· 12 min read

How to Build a Digital Wallet App in 2026: Fiat, Card and Crypto Wallets

“Wallet” covers three different products. One holds a dollar balance, one holds tokens for cards that live at a bank, one holds the keys to crypto. They share a home screen and very little else: the security model, the regulation and the partners all change. Here is how to pick your wallet type and build it in the right order, so people trust it with their money.
A wallet with a card and a coin, a phone with a contactless payment signal and a key, illustrating how to build a digital wallet app
Planning a wallet app?Tell us what your wallet holds: dollars, cards or crypto. We’ll map the partners, the security model and a first version you can launch.
Choose my wallet type

Start with three decisions: what the wallet holds, where it works, who keeps the secrets

Before features, answer three questions. They decide which product you are building:

  1. What does the wallet hold? A dollar balance, references to cards that live at a bank, or crypto.
  2. Where can users spend it? Only with your business (closed-loop), anywhere and out to a bank (open-loop), or wherever the card or chain works.
  3. Who keeps the secrets? You and a partner bank, a card network's token service, a custody partner, or the user's own phone.

The answers put you in one of four wallet types. Sending money between people is its own product with its own rules; we cover it in how to build a P2P payment app.

  • Examples: coffee chain and restaurant apps, campus cards, transit and parking balances.
  • You rent: card acceptance for top-ups from a processor, sometimes a gift card platform.
  • You build: a balance ledger, auto-reload, QR or barcode payment at your point of sale, rewards, an admin panel.
  • Watch out: keep it closed. Cash-out or transfers between users turn it into a licensed product. Gift card expiry and fee rules and state unclaimed property laws can apply to balances.
General information, not legal advice

Which rules apply depends on what your wallet holds, where users can spend it and who controls the funds or keys. Confirm your model with payments or crypto counsel before you build.

How to build a digital wallet app, step by step

Nine steps, in the order that saves the most rework. The security and recovery decisions come before screens, because they are the hardest to change later.

  1. Pick one type and one job"Customers prepay and pay in our 200 stores" or "users hold USDC and ETH on two chains" is a product. A wallet that holds dollars, cards and crypto on day one is three products with three sets of partners.
  2. Choose partners and start onboardingA processor for top-ups, a partner bank or program manager for open-loop balances, a token service or issuer processor for cards, a custody or key management provider for crypto. Approvals take months for regulated partners, so start in week one.
  3. Map the rules for your typeGift card and unclaimed property rules for closed-loop. Prepaid account rules, KYC and anti-money-laundering duties for open-loop. PCI DSS for anything touching card data. Money transmission and the Travel Rule for custodial crypto. Counsel confirms; the list becomes features.
  4. Decide where value and secrets liveDraw it before you design: which system is the source of truth for balances, where card tokens sit, where private keys are generated and stored. The figure below shows the usual answers.
  5. Size onboarding to the typeA closed-loop wallet may need only an email and a card. Open-loop and custodial wallets need identity checks before money moves. A self-custody wallet asks for nothing, while the on-ramp partner handles KYC for crypto purchases.
  6. Build the core for your typeA double-entry ledger with daily reconciliation for stored value. Token lifecycle handling for pass-through: new tokens when a card is reissued, suspension when a phone is lost. Key generation, signing, broadcasting and history for crypto.
  7. Harden the deviceBiometrics for payments and sensitive changes, device binding, re-verification on a new phone, app attestation through Apple App Attest and Google Play Integrity, and screenshot blocking on screens that show secrets.
  8. Design the lost-phone pathRemote sign-out, card token suspension, balance freezes and account recovery for custodial types. For self-custody: encrypted backups, MPC key shares or smart account guardians, tested with real users before launch.
  9. Test, audit and launch with limitsPen test the app and API, review signing and recovery code, audit any smart contracts, then launch with low limits and watch fraud, support tickets and reconciliation daily.
Where value and secrets live, by wallet type Closed-loop Open-loop Pass-through Self-custody crypto Your app keeps You protect Value sits at Balance ledgersource of truth Ledger, KYC filereconciled daily Token referencesno card numbers Public addressesand history only Logins andbalances Ledger andidentity data Tokens, devicebinding Private keyson the device Your company'sbank account Partner bank,held for users The user'scard issuer On-chain, at theuser's address A custodial crypto wallet looks like the open-loop column: a custody partner holds the keys, you keep a ledger and a KYC file.
The further right you go, the less money you hold and the more the user's phone matters. Security work moves from your servers to the device.

What you build and what you rent

Every wallet type rents the regulated or cryptographic core and builds the experience around it. A typical split:

LayerUsually rentedUsually built
Top-upsProcessor for card and ACH funding, hosted card fieldsTop-up and auto-reload flows, limits, holds
Holding fundsPartner bank or program manager for open-loop balancesYour ledger and daily reconciliation
Card tokensProcessor vault, network token services, issuer processorCard screens, token lifecycle, push provisioning flow
IdentityKYC vendor: documents, selfies, sanctions screeningOnboarding sized to your type, manual review queue
Crypto keysMPC or smart account SDK, or a regulated custody partnerKey setup, backup and recovery screens, signing UX
Blockchain accessRPC node providers, indexers, price data, on-rampBalances, history, fee estimates, transaction warnings
Back officeSupport deskUser view, freezes, refunds, case notes, audit log

Rented layers bill per user, per transaction or per active wallet. Put those fees next to your revenue model before you sign. For card acceptance, our payment gateway integration cost guide covers the details.

Security rules for each kind of wallet

A wallet is a target the day it launches. The rules differ by type, but every one of them is cheaper to build in than to add after an incident:

  • Balances come from a ledger. For stored value, every top-up, payment and refund is an entry. Balances are calculated, never edited, and the ledger reconciles with the bank or processor every day.
  • Never touch raw card numbers. Card entry goes through hosted fields and lives in a processor vault or as network tokens. Network tokens also update when a card is reissued, so fewer payments fail.
  • Keys stay in hardware. Generate and store private keys in the iPhone's Secure Enclave or the Android Keystore where the design allows. Seed phrases never go to your servers, analytics or crash reports.
  • Show what the user signs. Crypto signing screens should show the real amount, recipient, network and any token approval in plain words, and warn on new or flagged addresses. Blind signing is how users get drained.
  • Bind devices and step up. Biometrics for payments, re-verification on a new device, app attestation, and a cooling-off period for changes like a new phone number or withdrawal address.
  • Don't invent cryptography. Use audited libraries and a proven key management provider. Custom recovery schemes need an external review before real money touches them.

What goes into the first version

A wallet MVP is one type, done safely. A typical split:

At launchCan wait
One wallet type, one way to add valueDollars, cards and crypto in one app
Ledger with daily reconciliation for stored valueMulti-currency balances and FX
Cards through a processor vault or network tokensYour own token vault
Push provisioning to Apple Pay and Google Pay, if you issue cardsYour own tap-to-pay wallet on the phone's NFC chip
One or two chain families: send, receive, balancesSwaps, NFTs, staking, dApp connections
Biometrics, device binding, lost-phone and recovery flowsHardware wallet support
Back office: user view, freeze, refund, audit logSelf-serve partner reporting

On platforms: wallets lean on device features (secure hardware, biometrics, NFC, wallet provisioning), so check that your cross-platform framework supports each one through a maintained plugin, or plan native modules for those parts.

Built by Gilzor

Results we’ve shipped

70+products launched
98%delivered on time
85%clients come back
Art Scherbakov, Co-FounderAndrew Laminsky, CTOYuri Rudenya, Head of Mobile Development at GilzorAlena Timofeeva, Product Marketing Lead

Talk to the people who build it. Tell us about your project and get a free estimate of scope, timeline and cost.

See how we’d approach yours

Timeline and budget at a glance

$60–140kClosed-loop brand wallet, 3–5 months
$220–420kWallet with its own debit cards and Apple Pay and Google Pay provisioning, 7–10 months
$60–150kBasic self-custody crypto wallet, 4–6 months
$200–500kCustodial crypto wallet on a regulated custody partner

These are builds with a Central European or Latin American team; US onshore teams quote roughly twice as much or more. An embedded crypto wallet on an MPC or smart account SDK can start around $40k, and every type needs about 15–20% of the build per year for maintenance. For the full breakdowns and calculators, see our e-wallet app development cost and crypto wallet development cost guides.

Mistakes that cost the most later

  • Letting a closed-loop wallet drift open. Adding cash-out or transfers between users looks like a small feature. It can turn a brand wallet into money transmission, with licenses or a partner bank required.
  • Storing card numbers yourself. One database column puts your whole backend in PCI DSS scope. Hosted fields and tokens cost far less than the assessment.
  • Planning on push provisioning without issuing cards. Only issuers and their partners get Apple and Google approval for in-app provisioning. Confirm your card program supports it before you design around it.
  • Seed phrases in logs and backups. Analytics SDKs, crash reporters and unencrypted cloud backups have leaked secrets before. Audit every SDK that can see the backup screens.
  • Forgetting dormant balances. State unclaimed property laws can require you to report and hand over balances left unused for years. Track activity per balance from day one.
  • Publishing a crypto wallet from a personal account. Apple's App Review Guidelines allow wallet apps only from developers enrolled as an organization, and Google Play has its own crypto policies by country. Set up company accounts early.

Wallet launch readiness checklist

Tick what is already true for your wallet. It shows how close you are to holding real value for real users.

Wallet launch readiness

FAQ

How do I build a mobile wallet app?
Start by choosing the wallet type: a stored-value wallet with a dollar balance (closed-loop for one brand or open-loop for use anywhere), a pass-through wallet that stores tokenized cards, or a crypto wallet. Then pick partners for that type (a processor, a partner bank or program manager, a token service, a custody or key management provider), map the rules with counsel, and design where value and secrets live before any screens. Build the core (a ledger, token lifecycle handling or key management and signing), add device security and a lost-phone path, run a penetration test and launch with limits.
How do I build a crypto wallet app?
Decide on custody first. A self-custody wallet keeps keys on the user's device or splits them with MPC, so you build key generation, secure storage, signing, backup and recovery, plus blockchain access through RPC nodes and an indexer. A custodial wallet holds keys for users through a custody partner, which adds KYC, a ledger, a compliance back office and money transmission questions. Start with one or two chain families, use a proven key management SDK unless custody is your product, and get the signing and recovery code reviewed before launch.
How long does it take to build a wallet app?
A closed-loop brand wallet usually takes 3–5 months, and a wallet that issues its own debit cards with Apple Pay and Google Pay provisioning takes 7–10 months, often paced by partner and card network approvals. An embedded crypto wallet on an MPC or smart account SDK can ship in 2–4 months, a basic self-custody wallet in 4–6 months, and a multi-chain wallet with swaps and dApp connections in 6–10 months.
How much does it cost to build a digital wallet app?
With a Central or Eastern European or Latin American team in 2026: a closed-loop brand wallet costs about $60k–140k, a card-issuing wallet $220k–420k, a basic self-custody crypto wallet $60k–150k, a multi-chain crypto wallet $150k–350k and a custodial crypto wallet on a custody partner $200k–500k. US onshore teams quote roughly twice as much or more. Our e-wallet and crypto wallet development cost guides break each type down.
Can my app add cards to Apple Pay and Google Pay?
Only for cards you issue. Push provisioning, the Add to Apple Wallet or Add to Google Pay button inside your app, is available to card issuers and their program partners after approval from Apple and Google. If you don't issue cards, users add their own cards to Apple Pay or Google Pay, and your app can accept those wallets at checkout. Since iOS 18.1, Apple also lets approved developers in some countries, including the US, use the iPhone's NFC chip for in-store payments under a commercial agreement and fees.
Do I need a license to launch a wallet app?
It depends on the type. A closed-loop wallet spendable only with your own business usually needs no money transmitter license, though gift card and unclaimed property rules can apply. An open-loop wallet that holds money users can spend anywhere or withdraw generally needs a partner bank or state money transmitter licenses. A pass-through wallet leaves money with the card issuer. Custodial crypto wallets are treated as money transmission, while software for self-custody wallets generally is not. This is general information, not legal advice: confirm your model with counsel.

Where Gilzor fits

We design and build fintech software: mobile apps and web back offices, onboarding with KYC providers such as Sumsub, transfer and withdrawal flows, and the QA that keeps money paths correct. For KickEX, a crypto exchange app with a multi-currency wallet, our team refactored the app architecture and rewrote unstable code so users could transfer between wallets and withdraw reliably. We work from Poland and Cyprus, with a few shared hours a day with the US East Coast.

Send us what your wallet should hold, where people will spend it and which partners you're already talking to. We'll help you choose the type, map the security model and cut a first version you can launch.

No sales pitch

Get a straight answer for your project

Tell us what you’re building. We’ll reply with options, a rough cost and timeline. If we’re not the right fit, we’ll say so.

Next, a few optional questions so the first call is useful. We use your details only to reply to your request. Privacy Policy

Andrew Laminsky
Written byAndrew Laminsky

CTO of Gilzor. Responsible for architecture and the engineering standards our teams work by.

LinkedIn →

Gilzor · Mobile Development partner

Need a team for your mobile app?

95%referred by business partners
70+successful launches
85%repeat business
98%delivered on time

The team behind them

Art Scherbakov
Art ScherbakovCo-Founder
Andrew Laminsky
Andrew LaminskyCTOLinkedIn
Yuri Rudenya
Yuri RudenyaHead of Mobile Development at GilzorLinkedIn
Alena Timofeeva
Alena TimofeevaProduct Marketing LeadLinkedIn
Tell us what you’re buildingOptions, a rough cost and timeline for your project. No commitment.

More insights