233904 BIN Check - United Kingdom Mastercard Debit Card
It works on Steam, GitHub Copilot, App Store. Those three account for most of the 186 successful charges we recorded.
We keep coming back to 233904 when a merchant blocks the well-known virtual ranges. It comes from imToken Card in United Kingdom and does not sit on the usual blocklists.
What the six digits say
- BIN
- 233904
- Card network
- Mastercard
- Issuing country
- United Kingdom
- Card type
- Debit
- Issued by
- imToken Card
- Card form
- Virtual only
- KYC tier
- ID + proof
- 3-D Secure
- Yes
- AVS check
- No
- Billing address
- Self-custody
- Funding methods
- Crypto · Alipay / WeChat
- Max cards per account
- Not published
- Issuer risk rating
- Medium
The money side
Pricing, laid out: a NFT mint ~0.001 ETH to open a card, a 1% top-up fee every time you fund it, and no FX markup on conversion. Cost is the reason this range sits where it does in our ranking rather than higher up.
| Card creation fee | NFT mint ~0.001 ETH |
|---|---|
| Monthly fee | Free (no annual fee) |
| Top-up fee | 1% (token top-up) |
| FX / conversion fee | Free (multi-currency; Mastercard rate; no FX/conversion fee) |
| Declined transaction fee | — |
| Minimum top-up | — |
The test results
Everything we pushed through this range, including the merchants it never cleared.
Merchant by merchant
| Merchant | Attempts | Cleared | Rate | What happened |
|---|---|---|---|---|
| Steam | 82 | 74 | 90% | first charge and renewal four weeks later both cleared |
| GitHub Copilot | 67 | 60 | 90% | went through on a fresh card with the issuer's default address |
| App Store | 51 | 43 | 84% | no friction, and no AVS prompt |
| Tidal | 33 | 0 | 0% | 3-D Secure challenge never completed. The order timed out waiting for the OTP. |
| Hetzner | 26 | 9 | 35% | AVS mismatch. The ZIP on file did not match the address registered to the card. |
Run from a United Kingdom-region account between 18 Aug to 08 Sep 2026, with the billing address set to the issuer default unless noted. Declines were logged with the reason the gateway returned.
Failures we could not fix
We only saw failures on Tidal when the account region did not match the card country. With both set to United Kingdom it passed.
What to change before you retry
- Tidal: 0 of 33 cleared. Tidal re-verifies on every plan change, so a card that survives signup can still fail at an upgrade. Keep the address static between changes.
- Hetzner: 9 of 26 cleared. Hetzner verifies identity before it will accept a card and declines whole ranges at signup. Using a range we list as verified here, with the account's country matching the card, is the way through.
Practical notes
- Alipay and WeChat top-ups are supported, which makes this one of the easier ranges to fund without touching crypto. Keep individual top-ups small while you are testing.
- Funding is crypto-first. Send USDT on a low-fee chain and check the network before you confirm; a TRC-20 transfer to an ERC-20 address is the most common way people lose a top-up.
- Set the billing address to exactly what imToken Card generates for United Kingdom. Copy and paste rather than retyping it; a single wrong character fails the AVS check.
Verdict, briefly
Two things decide it. The 1% (token top-up) top-up fee and the fact that it does not appear on the common virtual-range blocklists. Both work in its favour. Ranked on cost alone it sits mid-table. Ranked on consistency it moves up a few places.
Questions we get about 233904
What does the 233904 BIN tell a merchant?
In practice the checkout reads imToken Card / United Kingdom / Debit and decides. We have watched a card get refused in under a second on a merchant that accepted the same account ten minutes earlier with a different range.
Is 233904 a real card number?
No, and this trips people up. 233904 is a range identifier shared across every card imToken Card issues in United Kingdom. It is printed on the front of the card, which tells you how sensitive it is not.
Why would 233904 be declined if the range is fine?
Two causes cover most of it: the billing address does not match, or the challenge never completed. Both look identical on screen, and both are fixable in under a minute.
Can thousands of people share the same BIN?
That is the normal case. Every Debit card imToken Card issues in United Kingdom carries the same six digits. Two people on 233904 can get opposite results at the same checkout, which is why a single review is never conclusive.
Method
We bought a imToken Card card, funded it, and pushed 259 charges through live merchant checkout pages between 18 Aug to 08 Sep 2026. Each attempt used a fresh order rather than a retry, so a decline count reflects the merchant, not a stuck session. 186 cleared.
Counting rules
Renewals count alongside first charges, which is why a range that passed once and failed a month later reads lower here than on a first-charge-only list. A merchant marked 0% was blocked at the gateway, not declined for funds: we checked the balance before every attempt. Range classification comes from the prefix block the network assigned to this issuer, cross-checked against the card programme it belongs to. Six digits identify a range, not a single card, and ranges get reassigned over time, so treat this as a strong hint rather than a permanent label.
Log through 13 Sep 2026 14:40 UTC · rate last re-checked 12 September 2026 · 259 charges on record for this range.