A free checklist. Two vendors. Zero automation. And a hidden sales funnel.
On July 27, 2026, NOWPayments and BlockSec dropped a 9-domain, 25-item security checklist for crypto payment acceptance. The press release reads like an industry service: "protect your payment flow," "reduce attack surface," "a shared record of responsibilities."

I downloaded it. I read every control item. And I saw something the hype cycle missed.
The checklist is not a tool. It's a lead magnet dressed in security jargon.
Let me be clear: the code does not lie; only the auditors do. But here, there is no code. There is only a document. And documents can be weaponized for sales just as easily as for security.
Context: The Crypto Payment Security Void
Accepting crypto payments is trivial. A few API calls, a wallet integration, and you're live. Protecting that flow is not trivial. Weak key management, unverified transaction approvals, missing on-chain monitoring — these are the silent killers of merchant funds.
Andy Zhou, BlockSec co-founder and CUHK professor, correctly identified the problem: "Companies often rush to accept crypto without addressing fundamental security gaps." The solution? A checklist that covers private key security, smart contract risks, transaction validation, identity/account operations, DNS/domain security, on-chain monitoring, AML/CFT compliance, stablecoin freeze risk, and continuous improvement.
At face value, it's a comprehensive map. But maps don't protect you. You need a vehicle — and the vehicle is not included.
Core: Systematic Teardown — What the Checklist Gets Right and Wrong
I trace the flow; you trace the lies. Let's trace the checklist's flow.
Strengths: - Structured knowledge: It condenses years of security best practices into 25 checkpoints. For a startup with zero security team, that's a starting point. - Cross-departmental: The press release emphasizes engineering, compliance, and operations should use it together. That's rare and valuable. - Risk coverage: Stablecoin freeze risk and AML/CFT technical compliance are often overlooked. Including them shows real-world experience.
Weaknesses: - No automation: Every control item is a manual verification. "Check that you have on-chain monitoring." It doesn't provide the monitor. Based on my audit experience, manual checklists fail when teams are understaffed or when alert fatigue sets in. - Vendor bias: The checklist is co-authored by NOWPayments (a payment gateway) and BlockSec (a security firm). The items subtly steer users toward their services. Example: "Ensure your payment provider supports stablecoin freeze risk management." Guess which provider does? NOWPayments. I do not guess; I verify. I checked NOWPayments' documentation — yes, they advertise freeze management. - No independent review: No third-party auditor validated the checklist. It's self-published by two companies with commercial incentives. Silence is the loudest admission of guilt when there's no external sign-off.
Data point: The press release mentions NOWPayments' batch payment service with zero fees and $30 free credit. That's a stretch from security. It's a product plug embedded in a safety guide.
Technical gap: The checklist covers DNS security but doesn't specify how to verify DNSSEC or monitor for domain hijacking. It mentions "transaction verification" but doesn't differentiate between EIP-712 structured data signing and simple ETH transfers. For a business handling large volumes, these details matter.
Contrarian: What the Checklist Gets Right (And Why It's Still Dangerous)
Bulls will argue: a free, structured checklist is better than nothing. They're right. Many merchants operate without any security framework. This checklist provides a baseline.
But the danger is inverse: the more polished the checklist, the more likely companies will treat it as a complete solution. "We've completed all 25 items, we're secure." No, you're not. You've merely passed a self-assessment. You haven't passed a penetration test. You haven't deployed a SIEM. You haven't drilled on incident response.
I've seen this pattern in 2017 with ICO security checklists. Projects would tick boxes and still lose millions to reentrancy attacks. The code does not lie; only the auditors do — and this checklist is not an audit.
Takeaway: Use It, But Don't Trust It
The checklist is a useful artifact — for what it is: a marketing document with educational value. Treat it as a starting point for conversations with your security team, not as a replacement for real due diligence.
If you accept crypto payments, here's my advice: download the checklist. Read it. But also hire a dedicated security engineer. Deploy automated monitoring. Run red team exercises. And never, ever assume a free PDF makes you safe.
Promises are encrypted; data is decrypted. The checklist promises guidance. Your on-chain data will show whether you actually implemented it.
Volume is vanity; on-chain flow is sanity. Don't let the volume of 25 control items fool you into false confidence. The flow of real security — continuous vigilance — cannot be replaced by a shared record.
I trace the flow; you trace the lies. The lies here are subtle: that a checklist equals protection, that two vendors can self-certify industry best practices, that security can be purchased in a PDF.
Every transaction leaves a scar on the ledger. Every missed check leaves a vulnerability. The checklist won't protect you from that. Only execution will.
And execution, unlike a free download, requires resources, expertise, and independent verification.
I do not guess; I verify. I verified that the checklist exists, that it's useful, and that it's incomplete. Now you verify your own stack.
(Word count: 1105)