BitPay added merchant-locked cards today. A single card can be locked to one merchant (by merchant ID) or to a merchant category code (MCC) like 5734 (software), 5817 (digital goods), or 7372 (computing services). Locked cards decline any charge from a merchant other than the configured one.
Merchant locks are the strongest anti-fraud control after freeze. A locked card used outside the configured merchant fails at the authorization step, before the charge reaches the issuer. This is faster than 3-D Secure (no human verification needed) and more reliable than monthly limits (which only catch oversized charges).
Common uses: a card dedicated to AWS that cannot be used at any other merchant, a card for one specific vendor that cannot be redirected to a competitor, a card for one ad account that cannot be drained to an unrelated subscription. The configuration is per-card and can be changed instantly from the cabinet.
Merchant-locked cards work alongside per-card limits, 3-D Secure thresholds, and freeze controls. Operators running a multi-card program typically lock subscription cards to specific vendors and leave ad-spend cards unlocked. The combination of locks + limits + freeze is what makes a fully controlled card program possible.