Self-Custody Crypto Card Programme
Let customers spend on-chain balances with a card that authorises against their own smart account, in real time - the program never takes custody of the money.
The full blueprint adds all 9 risks with their controls and owners, the DORA third-party pack and the delivery plan in 4 phases.
Web document · ~13 pages · 18 min read · one link opens all 22 blueprints
- Maturity
- Emerging
- Regime
- Card scheme + MiCA
- Proven stack (4 of 5)
- Monerium · Quantoz Payments · Paxos Issuance Europe · Safe
- Last verified
- August 2026

Reviewed by Ivor Jugo, Offer Owner at Protofire
Processed to date via Monerium's EURe issuance rail - the single production reference behind this pattern's only live implementation.
Not a market aggregate - Monerium's own disclosed volume, not the size of the crypto-card market. One live end-to-end program (Gnosis Pay) runs on it; the second announced issuer/BIN-sponsor combination is pipeline, not production.
01. The opportunity
Most cards marketed as crypto cards are custodial: the customer sends funds to the provider, the provider holds them, and the card spends from the provider's own balance. This pattern keeps the customer's euros in a smart account the customer controls. When the card is tapped, the authorisation is checked against that on-chain balance in real time and the spend settles on-chain afterwards to the program's wallet, so the program reads a balance it does not own and decides, in the moment, whether to approve. A fintech, neobank, CASP or self-custody wallet company can add a card product this way without becoming a custodian, and without the safeguarding, reconciliation and capital that custody carries.
Gnosis Pay has run the pattern in the EU since 2024: a SEPA transfer arrives, EURe is minted automatically into the customer's Safe, and the card authorises against that balance. It lets customers spend a euro token they already hold on a Visa card, without first withdrawing to a bank account, while the euro token stays a regulated e-money token issued under someone else's licence and no yield is paid on the balance, so MiCA Art. 50 does not arise. For a wallet or self-custody company whose product is built on customers holding their own keys, it is a way to ship a card without contradicting that.
02. The regulatory position
03. Who's already done this
SEPA top-up auto-mints EURe; spend is authorised against the customer's Safe balance; settlement goes on-chain. Survived a 1 Jun 2026 Safe-module exploit (~USD 1.5M extracted, ~USD 300k stranded), reimbursed 100% of affected users by early July 2026 - the pattern's clearest disclosed risk evidence, not proof the pattern is broken.
EURe issuance and SEPA; over EUR 2bn processed, distributed across several wallets and apps as the open issuance rail behind the Gnosis Pay reference.
Issues EURQ/EURD and can sponsor a BIN - PIPELINE, not a production reference; no public card program on this combination exists yet.
04. Does this fit you?
- Yes if the goal is a card product without becoming a custodian, and customers already hold (or are expected to hold) euro tokens.
- Not if a standard debit card on fiat balances already held is the actual need - a normal BIN sponsorship is faster and simpler.
05. The stack, layer by layer
Most of these layers can be rented from a named vendor, and usually should be. The part that matters is the one layer you have to own yourself.
Customer base, app and authorisation the institution already has
Customer base and KYC; app and support organisation; a payments authorisation, or an agent relationship with one; compliance function and reporting.
The token issuer and card scheme rails
The euro EMT and its reserve, under someone else's licence; SEPA in and out; BIN sponsorship, card manufacture, scheme connectivity; audited smart-account contracts. The authorisation logic, the reconciliation and the runbook sit on your side.
The authorisation and operations layer
The authorisation service and its balance oracle; limits, velocity rules and the decline policy; settlement collection and retry handling; three-way reconciliation across card, chain and scheme; refunds, disputes and chargebacks against a live on-chain balance; monitoring and the on-call rota.
06. Why this stack
- The customer keeps custody throughout; the program reads a balance it doesn't own and decides, in under a second, whether to authorise.
- Safe smart accounts carry the longest production history and the most audits of the account options available.
Risks, controls and owners
From the full blueprint · 3 of 9 shown, one with its control- Issuer fails or the token loses parControl: Licensed EMI, MiCA reserve rules, redemption at par on demand; diversify across two issuers if volumes justify itOwner: The issuer, under its own licence
- Smart-account contract defectControl: in the full blueprintOwner: The account vendor and its auditors
- Authorisation service is wrong or slowControl: in the full blueprintOwner: The integrator, then the institution after handover
The other 6 risks, and every control, are in the full blueprint.
Get all 9 with controls ↓Get the full BP-10
Web document · ~13 pages · 18 min read
This page is the short version. The full BP-10 adds all 9 risks with their controls and owners, the DORA third-party pack and the delivery plan in 4 phases. We email you a personal link, and it opens all 22 blueprints in the library.
We email your personal link and, now and then, a blueprint update. Privacy policy

Reviewed by Ivor Jugo, Offer Owner at Protofire · last verified August 2026



What the full blueprint adds, by reader
- Counsel
- The regulatory position across 4 regimes, article by article
- Risk & compliance
- All 9 risks, each with its control and the party that owns it
- Third-party risk
- The DORA pack: critical-or-important classification, the Art. 28(4) pre-contract assessment, Art. 30(3) contract clauses and Art. 29 concentration. Any commission we may earn on a named vendor is disclosed
- Technical lead
- Which of the 5 building blocks are essential and which are optional, and why
- Delivery
- The delivery plan in 4 phases, with the decision that gates each, then monitoring and incident response once live
- Board
- For the board paper: what each function gets, and where this pattern does not work
FAQ
What regimes govern a self-custodial crypto card, and why does MiCA Art. 50 not apply?
The Crypto-Backed Cards pattern sits across three non-overlapping regimes. The euro token is an e-money token under MiCA, covered by the issuer's licence rather than the card program's; the card leg runs under BIN sponsorship, scheme rules and PSD2, on the program's own or an agent authorisation; and Article 50 does not bite because the program pays no yield on the balance. The card authorises against the customer's own smart account in real time, so the program never takes custody of the money.
Who already runs a self-custodial crypto card, and how did it handle an exploit?
Gnosis Pay has run a Visa card program in the EU since 2024, where a SEPA top-up auto-mints EURe, spend is authorised against the customer's Safe balance, and settlement goes on-chain. It survived a Safe-module exploit on 1 June 2026 in which about USD 1.5 million was extracted and around USD 300k stranded, and it reimbursed 100 per cent of affected users by early July 2026. Its issuance rail is Monerium, an Iceland FSA EMI that has processed over EUR 2 billion of EURe.
What does the card program build versus rent, and who is it for?
The pattern fits fintechs, neobanks, CASPs and self-custody wallet companies that want a card spending against customers' own on-chain balances without becoming a custodian. The program keeps its customer base, app and authorisation. It rents the euro EMT and its reserve under someone else's licence, plus SEPA, BIN sponsorship and scheme connectivity, from providers such as Monerium, Quantoz Payments, Paxos Issuance Europe, Safe or Gnosis Pay. It builds the authorisation service and balance oracle, limits and decline policy, settlement, and three-way reconciliation across card, chain and scheme.
Already evaluating this for your institution?
When you are ready, we scope a business case on your own numbers: the costed build, the controls, the SLA and the ROI your board needs to approve it. Or talk it through first.
Run this pattern in production, or tried to and stopped? .