Wire Transfers, Neteller and Skrill: How Carding Proceeds Move Through Payment Rails
The conventional wisdom in financial crime circles is that the carding ecosystem runs exclusively on cryptocurrency. Bitcoin, Monero, and a rotating cast of stablecoins dominate the conversion layer, and blockchain analytics firms have built entire business models around tracing those flows. But that narrative misses a crucial, far less glamorous component of the fraud economy: the traditional payment rails that still move the bulk of illicit fiat. Wire transfers, e-wallets like Neteller and Skrill, and the humble bank login remain the connective tissue between stolen card data and spendable cash.
Understanding how these legacy systems are exploited is not just an academic exercise. For compliance officers, fraud analysts, and researchers, the convergence point between crypto and fiat is where the most actionable intelligence lives. The criminals know this too. They are not abandoning traditional finance; they are weaving it into a hybrid laundering pipeline that leverages the speed of crypto and the anonymity of cash-out services.
The Missing Fiat Step in the Crypto Narrative
Chainalysis data cited in recent dark web services research puts the underground economy at roughly $3.2 billion in global activity, with criminal-as-a-service offerings alone worth about $700 million. That figure is almost certainly understated because it only captures the on-chain portion of the lifecycle. The reality is that a significant percentage of carding proceeds never touch a blockchain until the very end of the pipeline—if at all.
The typical carding operation follows a familiar arc. Stolen card data is acquired via skimmers, web skimming, or BIN attacks, as documented in standard fraud typologies. The data is bundled and sold on darknet markets. But the buyer’s goal is not to hold a digital asset; it is to convert that data into goods, gift cards, or cash. This is where the payment rails come in. A carder might use a fullz package—complete with PII and sometimes a bank login to an online banking portal—to initiate a wire transfer or to fund a Neteller or Skrill account.
The preference for these e-wallets is not arbitrary. They sit at a jurisdictional and regulatory intersection that is uniquely vulnerable. Neteller and Skrill, both owned by Paysafe, operate across dozens of countries with varying anti-money laundering (AML) enforcement levels. They offer instant transfers, low friction for identity verification in certain regions, and—critically—the ability to move funds between users with little more than an email address. For a carder, a funded Skrill account is a stepping stone that converts stolen credentials into a usable balance with a few clicks.
The Supply Chain of Compromised Wallets
The infrastructure supporting this fiat side of carding is becoming as professionalized as the darknet markets themselves. It is no longer enough to phish a single credential. The modern approach involves targeted campaigns against the developers and integrations that power these payment platforms.
A recent campaign identified by security researchers at Socket.dev demonstrates this shift. Seventeen malicious packages were published to npm and PyPI, each mimicking the official Paysafe, Skrill, and Neteller software development kits. The packages were designed to harvest API keys, tokens, and other sensitive credentials from developer machines. The sophistication was notable—unique obfuscation keys for nearly every file, sandbox evasion tricks, and fake success responses that masked the data exfiltration.
This is not a random phishing attempt. This is a supply-chain attack targeting the very plumbing of the payment ecosystem. By compromising a developer who works on payment integrations, an attacker gains access not just to a single account, but potentially to the infrastructure that processes transactions for thousands of users. The harvested API keys can be used to initiate transfers, query balances, or even modify payout settings. For a carder, this is a goldmine—it provides a direct, automated path to move funds without ever needing to interact with a banking UI or raise a red flag on an individual account.
Wire Transfers as a Laundering Workhorse
While e-wallets offer speed and convenience, wire transfers remain the workhorse for larger sums. The reason is simple: wires are irreversible in practice, and they move through a lattice of correspondent banks that makes tracing time-consuming. A domestic wire between two accounts at the same bank is straightforward. An international wire that hops through three or four intermediary institutions creates a headache for investigators.
The abuse of wire transfers in carding typically follows a pattern. A carder gains access to a bank login through a phishing kit or a data breach. Instead of initiating a card-not-present transaction, which triggers velocity checks and AVS mismatches, they initiate a wire transfer to a mule account. The mule account is often opened with a synthetic identity—a mix of real and fake data that passes basic KYC checks. Once the wire lands, the mule either withdraws cash or forwards the funds via a second wire to another account, often in a country with lax cooperation on cross-border requests.
| Nexus |
nexusbem4wmo67jt723niftkejivtgxbsbxkb6aesj5gyzj7b3v3mxid.onion
|
| Torzon Market |
torzon7aphar3x4l5b77nsylgyw26kntbi4m2wemrjh72aczeh27f6qd.onion
|
| DarkMatter |
darkmafmzgnsmow5z3spgludhpwxhwbg77oam433fjx3clzh2yp2oaid.onion
|
| Omega Market |
omega7yhz7n4vg4yhf2na2qaaaeatdlqvjbj2juc245mr5muxtnuvgyd.onion
|
| BlackOps |
blackoogcnxogvymmebfwfjhx4k7efpgeoeytxtsev2lc4pqlbz54qad.onion
|
This is not speculative. Law enforcement case studies, such as the Houston Police Department’s recovery of $150,000 in stolen crypto, show that traceability improves dramatically when funds are held in exchanges or banks. The detective involved was able to freeze accounts within days, but that only worked because the stolen funds had not yet been moved through a wire chain. In the fiat world, the same investigative speed is rare. A wire that has passed through three jurisdictions becomes a multi-month international legal tangle.
The Cash-Out Layer
The final leg of the journey is the cash-out. Cryptocurrency is useful for paying vendors on darknet markets, but the operator of a carding shop still needs rent money. This is where the hybrid model shines. Funds are moved from a compromised bank account or a Skrill balance into a cryptocurrency exchange via a debit card or a wire. The exchange account is opened under a fake identity or a mule. Once the funds are in crypto, they are swapped through privacy coins like Monero or sent through a chain of wallets before landing in a seller’s account.
This layering technique is well documented in blockchain analytics reports. The on-chain portion is traceable, but the difficulty lies in linking the fiat-entry point to the final beneficiary. The exchange that receives the wire and converts it to crypto is the chokepoint. If the exchange has weak KYC—and many tier-3 exchanges do—the investigation dead-ends at a mule’s selfie and a phone number from a VoIP service.
The same professional services economy that supports darknet market infrastructure also provides the tools for this fiat laundering. The escrow systems and dispute resolution mechanisms that make crypto markets function are mirrored by a less formal but equally effective set of services for fiat. Vendors on forums offer “cash-out” services, where a carder provides a funded e-wallet or a bank login, and the vendor takes a 20-30% cut to convert the balance into clean crypto. These services are effectively the bulletproof hosting of the financial world—they are the underlying infrastructure that persists long after individual markets are taken down.
Why the Crypto Focus Misses the Point
There is a tendency in the compliance industry to treat crypto and traditional finance as separate domains. This is a mistake. The TRM Labs compliance summit briefings explicitly noted that bad actors are leveraging both traditional rails and digital assets, and that the nexus points where they converge are the critical areas for analysis. The same wallet that holds stolen Ethereum likely received its first funding via a Skrill transfer from a compromised developer’s API key.
The implications for defenders are clear. Blockchain analytics tools are excellent at following on-chain flows, but they are blind to the first mile of the transaction. A compliance program that only monitors crypto transactions will miss the carding proceeds that are being laundered through wire transfers and e-wallets before they ever become a blockchain transaction. The solution is not to abandon crypto surveillance, but to build detection models that flag the fiat-to-crypto on-ramps—the moments where a wire transfer or an e-wallet transaction behaves anomalously.
Practical Indicators for Analysts
For researchers and fraud teams, certain behaviors should raise flags. A wire transfer that originates from an account with no prior history of wires, routed to a newly opened account at a different bank, is a classic pattern. An e-wallet account that receives a high volume of transfers from other e-wallets linked to the same IP range, followed by an immediate withdrawal or exchange conversion, is equally suspicious. The use of a single email or phone number across multiple Neteller or Skrill accounts is another common indicator, as is the use of residential proxies or VPNs that consistently match a different region than the documented address.
These indicators are not unique to carding—they exist in traditional money laundering typologies as well—but they take on added weight when combined with signals from the darknet ecosystem. A compromised bank login that suddenly starts initiating wires at 3 a.m., followed by a transfer to a Paysafe-linked subsidiary, is a stronger signal than either event occurring in isolation.
Conclusion: The Fiat Frontier
Carding is not a crypto problem. It is a financial systems problem that uses crypto as one of several escape hatches. The malware campaigns targeting Skrill and Neteller SDKs, the wire transfer chains moving money through mule accounts, and the cash-out services that bridge the gap between fiat and crypto are all pieces of the same machine. Law enforcement agencies have gotten good at seizing crypto from exchanges; they are less effective at intercepting the conventional bank transfers that finance the entire operation.
The next wave of financial crime prevention will need to look beyond the blockchain explorer and back into the wire transfer logs and e-wallet APIs. The criminals have already figured that out. The defenders are still playing catch-up.