Wed. Oct 7th, 2026

Xendit Disables Coins.ph Payouts as BSP Cash-In Restriction Spreads Into Third-Party Rails

ByJohan Shamshad

October 6, 2026 #Xendit

Payment infrastructure provider Xendit has disabled payouts to Coins.ph, showing how a Bangko Sentral ng Pilipinas restriction on the crypto wallet’s inbound peso transfers is now propagating into third-party payment and remittance infrastructure.

In an official status notice posted at 12:32 WIB on October 6, Xendit said it was temporarily unable to process payouts to Coins.ph following the BSP directive suspending inbound transfers through InstaPay and PESONet.

The restriction applies to both of Xendit’s relevant destination codes: PH_COINS and PH_DCP. Xendit’s documentation normally lists Coins.ph and DCPay Philippines as separate Philippine e-wallet payout destinations, even though DCPay is the electronic-money entity behind Coins.ph’s peso wallet infrastructure.

That makes the latest development more significant than another notice inside the Coins.ph app. Businesses, remittance firms and platforms that use Xendit to deliver money to Philippine wallets can no longer route those payouts into the affected Coins.ph destination through Xendit.

Xendit said the restriction was effective immediately and that it was monitoring the situation. Its status system also classified remittance payouts and Philippine payout components as experiencing degraded performance, although the accompanying incident notice specifically identifies Coins.ph as the affected destination.

Coins.ph Can Still Send Money Out

The underlying BSP action is targeted rather than a full shutdown of Coins.ph.

Coins.ph says the central bank required the company to make enhancements to its internal controls. While that process is underway, PHP cash-ins through InstaPay and PESONet and QRPH collection services remain temporarily unavailable.

Existing customers can still cash out, make QRPH merchant payments, pay bills and trade cryptocurrency, according to the company. Its current status page also continues to show InstaPay and PESONet cash-in services as unavailable while the corresponding cash-out functions remain operational.

The distinction matters because the wallet has effectively become asymmetric: existing money can still move out or be spent, while several important routes for bringing new pesos into the platform have been restricted.

Industry reporting says the suspension was implemented through Philippine Payments Management Inc. Advisory No. 2026-0929-029 pursuant to BSP Monetary Board Resolution No. 839. The restriction applies to DCPay receiving incoming transfers through InstaPay and PESONet and also covers certain incoming QR transfers and participation in InstaPay for Business.

Neither Coins.ph nor the regulator has publicly specified which internal controls require enhancement or provided a firm date for restoring the affected services.

Xendit Turns a Wallet Restriction Into a Payments-Infrastructure Story

The Oct. 6 Xendit notice changes the scope of the story because users do not need to interact directly with Coins.ph for the restriction to affect them.

Xendit provides payment and payout infrastructure to businesses that integrate its APIs instead of establishing their own connections to every Philippine bank and wallet. A merchant, marketplace or remittance company can tell Xendit where a recipient should receive money, while Xendit handles the underlying local routing.

Normally, Coins.ph is one of those destinations.

Now it is not.

This is the same infrastructure-layer problem that appears across modern fintech: the customer-facing app can look independent even when the actual transaction depends on several companies behind it. Dave Finances has previously examined how retail financial apps depend on economic and regulatory structures several layers removed from the user interface.

The Coins.ph situation demonstrates the operational version of that dependency. A regulatory instruction affecting one recipient can propagate outward into APIs, payment aggregators and remittance services that simply use that recipient as the final leg of a transaction.

Both PH_COINS and PH_DCP Are Now Covered

The channel-code detail is particularly useful for understanding the scope.

Xendit historically lists PH_COINS for Coins.ph and PH_DCP for DCPay Philippines as separate e-wallet destinations. Its Oct. 6 notice explicitly says it cannot process payouts to “PH_COINS, PH_DCP.”

That removes ambiguity over whether a merchant could bypass the Coins.ph-labelled route by addressing the underlying DCPay destination instead.

At least through Xendit, both are currently blocked.

The same conclusion should not automatically be extended to every payment provider. Other international payment processors publicly document DCPay or Coins.ph as supported Philippine payout destinations, but those static integration documents do not establish whether the routes remain operational in real time.

No equivalent public Oct. 6 suspension notice from another major payout aggregator surfaced in the material reviewed for this article. Xendit is therefore the clearest confirmed example so far of the BSP restriction propagating into an external payout platform.

The Next Question Is How Far the Restriction Spreads

That is now the key monitoring point.

If additional PSPs and remittance aggregators disable Coins.ph or DCPay as destinations, this stops looking like a limitation contained within one wallet and starts looking more like destination-level isolation across the Philippine payment ecosystem.

That difference matters for businesses.

A company may believe it has redundancy because it works with several payout providers. But if every provider ultimately reaches Coins.ph through the same regulated national rails, switching aggregators does not necessarily restore the destination.

Provider redundancy is not the same thing as rail redundancy.

Recent payments cases show how quickly controls at an intermediary can affect services that appear unrelated from the user’s perspective. Dave Finances reported how Checkout.com rejected more than 80% of Polymarket deposits during a fraud attack, illustrating how decisions made at the processing layer can determine whether customers can fund an entirely separate platform.

The mechanism here is different—the trigger is regulatory rather than fraud screening—but the structural dependency is similar.

A Wallet Can Be Operational and Still Lose a Critical Rail

This is also why descriptions such as “Coins.ph is down” would be inaccurate.

The application continues to operate. Users can trade crypto. They can withdraw cryptocurrency. Existing peso balances can still be moved out through supported cash-out services, and merchant QR payments remain available.

What has been removed is a specific set of inbound financial connections.

For a payments business, however, losing the ability to receive money can be almost as consequential as a broader outage. A wallet becomes less useful as a destination if employers, merchants, remittance companies or counterparties cannot reliably send funds into it.

Dave Finances recently examined a different version of the same visibility problem in a case where a Stripe merchant said a $3,850 payment had remained unresolved for roughly a year. The broader lesson is that the end user often sees only a failed or unavailable payment, while the actual cause may sit somewhere deeper in the processor, banking or compliance chain.

Regulatory Action Can Travel Through APIs Faster Than Customers Realize

The bigger implication is how quickly modern financial infrastructure transmits a regulatory restriction.

Ten years ago, action against one financial institution might primarily affect that institution’s direct customers. Today, wallets are embedded inside remittance apps, payroll systems, merchant platforms and payout APIs.

That means a restriction can travel outward through software integrations without regulators separately issuing an order to every company whose customers ultimately use the affected destination.

Xendit does not need to be the target of the BSP action for Xendit clients to feel it.

The payment cannot complete because the final destination is restricted.

This interdependence is one reason some fintech companies are trying to reduce the number of intermediaries in their financial stack. Dave Finances previously covered how Telcoin is attempting to connect regulated banking and digital-dollar infrastructure more directly, partly to avoid the fragmented middleware structure common across fintech.

Coins.ph shows the opposite side of that equation. Interoperability creates enormous reach, but it also allows restrictions at one regulated node to propagate across otherwise separate products.

The Stronger Story Comes If More Payout Providers Follow Xendit

For now, this is still a partial restriction.

Coins.ph has not lost its crypto trading functionality, outbound transfers remain available, and there is no evidence that customer funds have been frozen across the platform. Coins.ph says customer funds remain safe and that it is working with the BSP to satisfy the regulator’s requirements.

But Xendit’s decision shows that the practical effect is expanding beyond Coins.ph’s own interface.

The next signals to watch are whether other remittance and payout providers remove DCPay or Coins.ph from their destination lists, whether failed transactions begin appearing across additional integrations, and whether the BSP or PPMI provides more detail about the controls that must be remediated before inbound access is restored.

If Xendit remains the only major aggregator publicly disabling the route, the impact may remain relatively contained.

If several providers independently block the same destination, the story becomes much larger.

At that point, the BSP would not merely have restricted one wallet’s ability to receive bank transfers. It would effectively have caused Coins.ph to disappear as an inbound destination across a wider section of the payments and remittance infrastructure built around it.

Financial Markets Analyst and Journalist at  |  More Posts

Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.

His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.

Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

Leave a Reply

Your email address will not be published. Required fields are marked *