01What 3-D Secure actually does
3-D Secure is a protocol between the merchant, the card network (Visa or Mastercard), and the card issuer. When 3DS is triggered, the issuer asks the cardholder for a one-time code sent via SMS, email, or authenticator app.
If the code matches, the charge proceeds. If the code does not match or is not entered, the charge is declined. The merchant never sees the code; the merchant only sees success or failure.
Modern 3DS2 is invisible to most legitimate users. The merchant and issuer share enough data (device fingerprint, location, charge amount) that 3DS only triggers when something looks off. Threshold-based 3DS is even more selective.
02When does 3DS trigger by default?
By default, 3DS triggers when the merchant or issuer has reason to suspect fraud. Typical triggers:
1. New device. The cardholder is charging from a phone, laptop, or browser that has never used the card before.
2. New geography. The charge originates from an IP address or country that does not match the cardholder's history.
3. Unusual amount. The charge is materially larger than the cardholder's typical spend pattern.
4. High-risk merchant category. The merchant is in a category with elevated fraud rates (electronics, travel, certain digital goods).
5. Issuer rule. The issuer has configured the card to require 3DS above a threshold amount.
03The right threshold for crypto cards
Threshold-based 3DS is configured by the issuer, not by the merchant. The issuer says: any charge above $X USD requires 3DS; any charge below $X does not. This protects the cardholder from large unauthorized charges without adding friction to routine small charges.
The right threshold depends on your typical charge pattern. For a card used for SaaS subscriptions ($50-$500/month per vendor), a $250 threshold is conservative - most charges go through without challenge, but a sudden $5,000 charge would trigger.
For a card used for ad spend ($100-$10,000 per charge), a higher threshold like $500 or $1,000 makes sense. The cardholder's routine charges all clear without challenge, but a stolen card attempting $15,000 would trigger.
BitPay defaults to $250. Most users raise this to $500 after 30 days of routine use.
04The merchant category consideration
Different merchant categories trigger 3DS differently. Card networks and issuers have lists of high-risk categories: electronics, jewelry, travel, certain digital goods. Charges in these categories trigger 3DS more often.
SaaS billing is generally low-risk. Google Ads billing is also low-risk. Online shopping for digital goods is moderate. Travel booking is high-risk because chargeback rates are higher.
If you have one card dedicated to Google Ads and another dedicated to travel booking, the travel card can have a higher 3DS threshold (because the legitimate charges are large anyway) and the Google Ads card can have a low threshold (because legitimate charges are predictable).
05When 3DS gets in the way
Three situations where 3DS hurts more than helps. First, charges from a shared device that 3DS has never seen before - your assistant's laptop, your travel laptop, a colleague's machine. 3DS triggers, you have to fish out the code.
Second, charges from a VPN. If you charge while connected to a VPN, the IP address may not match your card history. 3DS triggers. The fix: whitelist your VPN provider's IP range, or disable VPN for the moment of charge.
Third, charges from a corporate environment. Many corporate networks have multiple egress IPs that 3DS does not associate with your card. The fix: charge from a known device and network, or whitelist the corporate IP range.
These are solvable but they require some configuration. The default 3DS setup is conservative; the right 3DS setup is calibrated to your actual usage pattern.
06When 3DS saves you from real fraud
Stolen card scenarios. If someone has your card number but not your phone or authenticator, they cannot complete a 3DS challenge. The charge is declined. The card is flagged. The issuer initiates fraud investigation.
Account takeover. If your card number leaks through a merchant breach, the attackers will test it. With 3DS enabled, the test charge fails - you get an alert, you freeze the card, the damage is contained.
BIN attacks. Attackers generate card numbers based on known BIN ranges and try them at online merchants. 3DS catches most of these because the attacker does not have the cardholder's phone or email.
These scenarios happen. 3DS is the single most effective anti-fraud control available to issuers. The threshold just controls how often it activates.
07The configuration that works
Start conservative. Threshold $250, 3DS enabled for all charges above threshold. Observe 30 days. Count how many 3DS challenges you get. If you get zero challenges, raise to $500. If you get more than 5% of charges challenged, lower to $150.
Adjust per-card. A Google Ads card has different routine-charge amounts than a travel booking card. Each card should have its own threshold.
Whitelist your devices and networks. Most issuers support device fingerprinting - the first time you charge from a device, you whitelist it. After that, 3DS does not trigger for that device.
Test in low-stakes situations before relying on it for high-stakes spend. Charge $20 from a new device, see what happens. Charge $5,000 from a new device, see what happens. Calibrate before you need it to work right.
08How 3DS interacts with BitPay's fraud monitoring
BitPay runs fraud monitoring across the entire card portfolio. Cards with high charge attempts, unusual geography, or repeated 3DS failures are flagged for review.
When a card is flagged, the system does two things. First, it notifies the cardholder via the cabinet and (if enabled) Telegram. Second, it provides a one-click freeze action.
The combination of 3DS + fraud monitoring + freeze-on-demand is the layered protection most crypto cards offer. 3DS catches bad actors at the charge; fraud monitoring catches patterns across charges; freeze-on-demand catches anything that slipped through.
None of these is a substitute for the others. They layer. The right configuration uses all three.