Robinhood Wallet Users Bought Dogwifhat With Credit Cards and Earned Cash Back, Because Visa Was Told They Were Buying E-Books
Here is a trade that should not exist: swipe a Chase Sapphire on a bag of Dogwifhat, pay no cash-advance fee, skip the ID check, and collect the same points you’d get on a Kindle book.
That trade existed on Robinhood Wallet and Fomo for months. It worked because the company behind the checkout, Crossmint, coded the purchases as MCC 5815, the Visa merchant category for “books, movies, digital artwork/images or music that is delivered in electronic format.” Visa’s own rules say direct crypto purchases must run under MCC 6012 or 6051 with crypto flags attached, which is what triggers cash-advance treatment and kills rewards.
On Friday, Visa closed the door. According to correspondence reviewed by the Crypto in America newsletter, Visa told payment processors including Crossmint’s acquirer Checkout.com that the digital media code “is not appropriate for memecoin purchases.” Processors get a grace period that is expected to end next week. After that, every memecoin buy has to be processed like any other crypto transaction, with all of the restrictions that implies.
One industry source summarized Visa’s message to the newsletter in nine words: “Stop being cute, stay in your lane and use the appropriate codes.”
How The Block Caught It
The story starts with a September 1 investigation by The Block. Reporters used Visa and Mastercard credit cards, via Apple Pay and Google Pay, to buy the WIF memecoin inside Robinhood Wallet and Fomo. No separate identity check was required. The transactions posted as “digital goods media,” and the cards paid out ordinary purchase rewards.
That is a direct contradiction of how issuers treat crypto. Chase’s rewards terms exclude “cash-like transactions including, but not limited to … cryptocurrency, other similar digital or virtual currency.” Chase told The Block the 5815 code was “incorrect,” that its rewards eligibility is determined by “network data,” and that it had opened a case with Visa over the classification. Mastercard, which requires MCC 6051 plus a crypto transaction identifier for these buys, declined to bless or condemn the setup but said its goal is “to work with acquirers and issuers to remediate problems.”
Visa’s on-record statement at the time: “We require participants in our network to comply with Visa’s Rules. When we become aware of potential noncompliance, we conduct a thorough review.” That review is now over.
The New York Attorney General’s Office told The Block it was “aware of and reviewing the matter.”
Crossmint’s Defense: Memecoins Are Collectibles, Not Crypto
Crossmint did not deny the coding. It argued it was correct. The company said the classification had been “reviewed with relevant partners and stakeholders” and pointed to a 2025 SEC staff statement that described certain memecoins as akin to collectibles rather than securities, along with guidance that named WIF specifically among “digital collectibles available in the markets today.” In Crossmint’s framing, a memecoin is a community membership token, closer to a digital trading card than to a currency, so the digital-goods code fits.
Crossmint also described the product as “no KYC” while noting it includes “AML monitoring.”
Even after Friday’s report, the company is not backing down publicly. A Crossmint spokesperson told The Block: “Our position and procedures on how we process digital goods…has not changed.” Head of Strategy Fonz Olvera was more candid: “Complying with regulation…is super important, but we’re always going to have a little bit of tension between business and law that is healthy.”
Checkout.com, the acquirer that actually submits the transactions to Visa, said it “require[s] all our merchants to comply with applicable card network rules, KYC/AML obligations, and merchant category code requirements.” Robinhood and Fomo both deferred questions to Crossmint. Fomo said Crossmint accounted for about 7% of its user inflows.
Why Card Networks Care About a Three-Letter Code
Merchant category codes are boring on purpose. They are how issuers decide interchange rates, rewards eligibility, cash-advance fees, chargeback risk and which transactions get flagged for fraud and money-laundering review. A crypto purchase coded as an e-book bypasses every one of those checks at once. The issuer pays out rewards it never budgeted for, waives the cash-advance fee it would normally charge, and has no signal in its network data that a customer just leveraged a credit line into a volatile token with no ID check.
That last part is the one regulators notice. The card networks spent years building crypto-specific flags precisely so banks could see and limit this exposure. A setup that routes around the flags, even with a plausible legal theory attached, is the kind of thing that gets a state AG’s attention, and it now has one.
This also lands in a rough month for Robinhood. Three days ago, two of its engineers were charged with front-running the company’s own token listings on Hyperliquid. Robinhood was not accused of wrongdoing here either, but “our partner coded it that way” is not a great answer when the app carrying your logo is the one letting users buy WIF on credit without an ID check.
Why This Matters for Crypto Jobs
Every fiat on-ramp in crypto lives or dies on card-network relationships, and this is a reminder that those relationships are governed by rulebooks most crypto builders have never read. The takeaway for hiring:
- Payments compliance is now a core crypto skill, not a back-office one. Crossmint, MoonPay, Transak, Stripe’s crypto team and every wallet with a “buy with card” button need people who understand MCC assignment, acquirer obligations and network rules well enough to keep the button working. Someone who can read the Visa Core Rules and a token contract is rare and about to be expensive.
- “Collectible vs. currency” is a legal-product question, and someone has to own it. Crossmint’s argument was not crazy; it was built on real SEC staff language. It just ran into a card network that does not care what the SEC thinks. Teams need product counsel who can map a regulatory theory onto every rail the product touches, not just the one that issued the friendliest guidance.
- KYC-optional onboarding is on borrowed time. A no-KYC card flow with AML monitoring bolted on was the growth hack here. Expect the wallet apps that used it to staff up on identity, transaction monitoring and risk operations as they move to crypto-flagged transactions and whatever the NY AG asks for next.
- Robinhood’s partner risk problem is a hiring signal. Two partner-and-employee headlines in one week means third-party risk, vendor due diligence and trust-and-safety roles at consumer crypto apps are going to get budget.
If you can speak both card-network and on-chain, this is your market. Browse the latest crypto and Web3 jobs on Cryptogrind and find the teams that need a compliance-fluent builder before the next grace period expires.
Discussion
Comments are powered by GitHub. Sign in with your GitHub account to chime in.