Mastercard Crypto Credential and stablecoin payments: the card networks are rebuilding the permission layer
Key takeaways
- August 3, 2026: Mastercard completed its acquisition of BVNK — announced in March for up to $1.8 billion, including $300 million in contingent payments — buying infrastructure that holds, moves and converts value across fiat and blockchains in 130+ countries.
- August 5, 2026: Mastercard began piloting Mastercard Crypto Credential on cross-border stablecoin flows with orchestration network Borderless.xyz, whose first participating operators are Infinia, Walapay and Koywe, under what the companies call a single-audit compliance model at network scale.
- The stated problem is not settlement. Borderless.xyz's CEO put it exactly: "One of the biggest friction points for stablecoin payment operators isn't the payments. It's that compliance doesn't scale the same way the network does." The explicit model is correspondent banking — trust the originator's checks instead of redoing them at every hop.
- That friction is a property of hops. A network stitched from 15+ licensed providers across 100+ countries needs a trust layer because value passes through many hands. A customer paying a merchant on-chain has one hop and no correspondent chain.
- Both shapes will exist. Intermediated rails are the right tool for treasury, bank-to-bank corridors and fiat off-ramps at scale. Payzum is the other shape: non-custodial acceptance where USDC/USDT lands in the merchant's own wallet, final on-chain, no chargebacks, no balance held anywhere.
What Mastercard did in three days
Two announcements, seventy-two hours apart, that read as one strategy.
On August 3, 2026, Mastercard completed its acquisition of BVNK, the deal it had signed in March for up to $1.8 billion including $300 million of contingent consideration. BVNK is not a consumer brand; it is plumbing. It lets customers hold, move, manage and convert value across fiat and digital currencies, and send and receive payments across major blockchain networks in more than 130 countries. Mastercard's framing was a "multi-money world" in which the next paradigm is defined by how well each rail and form of money connects to the others.
Two days later, on August 5, 2026, Mastercard announced a pilot extending Mastercard Crypto Credential — its verification framework for digital-asset transactions — to cross-border stablecoin payments, run with the stablecoin orchestration network Borderless.xyz. Borderless connects wallet infrastructure to more than 15 licensed stablecoin providers across 100+ countries through a single API. Infinia, Walapay and Koywe are named as the first operators to run inside what the companies describe as a single-audit compliance model at network scale. Per reporting, Crypto Credential supplies standardized assurance signals that participants feed into their own approval and risk workflows; Mastercard is not described as moving or settling the funds in the pilot.
Put next to the rest of Mastercard's 2026 — regulated stablecoin settlement rolled out in June across a set of approved coins, and a crypto partner program launched in March with 85+ participants — the shape is clear. The network is not fighting stablecoins. It is doing the thing card networks are actually good at: selling trust between parties who don't know each other.
The quote that explains the whole strategy
The most useful sentence in the coverage came from Borderless.xyz CEO Kevin Lehtiniitty, and it is worth reading twice:
"One of the biggest friction points for stablecoin payment operators isn't the payments. It's that compliance doesn't scale the same way the network does. Every new provider means starting the verification process over."
He then named the precedent directly. Correspondent banking solved this decades ago by letting downstream institutions trust the originating institution's verification instead of repeating it at every counterparty. Mastercard is applying that model to digital-asset payments.
This is an honest description of a real problem, and the solution is sensible. But it also tells you exactly which problem is being solved — and for whom. Compliance re-verification is a cost that appears once per counterparty. If your architecture has many counterparties, you pay it many times. The fix is to make the checks portable across them.
Which raises the question nobody in the announcement had reason to ask: why are there so many counterparties?
The friction is a property of hops, not of stablecoins
A cross-border stablecoin network assembled from 15+ licensed providers in 100+ countries is, structurally, a correspondent network. Money enters at one licensed institution, moves through orchestration, exits at another licensed institution, and every one of those relationships is a party that must be identified, risk-rated and monitored. Adding the ninetieth provider adds the ninetieth verification burden. Of course compliance doesn't scale — the topology guarantees it.
Notice what the stablecoin is doing in that picture. It is the transport between hops. It is not removing the hops. The intermediaries are there because the network's job is to start in one currency and finish in another, inside a regulated wrapper, on someone's behalf. That work genuinely requires licensed parties, and pretending otherwise would be silly.
Now change the job. A customer pays a merchant. The customer holds USDC; the merchant wants USDC. There is no currency conversion to broker, no local institution to exit through, no balance to hold in the middle. The payment is a single on-chain transfer from one wallet to another, final in seconds. There is no correspondent chain, because there is no correspondent.
That's not a claim that compliance disappears — it doesn't, and it shouldn't. Payzum runs KYC on merchants, 2FA on accounts, encrypted secrets, signed webhooks and a full audit log, and every settlement leaves a permanent on-chain record that is easier to trace after the fact than any correspondent message ever was. The claim is narrower and more useful: the specific friction Mastercard just spent nine figures to smooth is friction you may never have had.
What merchants gain from a permission layer — and what they hand back
Be fair about the upside first, because there is one. A portable verification standard should mean faster onboarding at each new provider, fewer duplicated audits, more corridors that actually work, and — over time — cheaper cross-border payouts for businesses that need money to land in a bank account in another country. If you pay suppliers in six jurisdictions and reconcile in one, this is good news.
Now the part that rarely makes the press release. A permission layer is, by construction, a layer that can withhold permission. Three consequences follow, and every one of them has already happened to somebody in card payments.
1. Eligibility becomes a product feature. Read the language in this generation of announcements and the qualifier repeats: eligible clients, eligible merchants, approved participants. Access is granted, and what is granted can be reviewed. Whole verticals learned this the hard way with acquirers — which is why we wrote a separate piece on high-risk merchant accounts.
2. Your funds sit somewhere before they're yours. Intermediated rails work by taking value in at one end and paying it out at the other. Between those two moments there is a balance, and it is not in your wallet. That is the entire mechanism behind held funds, rolling reserves and frozen payouts — none of which require anyone to act in bad faith. They only require the money to be somewhere you don't control.
3. Consolidation reprices things. A $1.8 billion acquisition is a bet on distribution, and distribution eventually gets monetized. Stablecoin infrastructure that was independent last quarter is now a line inside a network's product portfolio, with a network's pricing logic and a network's risk appetite. Terms you agreed with a startup are not terms you agreed with an acquirer — and dependency on any single provider is a live risk, as we argued when a crypto payment provider shut down without warning.
None of this makes the intermediated rail bad. It makes it a rail with a landlord. Worth knowing which of your payment flows genuinely need one.
Two shapes of stablecoin payment, and how to tell which you need
The industry keeps saying "stablecoin payments" as if it were one thing. In practice, two very different architectures are being built at once, and they answer different questions.
Shape one: the intermediated rail. Value starts as one currency and ends as another, or starts on-chain and ends in a bank account. Licensed providers sit at each end. Somebody must be trusted, so trust gets standardized — which is precisely what Crypto Credential is for. Use it for treasury movements, bank-settled cross-border B2B, mass payouts that must arrive as local fiat, and anything where the destination is an account rather than a wallet. Payzum does not do this: there is no fiat leg, and pretending otherwise would be a disservice.
Shape two: direct acceptance. Someone pays you and you keep what they sent. A customer at your counter, a checkout on your site, an invoice to a client abroad, an AI agent buying one API call. Payer's wallet to payee's wallet, final on-chain, nothing in between. No correspondent chain, so nothing to standardize trust across.
Most businesses need shape two far more often than they think, and reach for shape one out of habit — because for thirty years there was no way to be paid that didn't route through somebody. That's the assumption stablecoins actually broke, and it's the one the current wave of announcements quietly restores.
How Payzum fits: acceptance without a middle
Payzum is a non-custodial, crypto-only payment processor. Funds go directly to wallets the merchant controls. Payzum never holds, pools or routes the money — the settlement is the payment. There is no Payzum balance to freeze, no reserve to hold back, no correspondent to vet, and no eligibility review standing between a customer and your wallet.
Concretely, that covers the ways a real business gets paid:
- Online: hosted checkout (redirect, modal or inline), no-code payment links and buttons, invoices with expiry and overpayment detection, recurring subscriptions, donations and tip jars — plus drop-in compatibility with existing e-commerce plugins, snippets and webhooks.
- In person: POS with a fresh QR per sale, physical terminals, PIN-protected cashier accounts and per-cashier or per-terminal analytics. No acquirer, no card-network fees, no chargebacks. Any phone is a terminal — the setup we walk through in turning a phone into a crypto POS.
- Paying others: mass payouts by CSV (BTC/LTC/DOGE) and EVM stablecoin payouts on Polygon, Arbitrum, Optimism, Base, BNB Chain and Avalanche — useful for affiliates, contractors and prize money, as covered in crypto mass payouts.
- Machine customers: a REST API with API keys and signed webhooks, an integration playground, and x402 so AI agents can pay USDC on Base per call straight to your wallet.
Accepted assets settle in crypto, with optional auto-conversion to USDC or USDT if you'd rather not hold volatility. Supported networks include Bitcoin, Ethereum, Solana, Polygon, Base, Arbitrum, Optimism, BNB Chain and Avalanche, with typical confirmations around 0.4 seconds on Solana and roughly 2 seconds on Base and Polygon. On x402 specifically, one clarification that gets muddled constantly: Payzum is the middleware/proxy in front of your API, not the facilitator — on-chain settlement is handled by an external facilitator, currently Coinbase's.
How it works, step by step
- Create the account and pass KYC. Standard merchant onboarding — identity and business verification, 2FA on the account, encrypted secrets. This is the compliance you do once, on your own side.
- Point it at wallets you already control. You supply the destination addresses per network. Because settlement is non-custodial, the very first payment lands in your wallet, not in a Payzum balance you later withdraw from.
- Turn on the channels you need. Hosted checkout or payment links for online, the POS with per-sale QR and PIN cashiers for the counter, invoices for B2B clients, subscriptions for recurring, the REST API or an x402 endpoint if machines are buying. Optionally set auto-conversion to USDC or USDT.
- Get paid, and reconcile. Payments confirm on-chain in seconds and are final — no reversal window, no chargeback. Signed webhooks push events to your systems, the audit log records everything, and per-cashier and per-terminal analytics tell you where the money came from. Details and endpoints are in the developer documentation.
Intermediated stablecoin rails vs. direct acceptance
| Dimension | Network-intermediated rail | Payzum direct acceptance |
|---|---|---|
| Parties in the path | Originating provider, orchestration layer, receiving provider — each one verified | Payer's wallet → your wallet. One on-chain transfer |
| Why a trust layer is needed | Compliance repeats per counterparty; the fix is portable assurance signals | No counterparty chain to make trust portable across |
| Where funds sit before they're yours | In a balance held by an intermediary until payout | Nowhere — settlement is the payment, straight to your address |
| Access | Granted to eligible clients; reviewable | Merchant KYC, then your own wallet. No acquirer approving each vertical |
| Reversibility | Depends on the rails at each end | Final on-chain — no chargebacks, no ~120-day dispute window |
| Speed to your control | Payout cycles set by the provider | Seconds — ~0.4s on Solana, ~2s on Base and Polygon |
| Best used for | Treasury, bank-settled cross-border B2B, payouts that must arrive as local fiat | Customer payments: checkout, POS, invoices, subscriptions, per-call API access |
| Fiat leg | Included — that's the product | None. Crypto-only; you off-ramp yourself, on your own schedule |
Three fair objections
"A card network standardizing compliance is a good thing. Why frame it as a cost?"
It is a good thing, for the flows it targets. Nothing here argues against portable verification in cross-border corridors — duplicated audits are pure waste, and Lehtiniitty's diagnosis is correct. The point is scope. A merchant taking payment from a customer is not in a correspondent chain, so the standard solves a problem they don't have while the architecture it standardizes reintroduces one they'd escaped: someone in the middle, holding the balance and granting the access.
"Doesn't 'no intermediary' just mean no protection?"
It means a different distribution of risk, and it's worth being precise about the trade. You lose the ability to have a payment reversed on your behalf — which cuts both ways, and is exactly why merchants with chargeback exposure come looking. You gain finality, a permanent auditable on-chain record, and the fact that nobody can freeze funds they never held. You keep operational security: 2FA, encrypted secrets, signed webhooks, a complete audit log, PIN-separated cashier accounts at the POS. What changes is that wallet custody is yours, which is a real responsibility and the honest cost of the model.
"We need money in a bank account. Doesn't that force us onto the intermediated rail?"
For the leg that ends in a bank account, yes — and Payzum won't pretend otherwise, because it settles in crypto with no fiat leg. But the two decisions are separable. You can accept payments non-custodially into your own wallet, hold in USDC or USDT so the amount doesn't move, and off-ramp when and where you choose, in whatever size you choose. That keeps the conversion a treasury decision you make on your schedule instead of a permission you're granted on someone else's.
Frequently asked questions
What is Mastercard Crypto Credential and what does the stablecoin pilot do?
Mastercard Crypto Credential is Mastercard's verification framework for digital-asset transactions. On August 5, 2026, Mastercard began piloting it on cross-border stablecoin payments with orchestration network Borderless.xyz, whose first participating operators are Infinia, Walapay and Koywe. It supplies standardized assurance signals that participants plug into their own approval, compliance and risk workflows, under what the companies call a single-audit compliance model — so each new counterparty doesn't trigger a fresh round of verification. Per reporting, Mastercard is not described as processing or settling the funds in the pilot.
Why did Mastercard buy BVNK, and for how much?
Mastercard completed the acquisition on August 3, 2026. The deal was signed in March 2026 for up to $1.8 billion, including $300 million in contingent payments. BVNK provides infrastructure to hold, move, manage and convert value across fiat and digital currencies, and to send and receive payments across major blockchain networks in more than 130 countries. Mastercard's stated rationale is connecting digital assets to traditional payment rails for cross-border B2B, payouts, settlement and treasury flows.
Does a merchant accepting stablecoins need Crypto Credential?
Not for the act of being paid. Crypto Credential addresses compliance duplication between payment providers in a multi-hop network. When a customer sends USDC or USDT directly to a merchant's wallet there is one on-chain transfer and no correspondent chain, so there are no counterparties to make verification portable across. Merchants still do their own compliance — Payzum includes KYC, 2FA, encrypted secrets, signed webhooks and a full audit log — but that's done once, on their own side.
What does non-custodial actually change for me?
Funds go directly to wallets you control, so there is no processor balance in the middle. That removes the mechanism behind held funds, rolling reserves and frozen payouts — there is nothing to hold back. It also means the payment is final when it confirms on-chain: no chargebacks and no months-long reversal window. The trade-off is that wallet custody and key security are your responsibility.
Can I still get the money into a bank account?
Not through Payzum. Payzum is crypto-only: it accepts crypto and settles in crypto, with optional auto-conversion to USDC or USDT so you're holding dollars rather than volatility. Moving from stablecoins into a bank account is a step you run yourself, with whatever off-ramp you already use, on your own schedule and in your own size.
Which networks and payment methods does Payzum support?
Supported networks include Bitcoin, Ethereum, Solana, Polygon, Base, Arbitrum, Optimism, BNB Chain and Avalanche, plus LTC and DOGE for payouts, with typical confirmations around 0.4 seconds on Solana and roughly 2 seconds on Base and Polygon. Ways to collect: hosted checkout, no-code payment links and buttons, invoices with expiry and overpayment detection, subscriptions, donations, POS with a fresh QR per sale and PIN cashiers, a REST API with signed webhooks, and x402 so AI agents can pay USDC on Base per call.
Book 20 minutes and cut the middle out of one flow
The card networks are busy standardizing trust between intermediaries. That's useful work for corridors that need intermediaries — and irrelevant to the payment where your customer pays you directly. Tell us how money reaches you today and we'll design the non-custodial version: checkout, POS, invoices or per-call API access, settling in USDC or USDT to a wallet you control, on the call.
Calendar not loading? Book a time here · [email protected]
This article is an independent analysis for general information only, and is not financial, legal, tax or investment advice. Dates, deal terms, participants and product details reflect Mastercard's published announcements and third-party reporting current as of August 2026; pilots change scope and may not reach production. Payzum is not affiliated with Mastercard, Borderless.xyz or BVNK. Payzum is crypto-only and settles in crypto — it does not provide fiat settlement or banking services — and on x402 it acts as the middleware/proxy in front of a client's API, not as the facilitator; on-chain settlement is handled by an external facilitator. Confirm the rules that apply in your own jurisdiction.