Skip to main content
Don't invest unless you're prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong. Take 2 min to learn more.

What Is 3D Secure? Why Your Card Asks for Extra Approval

The bank popup that interrupts online card payments: what it checks, why crypto purchases trigger it more than groceries, and how to pass it first time.

beginner6 min readWritten by Dan Clarke

TL;DR

  • 3-D Secure is the bank-run approval step on online card payments: a push to your banking app, a biometric check, or a one-time code.
  • In the EEA and UK the step is required by law for most online purchases, and crypto buys nearly always get the full challenge.
  • Most failures are stale bank settings: an old phone number, an unactivated banking app, a timeout, or approving on one device while refreshing on another.
  • Educational guide, not financial advice.

You get as far as the card details, hit pay, and instead of a receipt the page turns into something new: a panel with your bank's logo on it, asking you to approve the payment in a banking app you last opened months ago. No warning, and no explanation of who is asking or why. A surprising number of crypto purchases die right there on that panel, and hardly any of them die because the bank actually suspects anyone of anything.

The panel is called 3-D Secure, and it kills more card purchases of bitcoin than any fraud engine does, nearly always for reasons that take about five minutes to fix, and the fixes live in your banking app rather than anywhere near the crypto. This is a guide, not financial advice.

Three domains, one popup

3-D Secure is the card industry's extra identity check for online payments. The 3-D is not a graphics boast, it stands for the three domains involved: the merchant's bank, the card network in the middle, and your bank, which is the one that actually challenges you.

Visa switched the idea on in 2001 under the name Verified by Visa, and it runs today as Visa Secure. Mastercard's version, once SecureCode, is now Mastercard Identity Check. Both do one job: prove the person typing the card number is the person the bank issued it to.

From password boxes to a nod on your phone

The first version aged badly. 3DS1, the Verified by Visa era, made you invent yet another password and type it into a floating box, which trained a generation of shoppers to trust exactly the sort of popup that phishing pages love to imitate. EMVCo, the standards body the card networks run jointly, retired it in October 2022, and nobody much missed it.

Its replacement, EMV 3-D Secure, known as 3DS2, was built for phones. Approval now usually means a push notification to your banking app and a fingerprint or face check, or a one-time code by text as the fallback, so there is no password to remember or type wrong. The whole exchange takes seconds once the app is set up properly.

In Europe, the popup is the law

In the EEA and the UK the extra step is written into law. PSD2, the EU's second Payment Services Directive, introduced Strong Customer Authentication: most online card payments must be approved with two independent factors, something you have plus something you know or are. Enforcement arrived across the EEA on 31 December 2020, and in the UK on 14 March 2022.

So for European shoppers the challenge is standard plumbing, while everywhere else it appears whenever the bank or the merchant decides a payment deserves a second look.

Why the coffee skipped it and the bitcoin did not

3DS2 has a frictionless lane, and low-risk payments, the weekly shop, a subscription the bank has seen forty times, can pass invisibly, scored in the background with no challenge shown at all.

Crypto does not ride in that lane. Card systems code crypto purchases as quasi-cash, the same family as money orders, and quasi-cash sits squarely in the challenged bucket. A first payment to a crypto on-ramp is exactly the profile the scoring pulls aside.

There is money behind this, too, because on an authenticated payment, liability for fraud generally shifts from the merchant to the issuing bank. Merchants in risky categories therefore invoke 3-D Secure every time, because a passed challenge moves the fraud bill off their desk. And your bank, now holding that bill, would rather ask you first.

So a crypto purchase demanding approval while the same-day coffee sailed through is the system working as designed rather than a mark against you.

Why people fail the challenge

Hardly anyone fails 3-D Secure because a bank suspects them, they fail on stale settings. Four patterns cover nearly all of it, in rough order of how often they bite.

The phone number your bank holds is old. The code goes to a SIM you binned two phones ago, so you stare at the box and nothing arrives. The attempt dies, and no amount of retrying fixes this one until the number on file changes.

The banking app was never activated for approvals. Downloading it is only half the setup, and if you have never logged in and allowed notifications, the push has nowhere to land.

The challenge times out. The window is short, often a few minutes. Wander off hunting for your phone and the session can expire before you are back.

The approval lands on a different device. Buying on a laptop while the app lives on your phone is fine. Approve on the phone, then go back to the laptop tab and let the page finish on its own, because a refresh mid-challenge can kill the whole session.

All four are settings problems rather than judgements about you, your balance, or what you were buying.

And pace matters, so fix the setting first, then retry once, calmly, with the phone next to you. One clean attempt with the app awake usually works where five hurried ones just burn time.

The fix is one boring evening

Every cure here sits on the bank's side of the fence. Update the mobile number your bank holds before you next need a code, log in to the banking app once, properly, and let it send its notifications. Keep the phone within reach when you pay for anything online, and answer the challenge on the device it rings on while the window is still open.

Then retry the purchase, and usually the push just arrives and a thumbprint finishes it.

The rest of the flow is quick by comparison. Banxa has been running fiat-to-crypto payments since 2014, across more than 100 payment methods in 100-plus countries, and card orders typically complete within about 10 minutes of issuer approval. The human pause at the challenge is normally the slowest step in the whole purchase.

A failed challenge feels final, but it is the most fixable decline there is. Sort the bank app once and it stops happening.

Frequently Asked Questions

Close cousins. Two-factor authentication is any login asking for a second proof, a code on top of a password, say. 3-D Secure is the card networks' version, wired into online checkout and run by your bank rather than the shop.

Risk categories. 3DS2 lets low-risk payments pass with no visible challenge, and a supermarket the bank already knows scores low. Crypto is coded as quasi-cash, a high-risk category, so it nearly always gets the full challenge. Expected for the category, and nothing personal.

The payment stops before any money moves, and that attempt ends there. Fix whatever blocked the approval, usually an old phone number or a dormant banking app, then try once more. A failed challenge does not flag your card as stolen.

Not in the EEA or the UK, where Strong Customer Authentication rules have required it for most online card payments since 31 December 2020 and 14 March 2022 respectively. Elsewhere it depends on your bank and the merchant. Crypto platforms invoke it deliberately, so plan for the challenge rather than around it.

Three things, in order. Whether the phone number your bank holds is current, whether the banking app is registered and allowed to send notifications, and whether the push is landing on another device, an old phone or a tablet in a drawer. Most missing approvals are one of those three. If all pass, ask the bank whether approvals are switched on for your card.

About the author — Dan Clarke
Dan Clarke

Dan Clarke is the author of Bitcoin: The Complete Guide and a former content lead at Binance Academy, where he wrote crypto education for readers arriving with no background in the subject. He has worked in the cryptocurrency industry since 2017. His rule for these guides: plain language first, precision where it matters, no cheerleading.