Crypto Payment Gateway Development

We design and develop full-cycle blockchain solutions: from smart contract architecture to launching DeFi protocols, NFT marketplaces and crypto exchanges. Security audits, tokenomics, integration with existing infrastructure.
Showing 1 of 1All 1305 services
Crypto Payment Gateway Development
Medium
~1-2 weeks
Frequently Asked Questions

Blockchain Development Services

Blockchain Development Stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1374
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1256
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    965
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1208
  • image_logo-advance_0.webp
    B2B Advance company logo design
    667
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    954

Crypto Payment Gateway Development

The main mistake when designing a crypto payment gateway is trying to fit the traditional fiat payment model onto blockchain. Fiat payments have authorization, capture, refund, and chargebacks. Blockchain has only confirmed transactions and no forced reversal. Everything else must be built around this fundamental difference. This architectural gap determines how addresses are designed, confirmations are processed, and funds are swept. Ignoring it leads to double-spend vulnerabilities and loss of funds.

We develop crypto payment gateways with this architectural difference in mind. Our team has blockchain development experience and has delivered over 20 projects for accepting cryptocurrency payments in B2B and B2C. We offer a turnkey solution from architecture design to deployment and support. Every project undergoes a technical security audit and load testing before launch.

One common pain point is high transaction costs and long confirmation waits, especially in networks with congested mempools. Properly configuring sweeps and choosing send timings can cut gas fees by up to 30%. Gas optimization is a key focus during design. Contact us—we will help you reduce costs.

How to Properly Configure HD Wallet Derivation?

Two approaches with fundamentally different trade-offs. HD wallet derivation reduces confusion risk by 100 times compared to a shared deposit address without a memo.

  1. One address per order (HD wallet derivation) For each new payment we derive a unique address from the master xpub key using path m/44'/60'/0'/0/{orderId}. The customer sees a unique address for their order—no amount confusion, no conflicts between concurrent payments. The private key for sweeping is derived offline, only at withdrawal time.

    import { HDNodeWallet, Mnemonic } from "ethers";
    
    function derivePaymentAddress(xpub: string, index: number): string {
      const node = HDNodeWallet.fromExtendedKey(xpub);
      return node.deriveChild(index).address;
    }
    

    Problem: thousands of addresses to monitor. Solution—webhook subscriptions via Alchemy/Moralis/QuickNode for Activity on specific addresses, or a custom node using eth_getLogs over a block range.

  2. Shared deposit address with memo/tag One address, customer includes a unique payment ID in the data field. Simpler infrastructure but creates a UX problem: the user must remember the memo. Works in B2B, often fails in B2C.

Why Multi-Currency Support Is Critical for a Gateway?

Minimum production set today: ETH, USDT (ERC-20), USDC (ERC-20), BNB, USDT (BEP-20), BTC, TRC-20 USDT. Each network requires a separate monitoring worker.

For ERC-20 tokens, monitoring via the Transfer(address indexed from, address indexed to, uint256 value) event:

const transferTopic = ethers.id("Transfer(address,address,uint256)");

const logs = await provider.getLogs({
  address: USDT_CONTRACT,
  topics: [transferTopic, null, ethers.zeroPadValue(depositAddress, 32)],
  fromBlock: lastCheckedBlock,
  toBlock: "latest",
});

How to Implement a Confirmation Worker Step by Step

  1. Receive new transaction notification via webhook or polling.
  2. Calculate confirmation count (difference between current block and transaction block).
  3. If below threshold—set status to CONFIRMING.
  4. When threshold reached—set to CONFIRMED and trigger sweep.
  5. After successful sweep—mark as CREDITED.

Critical component: service tracking transaction status. Logic:

PENDING → CONFIRMING (1 confirmation) → CONFIRMED (N confirmations) → CREDITED

Confirmation count depends on amount and network:

Network Small (<$100) Medium ($100–$10k) Large (>$10k)
Ethereum 2 blocks 6 blocks 12 blocks
BSC 15 blocks 30 blocks 60 blocks
Bitcoin 1 confirmation 3 confirmations 6 confirmations
Tron 20 blocks 40 blocks 60 blocks

Reorgs are a real issue on BSC and fast-block EVM networks. The worker must detect reorgs (transaction blockhash changed) and roll back payment status.

Typical gas costs for sweep transactions (gas price in Gwei):

Network Gas limit for token transfer Average gas price (Gwei)
Ethereum 65,000 – 80,000 20–50
BSC 65,000 – 80,000 5–10
Polygon 65,000 – 80,000 30–100
Arbitrum 65,000 – 80,000 0.1–1

Hot Wallet and Sweeping

After payment confirmation, funds on the deposit address need to be swept to a hot wallet. For EVM networks this is a separate transaction with gas that must be funded:

async function sweepDeposit(depositIndex: number, amount: BigInt) {
  const depositKey = derivePrivateKey(masterKey, depositIndex);
  const depositWallet = new ethers.Wallet(depositKey, provider);

  // First send ETH for gas
  await hotWallet.sendTransaction({
    to: depositWallet.address,
    value: GAS_BUDGET, // ~0.001 ETH
  });

  // Then sweep tokens
  const token = new ethers.Contract(TOKEN_ADDRESS, ERC20_ABI, depositWallet);
  await token.transfer(hotWalletAddress, amount);
}

For ERC-20, there is a permit pattern (EIP-2612) — if supported, you can sweep without prior ETH gas transfer via transferFrom with a signature.

Security

Segregation of keys: master xpub (for address derivation) is stored in the application. Private keys are derived only for sweep operations, and only in an isolated signing service. Hot wallet — separate HSM or KMS (AWS KMS, GCP Cloud HSM).

Double-spend protection: do not credit until confirmation threshold is reached. Do not trust pending transactions—mempool can be replaced via RBF (Replace-by-Fee) on Bitcoin.

Rate limiting on deposit addresses: one address should receive one payment. After receiving the first transaction, mark the address as "used"; new transactions on it are handled separately with an alert.

Webhook signatures: all outgoing payment notifications are signed with HMAC-SHA256 using a secret. The recipient verifies the signature—protection against webhook forgery.

How to Choose a Production Stack?

Recommended configuration:

  • Backend: Node.js/TypeScript or Go for workers (high concurrency)
  • Queue: Redis + BullMQ or RabbitMQ for event processing
  • DB: PostgreSQL for payments, separate audit table (append-only)
  • Node monitoring: Alchemy/QuickNode with failover to backup provider
  • Alerts: Grafana + PagerDuty for worker stalls, anomalous amounts, confirmation errors

The stack is chosen based on expected load. For pilot projects a minimal configuration suffices; for production a fault-tolerant cluster is needed. Order gateway development with security guarantees—we will propose the optimal solution for your business.

What Is Included

  • API documentation (webhook notifications, REST endpoints for creating payments and checking status)
  • Monitoring access and transaction dashboard
  • Team training on gateway administration
  • 1-month support after launch

Development Timelines

MVP with 3-4 networks and a basic dashboard: 1-2 weeks if blockchain infrastructure is ready. Full-featured gateway with adaptive confirmation and sweep system: from 4 weeks. Contact us for an accurate estimate of your project. For a consultation, contact us—get a free estimate.

Basic architectural principles are described in BIP32 and EIP-2612.

Blockchain Infrastructure Deployment: Nodes, RPC, Indexing

Subgraph fell at 3:47 AM. By morning users saw outdated balances, transactions "hung" in the UI, support received 47 tickets in an hour. Cause: the handler in the subgraph failed on a transaction with a non-standard event log — and the entire index stopped. We have encountered such situations dozens of times. Our experience shows: blockchain infrastructure does not forgive gaps in observability. Guaranteeing uptime without multi-layered monitoring and fault-tolerant architecture is impossible. Over 8 years working with Ethereum, Polygon, and Solana, we have developed an approach that allows predictable deployment of infrastructure of any scale — from a single node to a multichain grid with dozens of subgraphs.

RPC Layer Architecture

Every dApp interaction with the blockchain goes through RPC — the JSON-RPC API provided by a node. Three options:

Managed providers — Alchemy, QuickNode, Infura, Ankr. Minimal operational costs, SLA, built-in monitoring. Limits: rate limits (Alchemy Free: 300 RU/sec), vendor lock, potential downtime during provider incidents. For most projects — the right choice at the start.

Self-owned nodes — full control, no rate limits, no third-party dependence. Cost: archive Ethereum node requires 2.5–3TB SSD, a strong server, and DevOps support. Sync from scratch on Ethereum via Geth/Nethermind — 3–7 days. Justified under high load or latency requirements.

Hybrid — self-owned node as primary, managed provider as fallback. Standard for protocols with high TVL. Proper load balancing can reduce costs by 20–30% compared to pure managed setup. Under high monthly request volume, hybrid saves significantly.

Provider Strength Limitation
Alchemy Supernode, Enhanced APIs, webhooks Expensive on high-volume
QuickNode Low latency, multi-chain More expensive than Alchemy on basic plan
Infura Historical reliability Rate limits on free, one major incident halted half of DeFi
Ankr Cheap, 40+ chains Less stable

How to Set Up an RPC Layer Without a Single Point of Failure?

At least two providers, DNS round-robin with health check every 5 seconds, automatic fallback when latency >500 ms. In practice, this gives 99.99% availability during any provider failure. For protocols with high TVL, we recommend a custom HA-proxy (nginx or Envoy) in front of two managed providers.

Why Is a Hybrid RPC Scheme More Cost-Effective Than Pure Managed?

At high request volumes, managed providers can be very expensive; a hybrid using a self-owned node as primary and a managed fallback cuts costs significantly without losing SLA.

Ethereum Node Clients

Execution clients: Geth (most used), Nethermind (C#, fast sync), Besu (Java, enterprise), Erigon (fastest sync, efficient archive mode ~2TB instead of 3TB).

Consensus clients (post-Merge): Lighthouse (Rust), Prysm (Go), Teku (Java), Nimbus (Nim). Each node after The Merge requires a pair of execution + consensus clients.

For DevOps: eth-docker — Docker Compose configurations for all client combinations. Setting up monitoring via Grafana + Prometheus is mandatory; a standard dashboard is available in each client's repository.

The Graph: Event Indexing

The Graph Protocol — decentralized indexing. A subgraph describes which events from which contracts to index and how to transform them into a GraphQL schema.

Subgraph structure:

  • subgraph.yaml — manifest: contract addresses, startBlock, events to handle
  • schema.graphql — GraphQL schema of entities
  • src/mapping.ts — AssemblyScript event handlers
dataSources:
  - kind: ethereum
    name: UniswapV3Pool
    network: mainnet
    source:
      address: "0x88e6A0c2dDD26FEEb64F039a2c41296FcB3f5640"
      abi: UniswapV3Pool
      startBlock: 12370624
    mapping:
      eventHandlers:
        - event: Swap(indexed address,indexed address,int256,int256,uint160,uint128,int24)
          handler: handleSwap

AssemblyScript handlers — not TypeScript. No nullable types, no closures, no many standard APIs. An error in the handler stops the subgraph indexing on that transaction. Important: add try-catch for operations that can fail (e.g., store.get() for an entity that may not exist).

How to Avoid Subgraph Indexing Stops?

Graph Node logs are monitored in real-time; on hasIndexingErrors = true an alert fires and an automatic node restart (via systemd or Kubernetes). Typical downtime on error — 150–300 seconds to recover. Additionally, for production we set up a watchdog that restarts Graph Node if subgraph lag exceeds 50 blocks.

Choosing Between Hosted Service and Decentralized Network

Graph Hosted Service (free, centralized) is deprecated in favor of Subgraph Studio + Graph Network. For production: deploy on Graph Network with GRT curation signal — the subgraph gets indexers proportional to curation.

Alternatives to The Graph: Ponder (TypeScript, self-hosted, easier to debug), Envio (ultra-fast indexer, supports EVM + non-EVM), Subsquid (TypeScript, own network), Moralis Streams (managed, webhook-based). Our experience shows: for high-load projects with unique logic, Ponder or Envio are more effective — they give full control over the process and do not require GRT tokenomics.

Webhooks and Real-Time Notifications

Alchemy Webhooks and QuickNode Streams allow receiving events in real-time via HTTP webhook or WebSocket. For monitoring addresses, new transactions, mints — this is faster than polling RPC.

Tenderly — platform for monitoring and alerts. You can set up an alert for a specific contract event, balance change, function call with certain parameters. Transaction simulation via Tenderly API is invaluable for debugging.

Monitoring and Observability

Minimum monitoring stack for a protocol:

On-chain: OpenZeppelin Defender Sentinel — watches contract events, triggers webhook or Autotask when conditions are met. Forta Network — community-maintained bots detect anomalies (large withdrawals, flash loans, governance attacks).

Infrastructure: Grafana + Prometheus for nodes, Datadog or Grafana Cloud for managed metrics. Alerts on: node is 10+ blocks behind, RPC latency >500ms, subgraph lag >100 blocks.

Uptime: Better Uptime or PagerDuty on RPC endpoint and subgraph health endpoint (The Graph provides _meta { hasIndexingErrors, block { number } }).

Why Is Monitoring Without Tenderly Insufficient?

Tenderly provides transaction simulation and detailed traces — critical for debugging subgraph and smart contract errors. Forta focuses on network anomalies, not your infrastructure. The combination of Tenderly plus a custom Grafana dashboard covers 90% of incident scenarios.

Multichain Infrastructure

A protocol on 5 chains = 5 separate RPC endpoints, 5 subgraphs, 5 monitoring configs. Manageable but requires deployment automation.

For subgraph multi-network deployment: graph deploy --network mainnet, graph deploy --network arbitrum-one etc. with a unified codebase and network-specific addresses in separate config files.

Chainlink CCIP and LayerZero for cross-chain messaging require monitoring of both chains and transactions on intermediate relayers. A reorg on the source chain after a confirmed mint on the target chain is a classic bridge problem. Solution: wait for finality (on Ethereum ~15 minutes after Merge for economic finality) before confirming on the target chain.

Infrastructure Setup Process

  1. Audit current stack — determine chains, request volume, latency and availability requirements.
  2. Architecture design — select providers, load balancing, redundancy.
  3. Subgraph development — manifest → schema → handlers → testing on local Graph Node → deploy to testnet → mainnet.
  4. Monitoring configuration — Tenderly alerts, Grafana dashboard, PagerDuty integration.
  5. Documentation and runbook — what to do when: subgraph falls behind, RPC downtime, node desync.
  6. Handover to operations — team training, access transfer, first month support.

What's Included

  • Deployment of managed or self-hosted Ethereum, Polygon, BNB Chain nodes
  • RPC layer setup with primary/fallback and load balancing
  • Subgraph development and deployment for your protocol
  • Monitoring connection (Tenderly, Grafana, alerts)
  • Runbook and operations documentation
  • Team training (up to 4 hours online)
  • 30-day support after delivery

Timeline

Task Duration
RPC and basic monitoring setup 1–2 weeks
Subgraph for one protocol 2–4 weeks
Self-hosted node with monitoring 2–3 weeks
Full infrastructure (multi-chain, monitoring, runbooks) 6–10 weeks

All projects are managed in a GitHub/GitLab repository with CI/CD; configuration code stays with you. Order infrastructure deployment — we'll show how to cut costs by 20–30% without losing reliability. Get a consultation — we'll demonstrate how we deployed infrastructure for a protocol with large TVL on Ethereum and Arbitrum. Contact us.