en

Crypto Payments for Online Casinos and Sportsbooks: How the Cashier Works and How to Pick a Provider

Published
28.10.2024
Updated
10.08.2026
A casino crypto cashier from the operator's side: network choice, invoice amount and the status a deposit sits in
Contents

    Players ask to deposit in USDT, and card rails for gambling are expensive and unstable. That is how casinos and sportsbooks arrive at crypto — and discover that "adding crypto" is not a button in the settings but a whole cashier. This article takes that cashier apart: how a deposit travels and where it breaks, what acceptance really costs, what the regulator will demand, and how to pick a provider. The clock is already running: for Curaçao licensees the first deadline is September 2026.

    The short version

    • A crypto deposit moves through four stages: invoice → transaction on the network → confirmations → crediting. Each stage carries a decision that is yours, not the provider's: the address scheme, the confirmation threshold, how payment errors are resolved, and what support can see.
    • Curaçao: a crypto policy on the CGA portal by September 2026; by June 2027 — wallet segregation, blockchain analytics and reconciliation against the chain. In the EU, MiCA's transitional period ended on 1 July 2026: a gateway without full CASP authorisation may not serve you.
    • The real cost of acceptance is five lines, and the published rate is only the first. A payout to a player and a withdrawal of your own funds are different products with different prices.
    • A casino and a sportsbook run different cashiers: sportsbook deposits arrive in a wave before an event, casino deposits flow more evenly. That difference sets what you need from crediting speed and peak load.
    • Ask for the gambling rate in writing before you sign. A provider who will not put the number on paper cannot be budgeted — cross them off.
    Player's phone showing a crypto deposit screen next to a casino cashier terminal, with USDT and bitcoin coins between them

    Who may legally serve you

    The sequence runs backwards from habit. First you read what your regulator will demand, then you list the evidence you will have to produce, and only then you ask for a price: a provider who cannot produce the evidence does not suit you even for free.

    Curaçao: the clock started in June

    The Curaçao Gaming Authority's crypto guideline for B2C licensees has applied since June 2026 — as reported by iGaming Business on 24 June 2026 and European Gaming on 30 June 2026. The authority has not published the document itself; this is what the trade press reports it to contain.

    The guideline runs on a clock:

    • Within three months, by September 2026 — a crypto policy uploaded to the CGA portal. That is the nearest date.
    • Within six months, by December 2026 — risk assessments, third-party VASP due diligence, wallet-ownership controls and staff training. A VASP is a virtual-asset service provider: the licensed exchange, custodian and gateway category.
    • By June 2027 — wallet segregation, blockchain analytics, reconciliation, withdrawal whitelisting and audit-ready records.

    The guideline also draws a boundary around what you are allowed to be. As reported, a licensee may take crypto as payment for gambling and may not act as an exchange, a PSP or a VASP; mixers and sanctioned addresses are barred outright, fiat-backed stablecoins are preferred, and privacy coins or wrapped tokens of unclear origin have to be assessed or excluded. The cashier accepts crypto — it does not become an exchange.

    One word on that list deserves a gloss — reconciliation. Reconciling the cashier against the chain is a routine procedure: the platform's records are matched against what actually happened on the network. Every cashier entry must have its payment on the chain, and every payment its entry. An unreconciled cashier is deposits that exist on the network but belong to nobody, and auditor questions with no answers.

    For the September filing this means the provider owes you materials, not promises: how wallet screening works — checking a player's address against sanctions and risk databases — how deposits and withdrawals are monitored, and what evidences fund segregation. And if you are still choosing the licence and the platform itself, what iGaming software really costs covers that budget end to end.

    If your company is established in the EU, the gateway needs full authorisation

    MiCA's transitional period for crypto-asset service providers ran out on 1 July 2026 under Article 143(3) — the outer limit ESMA confirmed on 17 April 2026. It is behind us: a gateway serving EU clients without full CASP authorisation is now outside EU law, and ESMA said in June 2026 that a pending application is not a permission to keep trading.

    Only full authorisation carries the right to serve clients across all 27 EU countries under one licence. The rule applies by where your company is established, not by where your players live: the gateway's client is you. Check the provider in the register of its home regulator by legal entity name — a claim on a gateway's own website is not evidence. ESMA keeps a consolidated register itself, and entries are added every few weeks; search it for your candidate's legal entity.

    Malta shows why you check the date on a rule

    Malta is the jurisdiction people quote a figure for: €1,000 a month per player in virtual financial assets. That figure came from the MGA sandbox, and the sandbox is gone — the Authority replaced it on 30 January 2023 with its Policy on the use of Distributed Ledger Technology, effective on publication.

    The old sandbox FAQ still sits on the MGA website, which is how a retired limit keeps travelling through blog posts and vendor decks. If you hold an MGA licence or want one, the document to read with counsel is the current policy. Take the habit rather than the number: before anyone builds a cashier around a cap, confirm the rule itself is still alive — the date on the document matters more than the figure in it.

    Everything in this section is the position as of 9 August 2026 and is not legal advice: check your own licence conditions with your regulator and counsel.

    What goes in the September policy, and which lines your provider fills

    The crypto policy is a document about how your cashier handles crypto: which coins you accept, how addresses are screened, who watches transactions, and what happens to a suspicious payment. Half of the answers are your decisions. The other half rests on the provider's data — which is why you choose the provider before you finish the document.

    Your half is decisions and rules: the asset list — fiat-backed stablecoins first, privacy coins assessed or excluded; confirmation thresholds per network, written as a risk appetite; the rules for underpayment, overpayment and a wrong-network transfer; and who inside the company does what — staff training sits on the December list.

    The provider's half is what you cannot produce alone: wallet screening and monitoring logs across deposits and withdrawals; payment statuses and webhooks that add up to a verifiable history of every operation; evidence of segregated wallets, and — by June 2027 — reconciliation and withdrawal whitelisting. These materials are the annexes of your policy, and the time to request them in writing is during negotiations, not after signing.

    What accepting crypto really costs: five lines

    The published rate is one line out of five. The full monthly bill for a gambling cashier is built like this:

    1. Acceptance on incoming deposits — the number on the pricing page.
    2. Network fees on payouts to players — the money moves both ways: what arrives as a deposit leaves as winnings, and the network charges every outbound transfer. How many transfers that is comes from your own numbers: the deposit-to-payout ratio is yours, not an industry constant.
    3. The conversion spread — the gap between the market rate and the rate at which the provider converts an incoming coin into a stablecoin or fiat.
    4. Withdrawal to your own bank — a separate fee, sometimes with a minimum amount.
    5. A rolling reserve — a share of turnover held back for a fixed period as the provider's insurance in a high-risk segment; not universal, but always worth asking about.

    Two words get swapped constantly and should not be: a payout is money sent to a third party — your player; a withdrawal is money you move out of your own balance into your own bank or wallet. Providers price them as different products, and treating them as one number is the most expensive arithmetic error in this category.

    Now price one illustrative month off the published rate card of one of the few providers that lists every line (real prices, illustrative volumes). Players deposit €100,000: acceptance at 1% costs €1,000. You send a thousand payouts worth €60,000 — a €0.50 fixed fee per payout plus 0.5% makes €500 and €300 — and withdraw €40,000 to the bank at 0.50%, another €200.

    The month's total: acceptance €1,000, payouts and withdrawal another €1,000. Halve the acceptance rate and the bill drops by €500 — exactly what the fixed payout fees alone added. That is why the rate is the first line and not the whole bill, and treat this as the floor: network fees on the outbound side sit on top.

    Crypto is also just one rail in the operator's stack; how the whole iGaming payment setup fits together — cards, banks, crypto — is covered separately.

    How to pick a provider

    Named services with rates and licences are compared in the review of ten crypto payment processors. Here are the criteria that make such a comparison meaningful for a gambling operator:

    • Verifiability. A legal entity and an authorisation number that you found in a regulator's register yourself. A phrase on the provider's site is not evidence.
    • Compliance materials. Screening records, monitoring logs, segregation evidence — as exports you can annex to the September filing, not as a manager's assurance.
    • A written gambling rate. Gambling is a high-risk category almost everywhere, and the public price grid may not apply to you. A provider who will not put the number on paper gets crossed off: you cannot budget them.
    • Both sides of the cashier. The price of payouts and withdrawals, not only acceptance; minimums; and the rolling reserve — whether there is one, how large, for how long.
    • The cashier's mechanics. The four decisions in the next section: does the provider run by your rules, or by its own that you cannot change.

    For example, CryptumPay charges 1% per successful payment, from 0.5% at larger volumes, and the fee can be passed on to the player; underpayments and overpayments are handled automatically, suspicious funds are held by the AML filter before they reach your balance, and you can withdraw to your own wallet at any moment with no minimum amount.

    A casino and a sportsbook run two different cashiers

    A bookmaker and a casino rarely share a paragraph about payments, yet their cashiers behave differently. A sportsbook's deposit flow is tied to a schedule: the line closes at kick-off, odds move until the last minute, and players top up in a dense wave before the event. A casino's flow is flatter: evenings, weekends, spikes around promotions. Slow crediting hurts conversion in both — but a casino player will still be back at the table twenty minutes later, while for a bettor the match has already started.

    Hence different demands on the provider. A sportsbook cares how fast a transaction becomes final and how the provider holds a peak: API rate limits, the webhook queue, delivery times when thousands of players pay at once. Average crediting time says little here — ask about the peak. For a casino, the front line is the stability of repeat deposits and an operation history support can actually read.

    The four decisions in your cashier

    Between the player pressing Deposit and the balance moving, a payment passes four forks. None of them appears on a pricing page, and the decision at each one is yours.

    One address per player, or one address with a tag

    A unique deposit address is issued per player or per payment. The alternative is one static cashier address for everyone, with transfers told apart by a note — a memo or tag.

    The XRP Ledger documentation explains why both designs exist: a destination tag is a more lightweight way to map deposits to individual customers than opening an address for each, because every XRPL address must hold a permanent reserve. Where addresses are cheap, each player gets their own; where an account costs money to keep alive, one address plus tags wins.

    The consequence lands on finance, not engineering: on a shared address, a transfer without a tag belongs to nobody. The cashier is then reconciled by hand, payment by payment — and by June 2027 reconciliation is something you show a regulator, so ask the provider how theirs works before signing.

    How many confirmations before the balance moves

    A confirmation is a block built on top of the block carrying your player's transaction. It is a processing setting, not a property of the network.

    There is no universal number, only somebody's decision. Kraken credits a bitcoin deposit after four confirmations — roughly forty minutes: one company's risk appetite written down, and yours is yours to write. For orientation: Bitcoin's first confirmation typically lands within about 10–60 minutes; on TRON a payment becomes irreversible in about a minute.

    Compare networks on one axis — minutes until a payment can no longer be undone; raw confirmation counts are not comparable across chains. For a sportsbook whose deposits peak an hour before the match, this distance touches revenue directly, so the threshold is set per network, not once for everything. And ask whether you can change it: a fixed threshold means running on the provider's risk appetite and describing it as yours in a regulatory filing.

    Underpayment, overpayment, and the wrong network

    Three failure modes produce almost every deposit ticket: a player sends less than the invoice because the wallet subtracted the network fee; a player sends more because he rounded; a player sends USDT on a network your cashier never listed. Once deposits flow at volume, none of this is rare — each mode feeds support its own queue.

    The fork is who resolves it. With some providers it is automation: the payment is completed or returned under rules written in advance; with others it is a support thread, and the difference is visible only in the contract. CryptumPay handles underpayments and overpayments automatically.

    Some failures happen before the transfer is even sent: the player holds USDT and no coin to pay the network fee with — why that payment never leaves the wallet is covered in USDT transfers without gas.

    What support sees at three in the morning

    Operator's back-office screen listing crypto deposits, three settled and one still waiting for confirmations

    A player says the money left his wallet an hour ago and his balance is still empty. What the agent sees on one screen decides whether that is a forty-second answer or a developer ticket in the morning.

    Ask for the payment lifecycle by name. CryptumPay's statuses run: created — currency chosen, address issued, waiting for payment; pending — the incoming transaction has been seen on the network, confirmations accumulating; crediting — confirmations sufficient, funds being credited; finished — payment complete. The amount credited after all fees arrives only with the finished webhook, which makes it the event your finance records should be built on.

    Two more things belong on that screen: webhook redelivery with duplicate protection, so a retried event cannot credit a bettor twice, and the transaction hash, so the agent can open the transfer himself — reading a transaction in a block explorer is a support skill, not a developer one.

    Where a deposit falls apart

    The places where a crypto deposit fails to reach the balance are known in advance and repeat from operator to operator:

    • the player picked USDT and sent it on a network the cashier is not listening to;
    • the wallet has no native coin to pay the network fee;
    • the fee was deducted from the transfer amount, and less than the invoice arrived;
    • the invoice expired and the payment landed late — the money is on the chain, the link to a player is not;
    • a webhook was redelivered and the system credited the same deposit twice.

    Each failure has a known fix on the integration side: invoice lifetime, an underpayment tolerance, a rule for late payments, an idempotency key. They are collected in why crypto payments fail — a useful document to hand a developer, because every line converts into a concrete task.

    The failures are not priced equally. The first four cost a support ticket and, if the case drags, a player. The fifth costs money directly: a double credit mints balance out of thin air, and combined with a bonus program it becomes a hole that someone finds before your finance team does. Idempotent event handling belongs in the provider requirements next to the fee.

    Paying players out is the other half of the cashier

    Coins leaving an operator's safe towards several player wallets at once, a payout batch going out

    Money moves both ways: winnings leave through the same networks deposits arrive on, and the network charges every transfer. The provider's network list is your future payout bill. The per-transfer price is set by the network, so which one you offer players first is a money question, not a technical one — choosing a USDT network walks through the arithmetic.

    Write monitoring of both sides of the cashier into your policy: a payout address is screened the same way a deposit address is. No rule names this explicitly — but explaining one-sided screening to a regulator is harder than doing it both ways.

    That leaves withdrawal whitelisting — payouts only to pre-approved addresses: it is on the CGA's list with a June 2027 date. Ask whether the candidate's API can keep such a list — if not, you will be keeping it yourself by the deadline.

    What to ask a provider before you sign

    Ask for the answers in writing: a verbal promise cannot be annexed to a regulatory filing.

    1. In which register, and under which legal entity name, can you be verified?
    2. Which materials do you give a licensee for the crypto policy due on the CGA portal: wallet screening, deposit and withdrawal monitoring, blockchain analytics?
    3. What evidences fund segregation and separate wallets?
    4. What acceptance rate applies specifically to gambling?
    5. What do payouts, conversion and fiat withdrawal cost — a separate figure per line?
    6. Is there a rolling reserve — what percentage, for how long?
    7. Are deposit addresses unique — or one static address with tags, and how is reconciliation handled in that case?
    8. Who sets confirmation thresholds per network, and can they be changed?
    9. Underpayment, overpayment, wrong network — automation or a support thread, and where does the contract say so?
    10. Which payment statuses does support see, and are webhooks redelivered after an outage?

    FAQ

    Can a casino on a Curaçao licence legally accept crypto?

    Judging by how the trade press reports the CGA guideline — yes: a licensee may take crypto as payment for gambling and may not act as an exchange, a PSP or a VASP. The first deadline is a crypto policy on the CGA portal by September 2026. The regulator has not published the official text, so check your own licence conditions with the CGA and counsel.

    How do I verify a gateway may serve EU clients?

    Ask the provider for its legal entity name and the country where it is authorised, then find that entity in the national regulator's CASP register; ESMA keeps a consolidated one. Marketing wording on the gateway's own site is not evidence. And remember: MiCA's transitional period ended on 1 July 2026, and a pending application is not a permission to trade.

    How many confirmations should a deposit need before the balance moves?

    There is no universal number — it is a processing setting and your own risk decision. For orientation, Kraken credits a bitcoin deposit after four confirmations, roughly forty minutes, while on TRON a payment becomes irreversible in about a minute. Compare networks by the time after which a payment cannot be undone: raw confirmation counts are not comparable across chains.

    A player sent a deposit on the wrong network — whose problem is that?

    Yours and your provider's, and it is solved by a procedure written in advance, not by heroic support. Before signing, find out what happens to a transfer on an unsupported network: automatic return, manual recovery for a fee, or refusal — whatever the contract says is what will happen.

    Are a payout and a withdrawal the same fee?

    No. A payout sends money to a third party — usually a player's winnings; a withdrawal moves your own balance to your own wallet or bank. Providers price them as separate products, and they appear as separate lines on rate cards. Use both words in negotiations and ask for a price on each.

    Start accepting crypto payments

    Create an account and connect the checkout yourself, or talk to sales and we will plan the integration with you.