noKYCme

Case file · Card

CinCin

A Telegram-run, no-KYC card that exploited a bank’s corporate-card loophole - and stopped working within about a day of a reporter contacting the sponsor bank in March 2026. The fastest death in the category.

Defunct · avoid
Based
Sonder Inc. (Marshall Islands); via Sutton Bank / Bluebanc corporate-card loophole
Price
Defunct - cards stopped working ~March 2026 after media contacted the sponsor bank
Site
cincin.io (defunct)
Reviewed
2026-07-21
Audited by
The noKYCme Bureau

The systematized overview

The bureau vs the internet.

What the bureau found

2.4/10 · Was no-KYC (grey-market)

CinCin was a no-KYC card run through a Telegram chatbot by Sonder Inc. (Marshall Islands), funded with crypto and issued by exploiting Sutton Bank’s corporate-card program via program manager Bluebanc. It advertised no ID and a $2,000,000-per-card monthly limit - and it stopped working within roughly a day of a reporter contacting Sutton and Bluebanc in March 2026. It is defunct, and a textbook example of how fast a grey-market card dies once the sponsor bank is alerted.

What the internet says

1 recurring praises · 2 recurring gripes

Most praised: was no-kyc while briefly live. Most cited downside: died within about a day of press contact.

We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.


The facts

Issuer, custody & load terms.

Issuer / BIN
Sutton Bank via program manager Bluebanc (corporate-card loophole); operator Sonder Inc.
Custody
Custodial (defunct)
KYC trigger
None - Telegram sign-up, no user verification
Card type
Crypto card via Telegram (defunct)
Load method
Funded with USDT-Tron, BTC, ETH (while operating)
Limits
Advertised $2,000,000 per card per month (while operating)
Fees
~$25 USDT issuance + $2.25 network fee, 4.5% crypto top-up (while operating)
Coins
USDT-Tron, BTC, ETH, $TRUMP (no Monero)
Payment privacy
Was no-KYC via Telegram; no Monero support
Availability
Defunct since ~March 2026
Freezes / voids if
Cards disabled when the sponsor bank was alerted
Since
Briefly operating; defunct ~Mar 2026

The full read

Our analysis, in plain words.

CinCin is the shortest-lived card in this audit, and that brevity is the entire lesson. Operated by Sonder Inc. through a Marshall Islands entity, it marketed a no-KYC card via a Telegram chatbot, funded with crypto and issued by exploiting Sutton Bank’s corporate-card program through program manager Bluebanc. It even advertised a $2,000,000-per-card monthly limit - the kind of number that should itself be a warning.

Its cards worked mid-Friday and had stopped by mid-Saturday, after a reporter contacted Sutton and Bluebanc. That is the grey-market card lifecycle compressed into 24 hours: an offshore operator, a Telegram sign-up, and a card whose existence depended entirely on a sponsor bank not noticing a loophole. The moment someone with authority looked, it was over, with no consumer recourse of any kind.

We retain CinCin as defunct because it and its sibling PayWithUs explain the structural fragility better than any live card can. When "no-KYC" is manufactured by quietly routing consumers through a bank’s corporate-card rails, the product is not a business so much as a countdown. CinCin’s countdown was about a day.


The score, broken down

How the 2.4 is built.

Privacy 1.8Trust 0.5Reliability 0.2 Headroom 7.6

Privacy

weight 50%

What identity, data and metadata the service can demand or collect.

35/100

35 × 50% = 1.8 of 10

Trust

weight 30%

Whether it can technically deliver what it claims — code, audits, age.

16/100

16 × 30% = 0.5 of 10

Reliability

weight 20%

Whether the no-KYC claim holds under real-world pressure.

8/100

8 × 20% = 0.2 of 10

Weighted total 2.4 / 10 · no reliability rule triggered, so the score stands. See the rubric →


Every point, sourced

What earned the score.

Privacy

  • +4Was no-KYC, sign-up via a Telegram chatbot / mini-app
  • +-5Anonymity depended on exploiting a bank’s corporate-card program
  • +-2USDT-Tron / BTC / ETH; no Monero

Trust

  • +-3Operated by Sonder Inc. via a Marshall Islands entity and Telegram
  • +-6Exploited Sutton Bank’s corporate-card loophole via Bluebanc
  • +-7Cards stopped working ~1 day after media contacted the sponsor bank

The fine print, read for you

The clause they bury.

Verbatim — the trapdoor
“According to Fintech Business Weekly, CinCin exploited Sutton Bank’s corporate-card program via program manager Bluebanc; its cards worked mid-Friday and had stopped by mid-Saturday after media inquiries reached the bank.”

What it meansCinCin shows the grey-market card lifecycle at its most compressed: a no-KYC card built on a sponsor bank’s corporate-card program, live one day and dead the next once the bank was alerted. There is no consumer recourse in a model like this - the entity is offshore, the sign-up is a Telegram bot, and the whole thing rests on a loophole that closes the moment anyone with authority looks.

Read the source →
KYC trigger threshold

CinCin required no ID - sign-up was a Telegram chatbot - because it rode Sutton Bank’s corporate-card program through program manager Bluebanc rather than verifying users itself. That made it no-KYC and extremely fragile; it stopped working within about a day of press contact and is now defunct.

Policy review — point by point

  • Corporate-card loophole

    CinCin rode Sutton Bank’s corporate-card program via Bluebanc rather than issuing compliantly - the mechanism that made it no-KYC and doomed.

  • Killed within a day

    Cards stopped working within roughly 24 hours of a reporter contacting the sponsor bank in March 2026.

Jurisdiction analysis

CinCin was operated by Sonder Inc. through a Marshall Islands entity, with sign-up via Telegram - a structure that offers users no recourse. Its no-KYC access depended on exploiting Sutton Bank’s corporate-card program via program manager Bluebanc, and ended when the bank was alerted. It is defunct; this dossier is a documented cautionary case only. The money-laundering framing in the source reporting is the journalist’s characterisation.


We keep watching

Incident & policy timeline.

  1. 2026

    No-KYC card via Telegram, on a corporate-card loophole

    Sonder Inc. (Marshall Islands) marketed CinCin as a "KYC-free" card, sign-up via Telegram, funded with USDT-Tron/BTC/ETH, issued by exploiting Sutton Bank’s corporate-card program through program manager Bluebanc. It advertised a $2,000,000-per-card monthly limit.

    source ↗
  2. Mar 2026

    Cards stopped working within about a day of media contact

    After a reporter contacted Sutton Bank and Bluebanc, CinCin’s cards - working mid-Friday - had stopped by mid-Saturday. The service is defunct.

    source ↗

The verdict

Where it stands.

Strengths

  • Was no-KYC while it briefly operated

Trade-offs

  • Defunct - cards stopped working ~March 2026
  • Built on exploiting a sponsor bank’s corporate-card program
  • Offshore Telegram operation with no consumer recourse
  • No Monero support
Flagged as defunct — we do not link to it. Do not send funds.

Across the internet

What reviewers report.

Consistently praised

  • Was no-KYC while briefly live

Recurring complaints

  • Died within about a day of press contact
  • Offshore Telegram operation with no recourse

CinCin’s only substantive coverage is the Fintech Business Weekly report documenting how quickly it collapsed once the sponsor bank was contacted. Retained as a defunct cautionary example.


Keep exploring

Related lists & categories.


Ask the bureau

CinCin, common questions.

Does CinCin still work?

No. CinCin’s cards stopped working within roughly a day of a reporter contacting the sponsor bank in March 2026. It is defunct; we list it only as a cautionary case and do not link to it.

How did CinCin offer no KYC?

It did not verify users itself - it rode Sutton Bank’s corporate-card program via program manager Bluebanc, with sign-up through a Telegram chatbot. That loophole is what made it no-KYC, and closing it is what killed the cards overnight.

Is CinCin safe?

It no longer operates, so there is nothing to use safely. While live it was an offshore, Telegram-run card with no consumer recourse, whose existence depended on a bank not noticing - the opposite of safe.

Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.