Crypto Card Chargebacks 2026: What You Can Actually Dispute

- KYC is the switch that turns your dispute rights on. Regulation E § 1005.18(e)(3) says a firm is not required to apply the liability caps or the error-resolution rules to a prepaid account it has not identity-verified. A no-KYC card is that account by definition.
- Verifying later does not backfill. The same rule only obliges the issuer to resolve errors that occur following verification, so disputes from your anonymous months stay outside it forever.
- Filing can cost more than the purchase. RedotPay publishes a $50 upfront fee per disputed transaction and $700 to escalate to pre-arbitration. Bybit charges $50 if your case is denied for incomplete information.
- Authentication is where most claims die. RedotPay does not treat a payment verified by PIN, 3D Secure, fingerprint, Apple Pay or Google Pay as fraud at all — and that is now most of how people pay.
- A UK or EU card is in a different league. PSD2 Article 73 and PSRs 2017 reg 76 require a refund by the end of the next business day, cap your loss at €50/£35, and put the burden of proof on the provider, not you.
On this page
- Three routes, and only one is a legal right
- The rule that decides everything: verified or not
- The US clocks, when Regulation E does apply
- The UK and EU: the strongest rights in the niche
- What the issuers actually promise
- The exclusions that cancel the right
- Self-custodial cards: nobody to dispute with
- Why the money comes back smaller
- How to file so it actually works
- Final take
- FAQ
A merchant took £340 and shipped nothing, and the card you paid with was a crypto card. Here is the part nobody tells you before you load one: whether a crypto card chargeback is something you can demand or something you can only politely request is decided by a single line of American prepaid-account regulation, and it turns on whether you ever sent in your passport. We read that regulation, the UK and EU instruments covering the same question, and the published dispute terms of five issuers. The spread is wider than anything in this market's fee tables: one card gives provisional credit while it investigates, another charges $50 before it will start.
Almost all chargeback content online is written for merchants fighting disputes, or for people who bought crypto with a stolen card. Spending from a crypto card and wanting your money back is a different problem with a different rulebook, and it is essentially unwritten. So this is the rulebook.
Three Routes, and Only One of Them Is a Legal Right
When a card payment goes wrong there are three separate mechanisms, routinely collapsed into the single word “chargeback”. They have different owners, deadlines and enforceability.
| Route | Who runs it | Can you compel it? | Typical speed |
|---|---|---|---|
| Merchant refund | The merchant | No — goodwill or contract | Days to 30+ days |
| Scheme chargeback | Visa / Mastercard, filed by your issuer | No — scheme rules, not law | 30 days to 6 months |
| Statutory refund | Your issuer, under Reg E / PSD2 / PSRs | Yes — where it applies to you | Next business day to 90 days |
That middle row is what most people are relying on without knowing it. Chargeback is a scheme devised by the card networks, not a statute, so there is no legal guarantee you get your money back. It is genuinely useful, it works often, and it is not a right you can enforce against anybody. The bottom row is the one that matters — and whether you are in it is not up to your issuer's generosity. It is up to a definition.

The Rule That Decides Everything: Verified or Not
In the US, prepaid accounts were brought under Regulation E by the CFPB's prepaid rule, which is where a crypto card's dispute rights come from. Section 1005.18(e)(3)(i) carries the carve-out that runs this market:
“For prepaid accounts that are not payroll card accounts or government benefit accounts, a financial institution is not required to comply with the liability limits and error resolution requirements in §§ 1005.6 and 1005.11 for any prepaid account for which it has not successfully completed its consumer identification and verification process.”
Read that against the product category this site covers. A no-KYC crypto card is, in the regulation's own language, a prepaid account for which the institution has not completed identity verification. The rule spells out three ways that can happen, and the third is the entire no-KYC business model: where the institution does not have a consumer identification and verification process for the program at all, provided it made the required alternative disclosure.
That disclosure requirement, at § 1005.18(d)(1)(ii), is remarkable once you notice it. A program with no verification process must describe its error resolution process and liability limits — “or, if none, state that there are no such protections.” The regulation contains a purpose-built slot for a card program to tell you in writing that you have no dispute rights at all.
| Protection under Reg E | Verified (KYC) card | Unverified (no-KYC) card |
|---|---|---|
| $50 / $500 liability cap on fraud | Required | Not required |
| Duty to investigate a reported error | Required | Not required |
| Provisional credit within 10 business days | Required | Not required |
| Written explanation if denied | Required | Not required |
| Disputes from before you verified | Still excluded | Not required |
That last row surprises people who assume they can fix this retroactively. Paragraph (e)(3)(iii) says that once the institution does verify you, it must resolve errors “that occur following verification”. Transactions from your anonymous months never come inside the rule, so upgrading tomorrow does nothing for the charge you are arguing about today.
Older comparisons on this site said no-KYC cards have “no chargeback protection”. That was too blunt, and this is the correction: the network machinery still exists and issuers do use it. What disappears is the layer underneath, the part obliging anybody to use it for you. See our no-KYC versus KYC comparison for the rest of that trade-off.
The US Clocks, When Regulation E Does Apply
If your card is verified, the machinery is strong, and it runs on deadlines most cardholders never see. Section 1005.11(c) sets them out.
| Stage | Deadline | Citation |
|---|---|---|
| You report the error | 60 days from access to the history; 120-day safe harbour from the debit | § 1005.18(e)(2) |
| Issuer determines whether an error occurred | 10 business days | § 1005.11(c)(1) |
| Provisional credit, if it needs longer | Within 10 business days (may withhold $50) | § 1005.11(c)(2)(i) |
| Extended investigation with credit given | 45 days | § 1005.11(c)(2) |
| Card purchases specifically | 90 days, not 45 | § 1005.11(c)(3)(ii)(B) |
| Results reported to you | 3 business days after completion | § 1005.11(c)(2)(iv) |
Note the fifth row, because it covers almost everything a crypto card does: the investigation window stretches from 45 to 90 days whenever the disputed item “resulted from a point-of-sale debit card transaction”. Every shop purchase is that. The compensation is that you should be holding provisional credit for the whole three months — the issuer must credit you within 10 business days, tell you within two business days of doing so, and give you full use of the funds meanwhile.
Your own exposure is tiered by how fast you speak up, under § 1005.6(b): $50 if you notify within two business days of learning the card was lost or stolen, $500 if you miss that window, and unlimited for transfers more than 60 days after the statement showing the first bad one. The gap between $50 and unlimited is measured in days of not checking your app.

The UK and EU: The Strongest Rights in the Niche
A card issued by a UK or EEA-authorised payment or e-money institution sits under a materially better regime than an American prepaid card, and far better than an offshore one. The PSRs 2017 and PSD2 build the same structure.
| Question | UK — PSRs 2017 | EU — PSD2 |
|---|---|---|
| Deadline to notify | 13 months from debit date (reg 74) | 13 months from debit date (Art 71) |
| Refund deadline for unauthorised payments | End of the business day following awareness (reg 76) | End of the following business day (Art 73) |
| Your maximum liability | £35 (reg 77(1)) | €50 (Art 74(1)) |
| Liability if the issuer skipped strong authentication | Nil (reg 77(4)(c)) | Nil (Art 74(2)) |
| Who must prove the payment was authenticated | The provider | The provider (Art 72) |
| Liability if you were grossly negligent or fraudulent | Unlimited (reg 77(3)) | Unlimited (Art 74(1)) |
Two rows there are worth more than the rest combined. The first is the refund clock: regulation 76(2) requires the refund “as soon as practicable, and in any event no later than the end of the business day following the day on which it becomes aware of the unauthorised transaction”. Not 45 days, not 90. Next day. The exception is narrow: the provider must have reasonable grounds to suspect you acted fraudulently, and must report those grounds in writing.
The second is Article 72, which puts the burden of proof on the provider to show the transaction was authenticated and accurately recorded. Nowhere else in this article does the law start from the assumption that you are telling the truth — and several of the issuer terms in the next section treat authentication as the end of the conversation.
One protection people expect and do not get: Section 75 of the Consumer Credit Act does not cover crypto cards. It makes the lender jointly liable with the merchant between £100 and £30,000, but only under a credit agreement. Crypto cards are prepaid or debit, so joint liability never attaches and chargeback is the fallback. For more, see our UK crypto card guide and crypto cards under MiCA.
What the Issuers Actually Promise
Statutes set a floor; what you meet in the app is the issuer's own published process, and these differ more than any other feature in this market. All of it is from each provider's help centre, read September 2026.
| Card | Window to file | Fee to file | Provisional credit | Time to resolve |
|---|---|---|---|---|
| Crypto.com | 120 days | None published | Yes, for fraud | 30–45 days |
| Bybit | 120 days | $50 if denied for bad info | Not published | Not published |
| RedotPay | Not published | $50 upfront, $700 to escalate | No | 3–6 months |
| Wirex | Per scheme rules | None published | Not published | Set by the scheme |
| Gnosis Pay | Help centre unreadable | — | No pooled balance to credit | — |
Crypto.com publishes the most cardholder-friendly process we found: up to 120 days to initiate, disputes “generally resolved within 30 to 45 days”, and provisional credit while it investigates if you lost funds to fraud. It also states the two obvious limits — you cannot dispute a transaction the merchant has already fully refunded, and your claim cannot exceed the transaction value.
RedotPay is the other end. Its chargeback process requires “a fee of 50 USD per transaction… paid upfront”, warns that chargebacks “usually take around 3–6 months”, and prices escalation to pre-arbitration at $700 per transaction, separate from the initial chargeback fee. It is candid that “neither a chargeback nor pre-arbitration is guaranteed to succeed”. On a disputed €80 subscription the fee structure alone settles whether to bother, which may be the point.
RedotPay's pages also contradict each other usefully: its fraud guidance walks you through freezing and then deleting the card, while its refund guidance warns that once a card is deleted it cannot guarantee you will receive outstanding refunds. If any refund is in flight, do not delete the card.
Gnosis Pay publishes an article on reversals, refunds and chargebacks that we could not read — its help centre returns 403 to every automated fetch, as it did when we researched why crypto cards get declined. We will not characterise a policy we could not open; the structural point below stands regardless.

The Exclusions That Cancel the Right You Thought You Had
A dispute window is worthless if your transaction type is carved out of it, and this is where most real claims die. RedotPay publishes the market's clearest exclusion list — to its credit, though the list is brutal. It does not treat any of these as fraud:
- “A transaction verified with a PIN, 3D Secure (3DS), fingerprint, facial recognition, Apple Pay, or Google Pay”
- “A subscription or automatic renewal you authorised”
- “A family member, friend, or someone else using the card with your permission”
- “Consumer disputes, such as goods or services not received, a service-related issue, or a refund you haven't received”
Read the first and last items together. The first excludes essentially every modern way of paying — set up Apple Pay on a crypto card and you authenticate every transaction you make. The last excludes the most common consumer grievance there is, the thing that did not arrive. Between them they cover most of why anybody ever wants their money back.
This is where the UK and EU regimes diverge hardest from an offshore issuer's terms. Under PSD2 Article 72 authentication does not close the question — the provider still has to prove the payment was authorised. Under an offshore card's terms, the 3DS prompt you cleared is the end of the argument.
Wirex adds a different exclusion: chargebacks only where Visa or Mastercard rules permit, merchant and ATM disputes sent back to the merchant or operator, and account-to-card and outbound transfers excluded from the refund and chargeback processes covering ordinary purchases. Sending money to another card is not a purchase, and it does not come back.
Self-Custodial Cards: Nobody to Dispute With
Cards that settle straight from a wallet you control — Gnosis Pay's Safe, MetaMask Card — change the shape of the problem rather than its size. There is still a licensed issuer behind the Visa logo who can file a scheme dispute. What is missing is the pooled custodial balance a conventional issuer credits you from while it investigates.
Provisional credit is the whole practical value of § 1005.11(c)(2): you get the money back in 10 business days and the argument happens afterwards, with your money in your account. On a self-custodial card there is nothing in an omnibus account to advance you, so a won dispute is a credit that arrives at the end, if it arrives.
It is the same trade documented elsewhere on this site. In what happens to your balance if the issuer fails, self-custody was the strongest position, because there is no pooled balance to trap. Here it is the weakest, for exactly the same reason: there is no pooled balance to draw on either.
Why the Money Comes Back Smaller
Even a fully successful dispute does not restore you to where you were, and this part is specific to crypto cards. A refund or a won chargeback returns value to the card account in that account's currency. It does not rewind the conversion that funded the purchase. Three things leak on the round trip:
| Leak | What happens | Who is exposed |
|---|---|---|
| Price movement | You are refunded the amount, not the coin. If the token rose, you buy back fewer units. | Any non-stablecoin funding |
| Two conversion spreads | Crypto to fiat on the way out, fiat to crypto on the way back, both at the issuer's rate. | Convert-at-checkout cards |
| The disposal stands | The taxable event created when the card was funded is not undone by the refund. | Most jurisdictions that tax crypto spending |
That third row is the one people miss at year end. As we set out in crypto card taxes for 2026, the card's funding architecture decides when the disposal happens, and a merchant refund months later is a separate event rather than a cancellation of the first. Your records need both legs. The practical consequence: the faster a dispute resolves, the less it costs you beyond the disputed amount. A card promising 30–45 days and one warning of 3–6 months are not the same product even if both eventually pay.

How to File So It Actually Works
Every published process we read rewards the same behaviour in the same order. None of it is complicated; almost all of it is time-sensitive.
| Step | Do this | Why it matters |
|---|---|---|
| 1 | Freeze the card in the app | Caps further loss; every issuer asks first |
| 2 | Do not delete the card | RedotPay cannot guarantee refunds to a deleted card |
| 3 | Contact the merchant in writing first | Most issuers require the attempt as evidence |
| 4 | File within 2 business days for fraud | $50 cap instead of $500 under § 1005.6(b) |
| 5 | Submit every transaction at once | Bybit allows one dispute per transaction, no duplicates |
| 6 | Ask in writing for provisional credit | Mandatory on a verified US card if the case runs past 10 business days |
Two deserve emphasis. Step 4 is the cheapest thing in this article: the difference between reporting a stolen card on day two and day four is $450 of your own money under § 1005.6(b)(2). Step 5 exists because Bybit states that you may submit only one dispute per transaction and duplicates are rejected, though you can bundle several transactions into one filing — a second attempt at the same charge is not available to you.
Before any of it, check which entity issued your card and where it is licensed. That single fact decides whether you are in the next-business-day world of regulation 76 or the $50-to-file world. We record the issuing entity and licence for every card in the Kardd directory.
Final Take
Crypto card dispute rights are real, and distributed almost the opposite way to how the marketing suggests. The cards advertising freedom from paperwork are the ones the regulation explicitly releases from any duty to investigate, cap your losses or credit you while they look. The cards that made you photograph your passport are the ones that owe you a written answer on a deadline.
That is not an argument against no-KYC cards, which exist for reasons unrelated to chargebacks. It is an argument about what you put on them. Match the card to the purchase: authenticated everyday spending on whatever you like, and anything large, shippable or unfamiliar on a card whose issuer has a legal deadline. The fee tables will never show you this difference, and it is worth more than any cashback rate in the market.
Compare cards by the rules behind them
Kardd tracks issuing entity, licence, KYC level, custody model and fees across the whole crypto card market — so you can see which regime a card actually sits in before you load it.
Kardd may earn a commission on sign-ups. Affiliate disclosure.
Related Articles
- Crypto Card Balance Protection 2026: The Insolvency Rules
- Crypto Card Declined? 9 Reasons and Fixes for 2026
- Crypto Card Frozen? What to Do When Your Card Locks Your Funds
- Are No-KYC Crypto Cards Safe? Risks You Need to Know
- Crypto Card Taxes 2026: What a Swipe Actually Triggers
- What Is a Crypto Card? The 2026 Pillar Guide
Frequently Asked Questions
Can you chargeback a crypto card transaction?
Often yes, but the right belongs to the issuer rather than to you. A Visa or Mastercard crypto card runs on the same dispute rails as any other card. What differs is whether you can compel it: in the US, Regulation E's error-resolution duties do not apply to a prepaid account whose holder has not been identity-verified, so on a no-KYC card a dispute is a customer service request rather than a legal obligation.
Do no-KYC crypto cards have chargeback protection?
Not as a statutory right. Section 1005.18(e)(3) of Regulation E says a financial institution is not required to comply with the liability limits and error resolution requirements for any prepaid account it has not identity-verified — which describes a no-KYC card exactly. The network process still exists, but nothing obliges the issuer to use it for you, give you provisional credit, or cap your losses at $50.
How long do I have to dispute a crypto card transaction?
It depends which clock you are under. Crypto.com and Bybit both publish 120 days from the transaction, and Regulation E's safe harbour is 120 days from the debit. In the UK and EU the outer limit is 13 months from the debit date, under reg 74 of the PSRs 2017 and Article 71 of PSD2. File within days regardless.
Does Section 75 cover a crypto card?
No. Section 75 of the Consumer Credit Act 1974 makes the lender jointly liable with the merchant, but only under a credit agreement and only between £100 and £30,000. Every mainstream crypto card is prepaid or debit, so it never attaches. The fallback is chargeback, a scheme rule rather than a statute, carrying no legal guarantee of a refund.
Why was my crypto card dispute rejected for using Apple Pay?
Because strong authentication shifts the presumption. RedotPay's policy lists a transaction verified with a PIN, 3D Secure, fingerprint, facial recognition, Apple Pay or Google Pay among the things it does not treat as fraud. UK and EU law pushes the other way: Article 72 of PSD2 puts the burden on the provider to prove authentication, which alone is not proof you authorised the payment.
Can you dispute a transaction on a self-custodial crypto card?
There is usually a licensed issuer behind the Visa logo who can file one, but the money has already left your wallet and no scheme rule reaches on-chain. What self-custody removes is the pooled balance an issuer credits you from while it investigates, so there is no provisional credit. See our stablecoin card comparison for which cards settle this way.
If a crypto card chargeback succeeds, do I get my crypto back?
You get the money back, not the coin. A refund credits value to the card account in that account's currency, so if the token you sold to fund the purchase has moved, the same amount buys back fewer units. The disposal made when the card was funded is not undone either. Treat a successful dispute as recovering the amount, never the position.
Sources
Primary sources, September 2026: 12 CFR § 1005.18 (the prepaid-account rule, including the (e)(3) unverified-account carve-out and the (d)(1)(ii) “no such protections” disclosure), 12 CFR § 1005.11 (error resolution, provisional credit, the 45- and 90-day windows), 12 CFR § 1005.6 (the $50/$500 liability tiers), the Payment Services Regulations 2017, reg 76 (next-business-day refund) with reg 77 (the £35 cap) and reg 74 (13 months), Directive (EU) 2015/2366 (PSD2), Articles 71–74, Crypto.com on disputes and chargebacks, RedotPay's chargeback process (the $50 and $700 fees and the exclusion list), and Bybit on submitting a card transaction dispute. Gnosis Pay's help centre returns 403 to automated requests, so its reversals and chargebacks article is not characterised here. RedotPay publishes no filing deadline we could find, which is why that cell reads “not published” rather than carrying a figure. Dispute rights depend on the entity that issued your card and its licence — confirm yours before you need them.