All systems operational 21 locations · null network Pay with crypto · ∅ KYC
Start / Guides / How to buy a no-KYC VPS with crypto and leave little to hand over
Operational guide

How to buy a no-KYC VPS with crypto and leave little to hand over

Fiber light streaks on a dark background

Minimum-data playbook: alias mail, a wallet you control, checkout over Tor, SSH keys. What this host keeps — and the hygiene that keeps it nameless.

Der Artikeltext ist auf Englisch. Header, Katalog und Kasse sind übersetzt.

What this is — and is not

This page is the minimum-data path to buying a VPS with crypto — or a dedicated server with Bitcoin or USDT — such that the file on this side holds a string, not a name. The intended reader is doing something lawful: journalism, self-hosting, a business that does not want a card processor inside its infrastructure. It is not a crime manual. CSAM, phishing and paid attacks stay prohibited, and offshore billing plus a no-KYC signup cancel neither physics, nor the law of the rack's country, nor your own operational mistakes.

VPS from $3* (fund $50+), storage 1–5 TB NVMe from $24/mo annual-eff, dedicated with IPMI from $30.80/mo. Crypto invoice, no KYC.

Launch now

What NulNet actually keeps

The signup collects no documents: no name, phone, selfie or home address. Cards are not accepted, AML checks do not run on coins, and no chain-analysis product scores incoming wallets. What remains after an order is short by design — an email string, a password hash, and the invoice that marks payment: amount, coin, address, transaction ID. Connection metadata lives at most 24 hours; payload logs do not exist. Mail from a jurisdiction that is not ours is not a reason to grow that file, and a copyright template from abroad is neither a court order here nor a discovery request we volunteer extra data to satisfy.

The second half of the job is yours: keep the leftover non-identifying. If the inbox is a mainstream account and the coin came straight from a KYC exchange, the file still holds only an email and a txid — but both strings now point at you. Order the no-KYC VPS with crypto after the inbox and the wallet are chosen, not before.

Which email to use

The address has one job: receive a credentials mail and later invoices. That is the only reason it is asked for. Mainstream mailboxes keep a name attached to the string, so use a provider that sells accounts without demanding identity — Proton Mail, Tuta Mail, or mailbox.org. Put SimpleLogin in front and the string this host stores is an alias, not your long-lived address. 1984 Hosting sells mail from Iceland when the inbox should share a jurisdiction story with a Reykjavik rack.

Pick an inbox

I already have Proton or Tuta, paid in crypto
Spin up a fresh address or alias used only for this host. Do not reuse the handle printed on any public profile.
I want the stored string to be disposable
Create an SimpleLogin alias, forward it to Proton or Tuta, hand us the alias. If the alias dies, invoice mail dies with it — keep the recovery path written down.
I refuse big US mail
mailbox.org or 1984 mail. Still traceable if the mailbox itself was bought with a named card — payment hygiene applies to the inbox too.
A throwaway that cannot receive mail
Skip it. No inbox means no credentials mail, and the account becomes a locked box you paid for.

How to open the checkout

Do not order from the home or office line if that address is part of what you are not writing down. Open Tor Browser or a no-account VPN such as Mullvad VPN — accounts sold for cash or crypto, no email asked. IVPN sits in the same class. Corporate VPNs that SSO-log your name, and consumer VPN accounts bought with a card, both defeat the exercise when that trail is in scope.

The two-hop pattern buys isolation: order a cheap VPS (Sentry) with crypto first, put WireGuard official site on it from WireGuard quick start, then purchase the real VPS or dedicated server from behind that tunnel. Two invoices and two emails, if you want them separate. Nothing here requires it — it is one more layer for operators who want it.

How to pay so the coin does not name you

Send from a wallet whose keys you control. Withdrawing from a KYC exchange straight onto our invoice hands the exchange both the destination and your passport — the single hop that de-anonymizes an otherwise quiet payment. Bisq is the public P2P route some operators use so the coin purchase itself never becomes an exchange KYC file. BTC and USDT clear on the same page; nothing AML-scores the arrival, and nobody asks where the wallet lived.

Minimum-data checkout
  1. A new alias that can receive mail. Not a mainstream inbox.
  2. Tor Browser or a no-account VPN. Not the office Wi-Fi.
  3. Deploy: plan, term, and Iceland or Switzerland if process posture is why you came. OS last.
  4. Password, 12+ characters, unique to this host. Stored as a hash.
  5. Invoice: BTC or USDT from your own wallet. Exact amount, one transfer, address never reused.
  6. Credentials mail lands in the alias. Do not forward it into a named inbox.

After the box is up

Renting root means the privacy argument starts at your sshd, not at our panel. Follow OpenSSH manual: key-only login, PasswordAuthentication off, no root password over the network. Generate the key on hardware that is not your named work laptop if that device is in the threat model, and never upload the key anywhere public. Publish services only after password auth is off, and consider WireGuard official site on the box first so admin access never rides the public SSH port. Hostnames, motd, TLS certificates and WHOIS all leak — a personal domain on real-name WHOIS undoes a crypto-paid no-KYC VPS in one lookup.

Dedicated metal takes the same hygiene and adds IPMI: reach the console through the documented VPN path, never from a cafe machine with a name on it. Buying a dedicated server with crypto on the same account keeps the leftover file identical — email plus invoice — while the Shield-to-Citadel ladder is priced on the no-KYC dedicated servers page.

What we will not invent later

No spend threshold switches KYC on. No foreign office email switches wallet scoring on. No shadow profile accumulates behind the panel. The strongest compelled disclosure this host could produce reads: this email string paid this invoice for this SKU in this datacenter. If the email is an alias and the coin is not tied to a name, there is no name to type into that sentence — which is the whole design of a no-KYC crypto VPS and of offshore dedicated servers paid in cryptocurrency. It remains true that no billing design erases you from the public internet; the site you publish still speaks in your voice.

Do you AML wallets?

No. Coins and wallets are screened by nobody here — the checkout is an amount and a network, not a compliance interview, and no chain-analysis product sits between your transfer and the invoice.

What if a US or other foreign office writes?

A template notice from a jurisdiction that is not ours is not a reason to build a dossier or pull a VM. Copyright-only mail gets filed and closed; process that actually lands at the facility is a different layer and works normally.

Is this the same as anonymous hosting?

No-KYC plus crypto covers two layers; this guide is the third — choosing an inbox and a wallet that do not name you. The fourth layer is the site itself, which can still identify you no matter how quietly it was bought.

Can I buy dedicated the same way?

Yes. A dedicated server purchases with Bitcoin or USDT on the same no-KYC terms, and the leftover file is identical: email string, password hash, invoice. Provisioning adds 2–4 hours of racking and nothing else.

Does no-KYC mean zero data is kept?

No — and any host claiming zero data is selling fiction. The honest list is an email string, a password hash, invoice fields, 24-hour connection metadata and panel action logs. The claim is narrower: nothing that names you enters that set unless you put it there.

Ready to launch?

Build the box — VPS, storage or bare metal — create the password, pay the invoice that follows.