Skip to content
Payfim - Secure. Simple. Yours.
Security

Secure Crypto Checkout: 15 Best Practices for Merchants

A secure crypto checkout rests on three rules: keep spending keys off your web server, let the server (never the browser) decide prices and payment status, and verify every notification before you release goods. The 15 practices below turn those rules into concrete settings and habits.

PFPayfim Team · September 22, 2026 · 9 min read
Secure Crypto Checkout: 15 Best Practices for Merchants
Key takeaways
  • The biggest risk is not the checkout page; it is where your private keys live. Keep them in a hardware or non-custodial wallet, never on the server.
  • Invoices should be created server to server, and payment notifications should be signed and re-checked before an order is marked paid.
  • Lock down the gateway admin with 2FA, an IP allowlist, HTTPS and up-to-date PHP.
  • Most real-world losses come from people, not code: poisoned addresses, fake "I overpaid" refund requests and shared logins.

Crypto payments cannot be charged back, which removes one kind of fraud and makes every other mistake permanent. If a price is tampered with, a fake payment notice is believed or a refund goes to the wrong address, there is no bank to call. The good news is that most of the protection comes from a few design choices and habits. Work through this list once and revisit it whenever you change hosting or staff.

How do you protect the wallets that receive payments?

1. Keep private keys off the web server

Your checkout only needs public receiving addresses. Any tool that asks for a seed phrase or private key to "receive" payments is a red flag. Payfim stores public addresses only (and, for Monero, a view-only key or your own wallet RPC), so even a fully compromised server has nothing it can spend.

2. Use a hardware wallet or a non-custodial wallet you control

For meaningful volume, a hardware wallet is worth the cost. Write the recovery phrase on paper or metal, store it offline, and never type it into a website, a support chat or a "wallet validation" form.

3. Never receive into an exchange deposit address

Exchange deposit addresses can change, may not credit unexpected amounts, and put your money under someone else's terms. Receive into your own wallet, then move funds to an exchange when you choose.

4. Separate business funds from personal funds

Use wallets dedicated to the business. It keeps your accounting clean and limits the blast radius if one device is compromised.

How do you stop price tampering and fake payments?

5. Create invoices server to server

A common weakness in simple crypto plugins is building the payment amount in the customer's browser. Anyone with developer tools can change it. In Payfim, your store asks the gateway to create the invoice over an authenticated API call, using the order total from the store's database. The browser only ever sees the result.

6. Verify signatures on every webhook

Payment notifications should prove they came from your gateway. Payfim signs each webhook with HMAC-SHA256 over a timestamp and the exact request body, and the official modules reject anything unsigned, wrongly signed or older than five minutes. If you build your own integration with the PHP & Laravel SDK or the API, verify the raw request body, not a re-encoded copy.

7. Re-check the invoice before fulfilling

A valid signature proves who sent the message, not that the message is still accurate. Payfim's modules read the invoice back from the gateway and compare the amount and currency with the order before marking it paid. If you fulfil orders with custom code, do the same.

8. Never count one transaction twice

Each blockchain transaction should pay exactly one invoice. Payfim stores transaction hashes with a database uniqueness constraint, and platforms like WHMCS additionally reject duplicate transaction IDs. If you ever mark an invoice paid by hand, include the transaction hash so the record is complete.

9. Choose confirmation counts that match your risk

Releasing a $1,000 item on an unconfirmed transaction invites trouble. Keep the per-coin defaults for everyday orders and raise them for high-value ones. Our confirmations guide explains the trade-off.

How do you harden the gateway server?

10. Serve everything over HTTPS

The gateway, the payment page and the store's webhook URL must all use HTTPS. Payfim requires it. A free certificate from your host is fine.

11. Lock the admin area

Turn on two-factor authentication for every gateway admin, and use the admin IP allowlist if your team works from fixed addresses. Use unique, long passwords and a password manager. Payfim also rate-limits sign-in attempts and logs sign-ins and sensitive changes, so review that log after staff changes.

12. Keep PHP, the gateway and your store updated

Payfim runs on PHP 7.4 to 8.4. Prefer a currently supported PHP version, apply gateway and module updates (12 months are included with your license), and keep your store's own plugins patched. Installing the gateway on its own subdomain, such as pay.yourstore.com, keeps it separate from the rest of your CMS.

13. Back up the gateway database

Your wallets hold the money, but the gateway database holds the link between transactions and orders. Include it in your nightly backups so you can prove which payment belonged to which customer.

Which human mistakes cost merchants the most?

14. Don't copy addresses from transaction history

Address poisoning works by sending you a tiny transaction from an address that shares the first and last characters with one you trust, hoping you will copy it later. When you refund a customer or pay a supplier, take the address from the original invoice, an email or a signed message, and compare it character by character, not just the ends.

15. Treat refund requests as a verification step

A classic scam: someone claims they "accidentally sent too much" and asks for the difference back, sometimes to a new address. Before refunding anything, open the invoice in your gateway, confirm the transaction hash and amount on a block explorer, and refund only to an address the customer confirms in writing. Our refund guide has a full procedure.

What should your team check every week?

Security is also routine. A five-minute weekly review catches most problems before customers do:

What should you do if you suspect a breach?

Because the gateway holds no spending keys, a breach of your web server is serious but not catastrophic for your funds. Act in this order:

  1. Check your receiving addresses. Open Wallets & coins and compare every address with the one in your wallet app. An attacker's most valuable move is to swap an address so new customers pay them. If anything differs, disable the checkout until it is fixed.
  2. Rotate credentials. Change admin passwords, reset 2FA, regenerate the store API key in Integrations and update it in every connected store.
  3. Review recent invoices. Look for invoices marked paid by hand, unusual notes or changes in the audit log.
  4. Restore or rebuild. Restore clean files from a backup or reinstall the gateway, then apply every pending update.
  5. Tell affected customers if any of them may have paid a wrong address, and get advice on any notification duties that apply to you.

How can you help customers pay safely?

Your customers face their own risks, and a lost customer payment still becomes your support ticket. Show the network name next to every coin ("USDT on TRON (TRC20)"), encourage scanning the QR code instead of typing, and ask them to check the first and last several characters of the address after pasting, because clipboard-swapping malware exists. Payfim's checkout runs on your own domain with your branding, which helps customers recognize a genuine page. Never send payment addresses through channels you cannot control, such as unverified chat accounts.

Where can you learn more?

The Payfim security overview documents how the gateway itself is built, including signed license checks with a 72-hour grace period, CSRF protection and session handling. The how it works page traces a payment from order to confirmation. If you are still choosing an architecture, self-hosted vs hosted gateways compares where the risks sit in each model.

Frequently asked questions

Is it safe to install a crypto gateway on shared hosting?

It can be, as long as the gateway never holds private keys. Payfim only stores public addresses, so a compromised hosting account cannot move your funds. Use HTTPS, 2FA and current PHP versions.

Can someone fake a payment notification to my store?

Not with signed and re-checked webhooks. Payfim signs each notification with HMAC-SHA256, and the modules also re-read the invoice from your gateway before marking an order paid.

What is address poisoning?

A scam where an attacker sends a tiny transaction from an address that looks like one you use, hoping you copy it from your history later. Always copy addresses from a trusted source and check every character.

Should I enable the admin IP allowlist?

If your team signs in from fixed IP addresses, yes. It blocks sign-in attempts from anywhere else. If you travel or use changing connections, rely on strong passwords and 2FA instead.

What happens if my license check fails?

Checkout keeps working for a 72-hour grace period while you fix it, and an outage at payfim.com never blocks payments.

Accept crypto on your store today

Self-hosted, non-custodial, zero fees. Lifetime license.