Mila Jovanović
Berlin, Germany
Oct 6, 2026

A crypto checkout can look like a payment processor without performing the same job. It may calculate an amount, display a wallet address and watch a blockchain for confirmation, while the customer alone authorizes the transfer. The regulatory question starts where that software acquires a different power: to move assets, act for a customer or take responsibility for executing the payment.

That distinction is central to a claimed reversal involving Germany’s Federal Financial Supervisory Authority, BaFin, and EcomTrade24. The notice identified as BaFin’s October 5, 2026 clarification is said to withdraw an earlier warning concerning the company’s website and “EcomTrade24 Pay Gateway” app. The withdrawal and its precise wording require verification before they can be treated as an established regulatory development. The underlying legal question, however, is consequential for wallet developers and merchants building stablecoin checkout systems.

A checkout is not necessarily an intermediary

Consider a straightforward wallet-to-merchant payment. A checkout generates a request specifying the asset, amount, destination and blockchain. The customer reviews that request in a wallet and signs the transaction. The network processes it, and the merchant’s software detects receipt.

In that arrangement, the checkout provider may never receive the assets or hold a key capable of spending them. Its contribution is information and coordination rather than custody. That distinction deserves more attention than the familiar payment button through which the customer experiences the transaction.

But the absence of custody does not settle every licensing question. A provider could arrange or execute transfers on a customer’s behalf without maintaining a conventional custodial wallet. An operator might also control a smart contract, possess an administrative key or have authority to substitute a destination address. Each capability changes the technical facts that a legal assessment must examine.

The useful question is therefore not simply whether a product is “non-custodial.” It is what the operator can do, for whom it does it and under what agreement.

Two regulatory frameworks, different tests

Germany’s Payment Services Supervision Act, or ZAG, governs payment services. At EU level, the Payment Services Directive, PSD2, recognizes that technical support is not automatically a payment service. Article 3(j) excludes certain technical services that support payment services without the provider entering into possession of the funds being transferred.

That provision is not a blanket exemption for software businesses. It expressly excludes payment initiation and account information services from that technical-services exclusion. The distinction illustrates why “we never hold the money” can be an important fact without being a complete legal answer.

Crypto-asset activity requires a separate assessment under the Markets in Crypto-Assets Regulation, MiCA. Its regulated services include custody and administration, but also exchange, execution of orders and transfer services for crypto-assets on behalf of clients. Article 59 establishes authorization requirements for providing crypto-asset services, subject to the regulation’s provisions for certain existing financial institutions.

A checkout that merely prepares information for a transaction is not necessarily providing one of those services. Equally, a provider cannot establish that it falls outside MiCA simply by showing that customers retain their private keys. The service it actually supplies remains decisive.

Stablecoins add another layer. Under MiCA, e-money tokens—tokens referencing the value of a single official currency—are deemed electronic money. Not every asset marketed as a stablecoin belongs to that category, and the legal analysis must identify both the token and the activity rather than treating all blockchain payments alike.

Follow the powers, not the branding

For developers, the most useful starting point is a transaction diagram that includes failure cases. Who selects the destination? Who signs? Can anyone change the amount, reroute the transfer or spend assets held in a contract? What happens when a customer pays on the wrong network, requests a refund or disputes whether the merchant received the payment?

The contractual map matters alongside the technical one. A software supplier that reports an on-chain confirmation occupies a different position from a business promising to settle a merchant’s receivable. Likewise, an independently licensed partner’s role should be distinguished from the checkout operator’s own obligations. Outsourcing one stage of a payment does not, by itself, explain the legal status of every other stage.

For innovation, this is a more productive approach than classifying every wallet connection as financial intermediation. Regulation should attach to identifiable activities and powers, not to the appearance of a checkout screen. Developers benefit from clear boundaries; customers benefit when responsibility is assigned to the entity that can actually intervene.

If authenticated, an EcomTrade24 withdrawal would be significant as a correction of a specific supervisory assessment. It would not establish a general exemption for non-custodial checkout products, nor would it eliminate the need to examine their implementation and contractual role.

Source verification: The EcomTrade24 notice linked above was supplied as the underlying official source, but its contents and the alleged July 30 and October 5, 2026 actions could not be independently verified here. No quotation or case-specific legal conclusion is therefore attributed to BaFin as confirmed. A withdrawal of an authorization warning, if verified, would also not constitute an endorsement of a product’s security or a guarantee that users can recover lost funds.