Cryptnox provides 100% on chain White Label Crypto cards (no card scheme) for banks, fintechs, and financial institutions. White label crypto wallet cards enable secure, user-friendly cryptocurrency management with full regulatory control.
This solution qualifies as “self-custody” as per EU & Swiss regulations.
Granted US patents: US 11,791,996 B2 · US 12,101,400 B2 · US 12,132,824 B2 · US 12,719,697 B2
EAL6+ certified secure element meets regulatory definitions for “self-hosted” wallets
Cards are pre-initialized and ready to use
Lost card? Instantly issue a new one with the same private key
Protected by patents US 11,791,996 B2, 12,101,400 B2, 12,132,824 B2 and 12,719,697 B2
The same patented technology powers the Shamir Secret Sharing cards — quorum-based key backup for institutions.
Card Options
Single-Tech: Crypto wallet only
(Web3, NFTs, DeFi)
Crypto + EMV
(Visa/Mastercard support)
Crypto + EMV + FIDO2 login (Online identification)
Mobile App
iOS & Android apps
PIN & Face ID login
Multi-token/ Multi-chain support
API Integration
Platform
Received via mail
No backup requirement
Provider can issue replacement
No desktop installation
Minimal steps to first transaction
Replicating credit card experience
Transactions
Customer signs transaction
Phone communicates with bank
Server perform checks, such as:
Server returns 2FA to phone
Card signs
Phone broadcasts transaction
Key Management
Onboarding
1. Scan a QR code online in the client user account.
2. Tap the card at the back.
Card Wallet as a Service (C-WaaS) is a white label crypto wallet platform through which a bank, fintech or financial institution issues NFC smart-card hardware wallets under its own brand, with branded iOS and Android apps, while every private key stays inside the customer's card.
A credit-card-sized NFC smart card with an EAL6+ certified secure element that generates and holds the customer's blockchain private keys. The issuer's app talks to the card over NFC: the card signs transactions, the phone broadcasts them. There is no card scheme in the crypto path, so the card is 100% on-chain; the Dual-Tech and Triple-Tech options add EMV and FIDO2 on the same card.
Banks, neobanks, fintechs, exchanges and other financial institutions that want to offer customers a self-custody crypto wallet without asking them to install a desktop wallet, write down a seed phrase or trust a third-party custodian. The issuer keeps its compliance controls; the customer keeps the key.
Through issuer-controlled co-signing, protected by US patent 12,719,697 B2 (granted August 2026). The card signs a transaction only after two independent checks succeed: the cardholder authenticates to the card, and the issuer's server returns a signing element after compliance-checking the transaction details. The server can enforce maximum amounts, whitelisted tokens, whitelisted recipients and smart contracts, sanctions screening, and freeze a lost card. It can approve, but it cannot spend: the private key never leaves the secure element, which is why the architecture qualifies as self-custody under EU and Swiss regulations.
| Question | Custodial crypto card | Cryptnox C-WaaS card |
|---|---|---|
| Who holds the private key? | The provider, in its own systems | The customer's card, inside the secure element |
| Who approves a transaction? | The provider signs on the customer's behalf | The customer signs on the card; the issuer co-signs after policy checks |
| Can the provider move funds alone? | Yes | No: the issuer can approve but cannot spend |
| Seed phrase for the customer? | Usually none, because the provider is the custodian | None: cards ship pre-initialized; a replacement card carries the same key |
The C-WaaS backend handles automated card issuance, key management, card shipping and the transaction policy checks, over encrypted communication with the cards.
Ready for EMV processors, Web3 and DeFi out of the box, and FIDO2 security-key login supported by major operating systems and browsers.
Single-Tech (crypto wallet), Dual-Tech (crypto + EMV) and Triple-Tech (crypto + EMV + FIDO2 login), each with branded iOS and Android apps.
Shamir secret sharing for key recovery (US 11,791,996 B2), secure key injection (US 12,101,400 B2), seedless initialization (US 12,132,824 B2) and issuer-controlled co-signing (US 12,719,697 B2). Cards are made in Switzerland. See the patent portfolio.
Need bespoke on-card logic, such as transaction filtering enforced inside the secure element? See custom smart card development. For institutional key backup across a quorum of cards, see the Shamir secret sharing cards.
Card Wallet as a Service (C-WaaS) is a white label crypto wallet card issuance platform for banks, fintechs and financial institutions. Cryptnox provides NFC smart-card hardware wallets, branded iOS and Android apps and an AWS-hosted backend for issuance, key management, shipping and transaction policy checks; the institution issues the cards under its own brand.
Yes. The private key is generated and kept inside the card's EAL6+ certified secure element and never leaves it. The issuer co-signs transactions after its own compliance checks but cannot spend on its own, so the architecture qualifies as self-custody under EU and Swiss regulations.
No. Cards ship pre-initialized and ready to use, so the user never writes down or stores a seed phrase. If a card is lost, the issuer can issue a replacement card that carries the same private key.
Yes. Cryptnox's patented key recovery (Shamir secret sharing, US 11,791,996 B2) and secure key injection (US 12,101,400 B2) let the issuer provision a replacement card with the same key, without the issuer ever holding the key in a spendable form and without the user handling a seed phrase.
Three: Single-Tech, a crypto wallet card for Web3, NFTs and DeFi; Dual-Tech, which adds EMV for Visa or Mastercard programs; and Triple-Tech, which adds EMV and FIDO2 login for online identification. All three come with branded mobile apps.
The customer approves a transaction in the branded app, the phone contacts the issuer's server, and the server runs its checks (maximum amount, whitelisted token, whitelisted recipient, whitelisted smart contract). If they pass, the server returns a signing element, the card signs with its on-card private key, and the phone broadcasts the transaction to the network.
It depends on the configuration (crypto-only, with EMV, or with EMV and FIDO2), the branding of the apps and the integrations required on the issuer's side. Contact Cryptnox with your use case and volumes for a scoped plan.
Certification statements refer to the NXP secure element and JCOP platform in their evaluated configurations, not to the finished card. Regulatory qualification of a specific program depends on the issuer's jurisdiction and setup.
Contact us to discuss how C-WAAS can work for your business.
Protected by US patents 11,791,996 B2 · 12,101,400 B2 · 12,132,824 B2 · 12,719,697 B2 · Geneva, Switzerland