A review of the FGS Software Solutions casino cluster shows a repeatable deposit architecture: (1) “instant bank transfer” flows that appear to convert depositsA review of the FGS Software Solutions casino cluster shows a repeatable deposit architecture: (1) “instant bank transfer” flows that appear to convert deposits

The FGS Casino Stack — Fake “Instant Bank Transfer” Rail And PayOp With Visa’s Tinker!

2026/01/21 15:15
5분 읽기

FinTelegram’s Rail Atlas review of the FGS Software Solutions casino cluster (Monixbet, Rakoo Casino, VoltSlot) shows a repeatable deposit architecture: (1) “instant bank transfer” flows that appear to convert deposits into USDC via a crypto rail (Rillpay → Kryptonim), (2) an open-banking stack where PayOp routes players into Visa-owned Tink and onward to Revolut’s open-banking interface, and (3) an alternative “instant banking” path using Contiant and a misspelled gateway domain (paymentproccesing.net), plus MiFinity deposits settling to FairGame G.P. N.V. as payment recipient.


Key Facts (Observed + Corroborated)

  • Same rail pattern across multiple casinos: Monixbet, Rakoo Casino, and VoltSlot present largely identical cashier options (bank + crypto + “instant” variants).
  • Payment recipient surfaced in flows: Screenshots show deposits directed to FairGame G.P. N.V. (Curaçao) as the receiving party in at least some rails (MiFinity; PayOp/Tink flow wording).
  • Open-banking rail chain: PayOp → Tink (via link.tink.com) → Revolut OBA (oba.revolut.com) → payment to FairGame G.P. N.V.
  • Contiant appears in the same ecosystem: A misspelled gateway domain paymentproccesing.net appears in cashier flow, and Similarweb signals show monixbet.com among the referring sites to paywith.contiant.com (small but present).
  • PayOp ↔ iGaming positioning: PayOp markets iGaming payment services and its documentation/terms reference its operating entity.
  • Tink is a Visa-owned open-banking provider (Visa completed acquisition) and markets payment-initiation/open-banking capabilities, including iGaming use-cases.

Rail Map Snapshot (How the Money Moves)

1) “Instant Bank Transfer” that behaves like a crypto on-ramp

Player selects: “Direct Bank Transfer / Instant Bank Transfer” (casino cashier label)
Observed stack (from our testing notes + cashier UI):
Rillpay → Kryptonim → USDC → casino wallet(s)
Why it matters: This is a pattern we see repeatedly in offshore casino environments: a bank-transfer UI that is operationally fulfilled by a crypto purchase (stablecoins), reducing traditional card/acquirer visibility and potentially shifting AML/KYC responsibilities onto the crypto leg.

Kryptonim context: Kryptonim publicly states it holds a VASP licence entry number and references multiple entity registrations.


2) Open Banking rail: PayOp → Tink → Revolut OBA → FairGame G.P. N.V.

Player selects: PayOp in cashier
Observed flow (screenshots):

  • PayOp modal routes user into Tink (link.tink.com) and explicitly states that FairGame G.P. N.V. uses Tink to process the payment.
  • User is then redirected to Revolut’s open banking authorization page (oba.revolut.com) showing “Authorize Tink AB.”
    Interpretation: This is consistent with a PIS/AIS-style account-to-account payment initiation flow where Tink acts as the open-banking layer and Revolut’s OBA is the bank-side consent/auth step.

Tink context: Visa completed the acquisition of Tink, and Tink markets open-banking payment initiation (including iGaming-related use cases).

PayOp context: PayOp’s own materials position it in high-risk/iGaming processing, and its terms identify the operator entity.


3) Contiant rail via misspelled gateway domain: Monixbet → paymentproccesing.net → (Contiant / Bank selection / Revolut OBA)

Player selects: “Instant Bank Transfers” (casino cashier label)
Observed indicators:

  • The browser status bar shows requests to paymentproccesing.net (note the double “cc”), suggesting an intermediary deposit page/gateway.
  • Similarweb signals show monixbet.com appears among referrers to paywith.contiant.com (small share), linking this casino into the same Contiant gateway ecosystem you previously mapped.
  • Your prior Contiant work established Contiant as a “technical” pay-by-bank layer in front of regulated open-banking rails, with a notable Benelux footprint.

Contiant context: Contiant’s own merchant documentation identifies the company as a Bulgarian entity and describes AIS/PIS technical services positioning.


4) MiFinity rail: Monixbet → paymentproccesing.net → MiFinity → FairGame G.P. N.V.

Observed (screenshots):

  • A MiFinity-branded deposit page hosted at paymentproccesing.net shows “Deposit to FairGame G.P. N.V.” and the MiFinity support email contact.
  • MiFinity context: MiFinity states it is dual-licensed (UK FCA + Malta MFSA) and its legal terms identify MiFinity UK Limited as an FCA-authorised EMI (Register Ref. 900090).

Who is the “Payment Agent” here? (FairGame G.P. N.V.)

Our testing indicates that FairGame G.P. N.V. (Curaçao) appears as the named recipient/payment agent in multiple deposit rails (PayOp/Tink flow wording; MiFinity deposit page). That is a key compliance signal: it suggests consolidation of player funds at a central entity that may sit between the casino brand and upstream PSP/open-banking providers.

Verification targets:

  • bank beneficiary details (IBAN/BIC), merchant IDs, PayOp/Tink “client_id” mappings, and settlement statements showing where funds land and under what descriptor.

Why This Matters (Compliance Lens)

  1. Benelux exposure + open-banking chokepoints
    Our earlier Contiant traffic intelligence suggested a strong Netherlands/Belgium banking footprint. If these rails are used to fund offshore casinos that appear to be offered into NL/BE without local authorisation, that is a high-sensitivity corridor for regulators and banks.
  2. Open-banking providers can become the “quiet rail” for high-risk merchants
    Even where the open-banking layer is regulated (e.g., Tink as a payment institution and MiFinity as an EMI), risk concentrates at the edges: merchant onboarding, MoR identification, and monitoring of downstream brand networks and affiliate funnels.
  3. Gateway opacity is a recurring red-flag pattern
    The use of thin, sometimes oddly named domains (e.g., paymentproccesing.net) as cashier gateways complicates consumer recognition, dispute handling, and third-party monitoring. It also raises questions about who controls the payment page and what scripts/vendors are embedded.

Call for Information (Whistle42)

If you have direct evidence about these rails—PayOp/Tink onboarding records, merchant contracts, settlement statements, MoR documentation, bank beneficiary details, gateway operator identity for paymentproccesing.net, or correspondence with compliance teams—please submit it via Whistle42.com. We are specifically looking for: (1) PayOp account/merchant IDs, (2) Tink client_id mappings and service agreements, (3) bank transfer descriptors and beneficiary IBANs, (4) proof of who controls the cashier gateway domains, and (5) any regulator notices, chargeback/dispute logs, or account closures linked to these flows.

Share Information via Whistle42
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, [email protected]으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

추천 콘텐츠

Shiba Inu Leader Breaks Silence on $2.4M Shibarium Exploit, Confirms Active Recovery

Shiba Inu Leader Breaks Silence on $2.4M Shibarium Exploit, Confirms Active Recovery

The lead developer of Shiba Inu, Shytoshi Kusama, has publicly addressed the Shibarium bridge exploit that occurred recently, draining $2.4 million from the network. After days of speculation about his involvement in managing the crisis, the project leader broke his silence.Kusama emphasized that a special ”war room” has been set up to restore stolen finances and enhance network security. The statement is his first official words since the bridge compromise occurred.”Although I am focusing on AI initiatives to benefit all our tokens, I remain with the developers and leadership in the war room,” Kusama posted on social media platform X. He dismissed claims that he had distanced himself from the project as ”utterly preposterous.”The developer said that the reason behind his silence at first was strategic. Before he could make any statements publicly, he must have taken time to evaluate what he termed a complex and deep situation properly. Kusama also vowed to provide further updates in the official Shiba Inu channels as the team comes up with long-term solutions.Attack Details and Immediate ResponseAs highlighted in our previous article, targeted Shibarium's bridge infrastructure through a sophisticated attack vector. Hackers gained unauthorized access to validator signing keys, compromising the network's security framework.The hackers executed a flash loan to acquire 4.6 million BONE ShibaSwap tokens. The validator power on the network was majority held by them after this purchase. They were able to transfer assets out of Shibarium with this control.The response of Shibarium developers was timely to limit the breach. They instantly halted all validator functions in order to avoid additional exploitation. The team proceeded to deposit the assets under staking in a multisig hardware wallet that is secure.External security companies were involved in the investigation effort. Hexens, Seal 911, and PeckShield are collaborating with internal developers to examine the attack and discover vulnerabilities.The project's key concerns are network stability and the protection of user funds, as underlined by the lead developer, Dhairya. The team is working around the clock to restore normal operations.In an effort to recover the funds, Shiba Inu has offered a bounty worth 5 Ether ($23,000) to the hackers. The bounty offer includes a 30-day deadline with decreasing rewards after seven days.Market Impact and Recovery IncentivesThe exploit caused serious volatility in the marketplace of Shiba Inu ecosystem tokens. SHIB dropped about 6% after the news of the attack. However, The token has bounced back and is currently trading at around $0.00001298 at the time of writing.SHIB Price Source CoinMarketCap
공유하기
Coinstats2025/09/18 02:25
Rising Altcoin Inflows Signal Potential Market Sell-Off: CryptoQuant

Rising Altcoin Inflows Signal Potential Market Sell-Off: CryptoQuant

        Highlights:  Inflows of altcoins in exchanges have surged by 22% in early 2026. An increase in deposits indicates a growing sell-side pressure. The 
공유하기
Coinstats2026/02/22 02:03
The Strategic Impact of Health Tech on Healthcare Infrastructure and Service Delivery

The Strategic Impact of Health Tech on Healthcare Infrastructure and Service Delivery

Health tech has become a foundational element in strengthening healThe Strategic Impact of Health Tech on Healthcare infrastructure and improving service delivery
공유하기
Techbullion2026/02/22 02:52