Skip to content
Blueprints / BP-10 · CASPs, neobanks & brokers

Crypto-Backed Cards With Self-Custodial Spend

Let customers spend on-chain balances with a card that authorises against their own smart account, in real time - the program never takes custody of the money.

Maturity
Emerging
Regime
Card scheme + MiCA
Proven stack
Monerium · Quantoz Payments · Paxos Issuance Europe · Safe
Last verified
August 2026

Reviewed by Ivor Jugo, Offer Owner at Protofire

Trusted across 60+ networks and 95+ protocols
EUR 2bn+

Processed to date via Monerium's EURe issuance rail - the single production reference behind this pattern's only live implementation.

Not a market aggregate - Monerium's own disclosed volume, not the size of the crypto-card market. One live end-to-end program (Gnosis Pay) runs on it; the second announced issuer/BIN-sponsor combination is pipeline, not production.

01. The opportunity

Most cards marketed as crypto cards are custodial: the customer sends funds to the provider, the provider holds them, and the card spends from the provider's own balance. This pattern keeps the customer's euros in a smart account the customer controls. When the card is tapped, the authorisation is checked against that on-chain balance in real time and the spend settles on-chain afterwards to the program's wallet, so the program reads a balance it does not own and decides, in the moment, whether to approve. A fintech, neobank, CASP or self-custody wallet company can add a card product this way without becoming a custodian, and without the safeguarding, reconciliation and capital that custody carries.

Gnosis Pay has run the pattern in the EU since 2024: a SEPA transfer arrives, EURe is minted automatically into the customer's Safe, and the card authorises against that balance. It lets customers spend a euro token they already hold on a Visa card, without first withdrawing to a bank account, while the euro token stays a regulated e-money token issued under someone else's licence and no yield is paid on the balance, so MiCA Art. 50 does not arise. For a wallet or self-custody company whose product is built on customers holding their own keys, it is a way to ship a card without contradicting that.

02. The regulatory position

Three non-overlapping regimes - the euro token is an EMT under MiCA (the issuer's licence, not the card program's); the card leg is BIN sponsorship/scheme rules/PSD2 (the program's own or an agent authorisation); Article 50 does not bite because the program pays no yield on the balance.

03. Who's already done this

Market references, not our clients
Gnosis Pay
Visa card program, EU · Live 2024

SEPA top-up auto-mints EURe; spend is authorised against the customer's Safe balance; settlement goes on-chain. Survived a 1 Jun 2026 Safe-module exploit (~USD 1.5M extracted, ~USD 300k stranded), reimbursed 100% of affected users by early July 2026 - the pattern's clearest disclosed risk evidence, not proof the pattern is broken.

Monerium
Iceland FSA EMI

EURe issuance and SEPA; over EUR 2bn processed, distributed across several wallets and apps as the open issuance rail behind the Gnosis Pay reference.

Quantoz Payments
Dutch central-bank EMI, Visa Principal Member

Issues EURQ/EURD and can sponsor a BIN - PIPELINE, not a production reference; no public card program on this combination exists yet.

04. Does this fit you?

  • Yes if the goal is a card product without becoming a custodian, and customers already hold (or are expected to hold) euro tokens.
  • Not if a standard debit card on fiat balances already held is the actual need - a normal BIN sponsorship is faster and simpler.

05. The stack, layer by layer

Most of these layers can be rented from a named vendor, and usually should be. The part that matters is the one layer you have to own yourself.

Yours

Customer base, app and authorisation the institution already has

Customer base and KYC; app and support organisation; a payments authorisation, or an agent relationship with one; compliance function and reporting.

Rented

The token issuer and card scheme rails

The euro EMT and its reserve, under someone else's licence; SEPA in and out; BIN sponsorship, card manufacture, scheme connectivity; audited smart-account contracts. The authorisation logic, the reconciliation and the runbook sit on your side.

MoneriumQuantoz PaymentsPaxos Issuance EuropeSafeGnosis Pay
Ours

The authorisation and operations layer

The authorisation service and its balance oracle; limits, velocity rules and the decline policy; settlement collection and retry handling; three-way reconciliation across card, chain and scheme; refunds, disputes and chargebacks against a live on-chain balance; monitoring and the on-call rota.

Yours, never rentableRented from a named vendorBuilt and run by Protofire

06. Why this stack

  • The customer keeps custody throughout; the program reads a balance it doesn't own and decides, in under a second, whether to authorise.
  • Safe smart accounts carry the longest production history and the most audits of the account options available.

Request the full blueprint

This is the short version. The full blueprint is a single document your counsel and board can read cold, and a third-party-risk function can lift wholesale. Leave your work email and your personal link arrives in your inbox.

What is inside
  • The regulatory position, stated article by article
  • Proven options at each layer, with the vendors that hold up
  • The risk table with a named owner for each risk
  • The division of labour: what is rented, built, and operated
  • The third-party-risk pack a DORA governance function can lift
  • The delivery path, step by step, with the monitoring and incident model

FAQ

What regimes govern a self-custodial crypto card, and why does MiCA Art. 50 not apply?

The Crypto-Backed Cards pattern sits across three non-overlapping regimes. The euro token is an e-money token under MiCA, covered by the issuer's licence rather than the card program's; the card leg runs under BIN sponsorship, scheme rules and PSD2, on the program's own or an agent authorisation; and Article 50 does not bite because the program pays no yield on the balance. The card authorises against the customer's own smart account in real time, so the program never takes custody of the money.

Who already runs a self-custodial crypto card, and how did it handle an exploit?

Gnosis Pay has run a Visa card program in the EU since 2024, where a SEPA top-up auto-mints EURe, spend is authorised against the customer's Safe balance, and settlement goes on-chain. It survived a Safe-module exploit on 1 June 2026 in which about USD 1.5 million was extracted and around USD 300k stranded, and it reimbursed 100 per cent of affected users by early July 2026. Its issuance rail is Monerium, an Iceland FSA EMI that has processed over EUR 2 billion of EURe.

What does the card program build versus rent, and who is it for?

The pattern fits fintechs, neobanks, CASPs and self-custody wallet companies that want a card spending against customers' own on-chain balances without becoming a custodian. The program keeps its customer base, app and authorisation. It rents the euro EMT and its reserve under someone else's licence, plus SEPA, BIN sponsorship and scheme connectivity, from providers such as Monerium, Quantoz Payments, Paxos Issuance Europe, Safe or Gnosis Pay. It builds the authorisation service and balance oracle, limits and decline policy, settlement, and three-way reconciliation across card, chain and scheme.

Already evaluating this for your institution?

When you are ready, we scope a business case on your own numbers: the costed build, the controls, the SLA and the ROI your board needs to approve it. Or talk it through first.

Run this pattern in production, or tried to and stopped? .

Related readingEuro accounts into a walletStablecoin models comparedCrypto payments

Protofire 2026. All rights reserved

Message us on Telegram