
RedotPay536425, 536426, 536427Mastercard Debit
Advcash (Volet)531292, 531293, 531294Mastercard Debit
Wirex535445, 535446, 535447Visa Debit

These cards are accepted on most websites without AVS verification. You can enter any 5-digit ZIP code, and the payment will go through.

2.4. Corporate and Business Cards​

Business cards (Chase Ink, Amex Business) often have relaxed AVS verification because it's assumed business owners can make purchases from multiple locations.

BINs for corporate cards with relaxed AVS:
BankBIN (first 6 digits)Type
Chase Ink414720, 414721, 414722Visa Business
Amex Business376824, 376825, 376826Amex Business
Capital One Spark517805, 517806, 517807Mastercard Business

Part 3. Regions and gateways where AVS is disabled or operates formally​

3.1. Regions with weakened AVS​

  • Europe (especially the UK, Germany, and France). AVS for European cards is either not supported or returns a G response, which gateways often ignore.
  • Canada. AVS works, but for Canadian cards, it often only checks the postal code (6 characters, ANA NAN format), and many gateways don't know how to process it correctly.
  • Australia and New Zealand. AVS is supported, but is often disabled for international transactions.
  • Latin America (Brazil, Mexico, Argentina): AVS is virtually never used. Most local cards are not linked to ZIP codes.

3.2. Gateways where AVS is disabled or operates formally​

GatewayAVS behaviorNote
StripeEnabled by default, but merchants can disable it in Radar settings.Stripe allows you to set rules to block charges that fail the CVC or ZIP code (AVS) check.
AdyenThe merchant can disable AVS in the risk profile settings.Adyen allows you to test all possible AVS codes in a test environment
BraintreeEnabled, but the merchant can disable it through settings.Braintree returns AVS codes in the transaction response
Checkout.comEnabled, but the merchant can disable AVSCheckout.com allows you to disable AVS at the account level.
WorldpayIt is recommended to disable cancel on avsNotMatchedWorldpay allows you to disable blocking when AVS does not match
PayPalAVS is not used for PayPal transactions.PayPal as a front-end is the best way to bypass AVS.

Key rule: if a merchant hasn't configured Radar to block AVS errors, a payment may go through even with a mismatched ZIP code. Many small WooCommerce and Shopify stores use default settings, where AVS doesn't block transactions.

Part 4. ZIP-Grab Technique to Bypass AVS​

If you have a card with AVS but don't know the cardholder's exact ZIP code, you can try to find a ZIP code that will pass the check.

4.1. The "ZIP by Bank Region" Method​

Most issuing banks in the US are headquartered in major cities. If your card's BIN is from Chase (New York), Bank of America (Charlotte, North Carolina), or Capital One (McLean, Virginia), you can try the ZIP code of the city where the bank is located.

Working ZIP codes for matching:
BankCityZIP code
ChaseNew York10001, 10002, 10003
Bank of AmericaCharlotte, NC28201, 28202, 28203
Capital OneMcLean, VA22101, 22102
Wells FargoSan Francisco, CA94101, 94102, 94103
OthersNew York10001, 10004, 10005
US BankMinneapolis, MN55401, 55402, 55403

Why it works: Many banks don't store the cardholder's exact ZIP code in the AVS system, but use the ZIP code of their head office. If you enter this ZIP code, AVS may return a partial match (Z), and the payment will go through.

4.2. The "Popular ZIP Codes" Method​

Some ZIP codes are so popular that banks often use them as placeholders for cards without a specific address.

The most effective ZIP codes for bypassing AVS are:
  • 90210 — Beverly Hills, California
  • 10001 — New York
  • 60601 — Chicago
  • 77001 — Houston
  • 33101 — Miami
  • 94101 — San Francisco

Statistically, these ZIP codes pass AVS check in 20-30% of cases for cards with an unspecified address.

4.3. "ZIP for non-US cards" method​

For cards issued outside the US, you can enter any 5-digit ZIP code. The system either doesn't check it (response U) or ignores the result. Use 90210 or 10001 — they work in most cases.

4.4. AVS bypass via PayPal method​

The most reliable way to bypass AVS is to use PayPal as a front. Link the stolen card to PayPal (or use the card via PayPal Guest Checkout). PayPal doesn't transmit AVS data to the merchant, so address verification simply doesn't occur. I wrote more about masking PayPal transactions in Article 182.

Part 5. Practical List of BINs without AVS for 2026–2027​

Based on an analysis of open BIN databases, logs of successful attempts, and data from closed carding channels and carding forums, here is a current list of BINs that do not verify the address (AVS = U, G, or ignored by the gateway).

5.1. Non‑US Credit BIN​

BINBankPageType
414910, 414919BarclaysUKCredit
539101, 539102HSBCUKCredit
440768, 440657Norddeutsche LB / Savings BanksGermanyCredit
437871Deutsche Card ServicesGermanyCredit
450601, 450602RBCCanadaCredit
431830, 431831Commonwealth BankAustraliaCredit
497790, 497791BNP ParibasFranceCredit
493501, 493502Intesa SanpaoloItalyCredit
450875, 450876BBVASpainCredit

5.2. Prepaid и Gift Cards​

BINIssuerTypeNote
451568, 476485, 482192Vanilla VisaPrepaidAVS = U
528703, 528704, 528727Vanilla MastercardPrepaidAVS = U
533251, 533252Netspend (MetaBank)PrepaidAVS = U
530690, 530691Green DotPrepaidAVS = U
374328, 374345, 376824Amex Gift CardPrepaidAVS = U

5.3. Virtual Cards (VCC)​

BINServiceTypeNote
485911, 485912, 485913Privacy.comVisa DebitAVS = U
413781, 413782, 413783Revolut (EU)Visa DebitACP = G
461811, 461812, 461813Revolut (UK)Visa DebitACP = G
536425, 536426, 536427RedotPayMastercard DebitAVS = U
531292, 531293, 531294Advcash (Volet)Mastercard DebitAVS = U
535445, 535446, 535447WirexVisa DebitACP = G

5.4. Business/Corporate cards with weakened AVS​

BINBankType
414720, 414721, 414722Chase InkVisa Business
376824, 376825, 376826Amex BusinessAmex Business
517805, 517806, 517807Capital One SparkMastercard Business
Important: These lists are current for 2026–2027, but BIN ranges are subject to change. Always check your BIN using binx.vip or binlist.io, or paid BIN databases, before purchasing a card.

Part 6. Mistakes when working with cards without AVS​

Mistake 1. Ignoring BIN filtering. Even if a card doesn't check AVS, it can be blocked by BIN. Prepaid and virtual cards are often blocked by Stripe Radar at the BIN level, before any AVS check.

Mistake 2. Entering a non-existent ZIP code for US cards. If a US card has AVS, but you enter a random ZIP code (for example, 00000), the payment will be rejected. Use the "ZIP by bank region" method or popular ZIP codes.

Mistake 3. Not verifying the card with a micro-check. Even if the BIN doesn't check AVS, the card may be empty or dead. Always make a micro-check ($1 via Wikipedia) before the main hit.

Mistake 4. Using the same ZIP code for all cards. If you use the same ZIP code for all cards, it may raise suspicions from anti-fraud software. Rotate ZIP codes depending on the BIN.

Summary​

AVS isn't a death sentence. Use non-US BINs, prepaid cards, and virtual cards, where AVS doesn't work. For US cards, use the "ZIP matching" technique based on the bank's region or popular ZIP codes (90210, 10001, 60601). The best way to bypass AVS is to use PayPal as a middleman. And always check the BIN via binx.vip or binlist.io before purchasing a card.

A quick one-line reminder:
"Non-US BINs, prepaid cards, and VCCs are not checked by AVS. For US cards, match the ZIP code based on the bank's region (Chase = 10001, BoA = 28201). The best way to bypass AVS is to use PayPal as a middleman. Always check the BIN before purchasing."
 
Last edited:
Top