How your payouts are protected at Paysell
What happens to a withdrawal request after you hit the button: automated anti-fraud checks, isolated signing, cold storage — and the part that is up to you.
- Published
- 12 Sep 2026
- Reading time
- 2 min read
On this page
Withdrawals are the most sensitive operation any payment service performs — they are exactly what an attack on a merchant account is aiming for. Here is what happens to a request after you press "Withdraw", and why the money ends up with you.
What happens after you request a payout#
You create the request in the dashboard: asset, amount, destination address. If two-factor authentication is on, a TOTP code is required as well — for payouts that is a hard requirement, not an option you can skip.
The request then goes through automated checks: balance and limits, the destination address, account behaviour. After that the transaction is signed — and this is the part that matters: the application has no access to the keys. Signing happens in a separate, isolated service with no public interface and no way to send money anywhere other than the approved request. Even a full compromise of the web layer does not let an attacker sign someone's payout.
The layers that are always on#
Hot and cold storage#
Hot wallets hold only a working balance — enough for current payouts. Everything above that moves to cold storage automatically, where the online perimeter cannot reach it at all. That caps the worst case for any attack on the infrastructure.
Destination address screening#
USDT issuers do freeze addresses tied to sanctions lists and documented fraud — this happens in practice. A payout to a "tainted" address creates a problem for everyone: you, the recipient and us. So the destination is screened before the transfer goes out, not after the funds are already frozen.
Anti-fraud on unusual requests#
Account takeover looks predictable: a brand-new withdrawal address, an amount unlike the store's normal activity, an attempt to drain the balance at once. Requests like that are held for an additional check — a rare event, but it is the one that separates "the money went to an attacker" from "the money stayed yours".
The part that is up to you#
Three things make withdrawals faster and your account harder to take over:
- Turn on 2FA. A request confirmed with a TOTP code is a far stronger signal that it is really you than a password alone.
- Withdraw to the same address. Changing it is a normal thing to do, but the first payout to a new address gets a closer look.
- Keep your store profile complete and current. An account with no gaps in its data clears checks faster.
The point: none of this exists to make withdrawals harder. It exists so that the payout reaches you, and only you.
If a payout is taking longer than you expected, open a ticket from the dashboard — we will look at that specific request and tell you where it stands.
Start accepting USDT and TON
A merchant account, an API key and a hosted checkout page — 0.2% per payment, no monthly fee.
Create an account