How to Build a Digital Wallet App in 2026: Fiat, Card and Crypto Wallets

In this article
- Pick the wallet type first: a stored-value wallet that holds a dollar balance, a pass-through wallet that holds tokenized cards, or a crypto wallet, custodial or self-custody. Each has its own partners, rules and security model.
- What you protect changes by type: a balance ledger for stored value, card tokens for pass-through, private keys for crypto. Raw card numbers and seed phrases should never reach your servers.
- Regulation follows the money. Closed-loop balances meet gift card and unclaimed property rules, open-loop balances need a partner bank or money transmitter licenses, custodial crypto is money transmission, and self-custody mostly is not.
- A closed-loop brand wallet starts around $60k–140k and 3–5 months, and a basic self-custody crypto wallet around $60k–150k and 4–6 months, with a Central European or Latin American team.
Jump to
- Start with three decisions: what the wallet holds, where it works, who keeps the secrets
- How to build a digital wallet app, step by step
- What you build and what you rent
- Security rules for each kind of wallet
- What goes into the first version
- Timeline and budget at a glance
- Mistakes that cost the most later
- Wallet launch readiness checklist
- Where Gilzor fits
Start with three decisions: what the wallet holds, where it works, who keeps the secrets
Before features, answer three questions. They decide which product you are building:
- What does the wallet hold? A dollar balance, references to cards that live at a bank, or crypto.
- Where can users spend it? Only with your business (closed-loop), anywhere and out to a bank (open-loop), or wherever the card or chain works.
- Who keeps the secrets? You and a partner bank, a card network's token service, a custody partner, or the user's own phone.
The answers put you in one of four wallet types. Sending money between people is its own product with its own rules; we cover it in how to build a P2P payment app.
- Examples: coffee chain and restaurant apps, campus cards, transit and parking balances.
- You rent: card acceptance for top-ups from a processor, sometimes a gift card platform.
- You build: a balance ledger, auto-reload, QR or barcode payment at your point of sale, rewards, an admin panel.
- Watch out: keep it closed. Cash-out or transfers between users turn it into a licensed product. Gift card expiry and fee rules and state unclaimed property laws can apply to balances.
- Examples: prepaid wallets, wallets with a linked debit card, payroll or benefits balances.
- You rent: a partner bank or program manager that holds funds, KYC checks, card issuing if you add a card.
- You build: your own ledger that reconciles with the bank daily, onboarding, funding and withdrawal flows, disputes, the back office.
- Watch out: the CFPB's prepaid account rules under Regulation E bring disclosures and error resolution duties. Holding funds yourself means state money transmitter licenses.
- Examples: checkout wallets that store cards, issuer apps that add cards to Apple Pay and Google Pay, loyalty apps with saved payment methods.
- You rent: a processor's card vault or network tokens (Visa Token Service, Mastercard MDES), Apple Pay and Google Pay.
- You build: card management screens, token lifecycle handling, push provisioning if you issue the cards.
- Watch out: money never sits with you, but card data can. Keep raw card numbers in the processor's hosted fields to keep PCI DSS scope small.
- Examples: self-custody mobile wallets, embedded wallets inside games or apps, custodial wallets inside an exchange or neobank.
- You rent: an MPC or smart account SDK, or a regulated custody partner; RPC nodes and an indexer; a fiat on-ramp.
- You build: key setup and recovery, signing screens, balances and history, address book, transaction warnings.
- Watch out: custodial wallets are money transmission under FinCEN guidance and need KYC. Self-custody mostly is not, but you can't recover a lost key, so recovery design is the product.
Which rules apply depends on what your wallet holds, where users can spend it and who controls the funds or keys. Confirm your model with payments or crypto counsel before you build.
How to build a digital wallet app, step by step
Nine steps, in the order that saves the most rework. The security and recovery decisions come before screens, because they are the hardest to change later.
- Pick one type and one job"Customers prepay and pay in our 200 stores" or "users hold USDC and ETH on two chains" is a product. A wallet that holds dollars, cards and crypto on day one is three products with three sets of partners.
- Choose partners and start onboardingA processor for top-ups, a partner bank or program manager for open-loop balances, a token service or issuer processor for cards, a custody or key management provider for crypto. Approvals take months for regulated partners, so start in week one.
- Map the rules for your typeGift card and unclaimed property rules for closed-loop. Prepaid account rules, KYC and anti-money-laundering duties for open-loop. PCI DSS for anything touching card data. Money transmission and the Travel Rule for custodial crypto. Counsel confirms; the list becomes features.
- Decide where value and secrets liveDraw it before you design: which system is the source of truth for balances, where card tokens sit, where private keys are generated and stored. The figure below shows the usual answers.
- Size onboarding to the typeA closed-loop wallet may need only an email and a card. Open-loop and custodial wallets need identity checks before money moves. A self-custody wallet asks for nothing, while the on-ramp partner handles KYC for crypto purchases.
- Build the core for your typeA double-entry ledger with daily reconciliation for stored value. Token lifecycle handling for pass-through: new tokens when a card is reissued, suspension when a phone is lost. Key generation, signing, broadcasting and history for crypto.
- Harden the deviceBiometrics for payments and sensitive changes, device binding, re-verification on a new phone, app attestation through Apple App Attest and Google Play Integrity, and screenshot blocking on screens that show secrets.
- Design the lost-phone pathRemote sign-out, card token suspension, balance freezes and account recovery for custodial types. For self-custody: encrypted backups, MPC key shares or smart account guardians, tested with real users before launch.
- Test, audit and launch with limitsPen test the app and API, review signing and recovery code, audit any smart contracts, then launch with low limits and watch fraud, support tickets and reconciliation daily.
What you build and what you rent
Every wallet type rents the regulated or cryptographic core and builds the experience around it. A typical split:
| Layer | Usually rented | Usually built |
|---|---|---|
| Top-ups | Processor for card and ACH funding, hosted card fields | Top-up and auto-reload flows, limits, holds |
| Holding funds | Partner bank or program manager for open-loop balances | Your ledger and daily reconciliation |
| Card tokens | Processor vault, network token services, issuer processor | Card screens, token lifecycle, push provisioning flow |
| Identity | KYC vendor: documents, selfies, sanctions screening | Onboarding sized to your type, manual review queue |
| Crypto keys | MPC or smart account SDK, or a regulated custody partner | Key setup, backup and recovery screens, signing UX |
| Blockchain access | RPC node providers, indexers, price data, on-ramp | Balances, history, fee estimates, transaction warnings |
| Back office | Support desk | User view, freezes, refunds, case notes, audit log |
Rented layers bill per user, per transaction or per active wallet. Put those fees next to your revenue model before you sign. For card acceptance, our payment gateway integration cost guide covers the details.
Security rules for each kind of wallet
A wallet is a target the day it launches. The rules differ by type, but every one of them is cheaper to build in than to add after an incident:
- Balances come from a ledger. For stored value, every top-up, payment and refund is an entry. Balances are calculated, never edited, and the ledger reconciles with the bank or processor every day.
- Never touch raw card numbers. Card entry goes through hosted fields and lives in a processor vault or as network tokens. Network tokens also update when a card is reissued, so fewer payments fail.
- Keys stay in hardware. Generate and store private keys in the iPhone's Secure Enclave or the Android Keystore where the design allows. Seed phrases never go to your servers, analytics or crash reports.
- Show what the user signs. Crypto signing screens should show the real amount, recipient, network and any token approval in plain words, and warn on new or flagged addresses. Blind signing is how users get drained.
- Bind devices and step up. Biometrics for payments, re-verification on a new device, app attestation, and a cooling-off period for changes like a new phone number or withdrawal address.
- Don't invent cryptography. Use audited libraries and a proven key management provider. Custom recovery schemes need an external review before real money touches them.
What goes into the first version
A wallet MVP is one type, done safely. A typical split:
| At launch | Can wait |
|---|---|
| One wallet type, one way to add value | Dollars, cards and crypto in one app |
| Ledger with daily reconciliation for stored value | Multi-currency balances and FX |
| Cards through a processor vault or network tokens | Your own token vault |
| Push provisioning to Apple Pay and Google Pay, if you issue cards | Your own tap-to-pay wallet on the phone's NFC chip |
| One or two chain families: send, receive, balances | Swaps, NFTs, staking, dApp connections |
| Biometrics, device binding, lost-phone and recovery flows | Hardware wallet support |
| Back office: user view, freeze, refund, audit log | Self-serve partner reporting |
On platforms: wallets lean on device features (secure hardware, biometrics, NFC, wallet provisioning), so check that your cross-platform framework supports each one through a maintained plugin, or plan native modules for those parts.
Built by Gilzor
Results we’ve shipped




Talk to the people who build it. Tell us about your project and get a free estimate of scope, timeline and cost.
Timeline and budget at a glance
These are builds with a Central European or Latin American team; US onshore teams quote roughly twice as much or more. An embedded crypto wallet on an MPC or smart account SDK can start around $40k, and every type needs about 15–20% of the build per year for maintenance. For the full breakdowns and calculators, see our e-wallet app development cost and crypto wallet development cost guides.
Mistakes that cost the most later
- Letting a closed-loop wallet drift open. Adding cash-out or transfers between users looks like a small feature. It can turn a brand wallet into money transmission, with licenses or a partner bank required.
- Storing card numbers yourself. One database column puts your whole backend in PCI DSS scope. Hosted fields and tokens cost far less than the assessment.
- Planning on push provisioning without issuing cards. Only issuers and their partners get Apple and Google approval for in-app provisioning. Confirm your card program supports it before you design around it.
- Seed phrases in logs and backups. Analytics SDKs, crash reporters and unencrypted cloud backups have leaked secrets before. Audit every SDK that can see the backup screens.
- Forgetting dormant balances. State unclaimed property laws can require you to report and hand over balances left unused for years. Track activity per balance from day one.
- Publishing a crypto wallet from a personal account. Apple's App Review Guidelines allow wallet apps only from developers enrolled as an organization, and Google Play has its own crypto policies by country. Set up company accounts early.
Wallet launch readiness checklist
Tick what is already true for your wallet. It shows how close you are to holding real value for real users.
Wallet launch readiness
FAQ
How do I build a mobile wallet app?
How do I build a crypto wallet app?
How long does it take to build a wallet app?
How much does it cost to build a digital wallet app?
Can my app add cards to Apple Pay and Google Pay?
Do I need a license to launch a wallet app?
Where Gilzor fits
We design and build fintech software: mobile apps and web back offices, onboarding with KYC providers such as Sumsub, transfer and withdrawal flows, and the QA that keeps money paths correct. For KickEX, a crypto exchange app with a multi-currency wallet, our team refactored the app architecture and rewrote unstable code so users could transfer between wallets and withdraw reliably. We work from Poland and Cyprus, with a few shared hours a day with the US East Coast.
Send us what your wallet should hold, where people will spend it and which partners you're already talking to. We'll help you choose the type, map the security model and cut a first version you can launch.
No sales pitch
Get a straight answer for your project
Tell us what you’re building. We’ll reply with options, a rough cost and timeline. If we’re not the right fit, we’ll say so.

CTO of Gilzor. Responsible for architecture and the engineering standards our teams work by.
LinkedIn →Gilzor · Mobile Development partner
Need a team for your mobile app?
Services
Mobile DevelopmentNative and cross-platform iOS and Android apps, from MVP to scale.→By company type
Selected projects






The team behind them





