Walmart's OnePay Adds SOL—Gateway Drug to Real Crypto or Permanent Walled Garden?

I just saw that Walmart’s OnePay fintech platform added Solana (SOL) to their crypto offerings on March 22nd. That’s 3 million+ monthly active users who can now buy, sell, and hold SOL directly in the Walmart app.

My first reaction: This is huge for legitimacy and visibility. My second reaction: Wait, is this actually Web3 adoption or just fintech with better backend infrastructure?

The Good News

Let’s start with what’s exciting:

  • Retail scale: 3M+ users is massive distribution. Most crypto wallets would kill for that user base.
  • Institutional validation: Goldman Sachs holds $108M in SOL, BlackRock’s BUIDL fund has $550M on Solana. This isn’t fringe anymore.
  • User experience: OnePay users can buy SOL for as little as $1. Familiar UX, no scary seed phrases, instant transactions.
  • Walmart’s reach: Rural and underserved markets where traditional crypto onboarding is harder. This actually could “bank the unbanked.”

The Uncomfortable Questions

But here’s what keeps me up at night as a founder trying to build sustainable Web3 businesses:

1. Users never touch private keys. OnePay is fully custodial (powered by Zero Hash). Users have an account balance, not actual wallet access. They can’t withdraw SOL to a self-custody wallet or use it in DeFi protocols like Jupiter or Orca.

2. If SOL is just another payment option alongside Visa/Mastercard, what makes it crypto? Same UX, same reversibility expectations, same KYC/AML. Walmart can freeze accounts, reverse transactions, comply with subpoenas. Is this disintermediation or just TradFi with blockchain rails?

3. Who captures the value? Walmart gets transaction fees, interchange, user data, payment float. Solana validators earn pennies per transaction. If blockchain becomes invisible infrastructure while incumbents own the customer relationship, is this the future we wanted?

The AOL Question

This reminds me of AOL and CompuServe in the 1990s. They provided “internet access” via walled gardens—curated content, proprietary protocols, couldn’t actually access the open web. That was mainstream adoption, but not the real internet.

Does Walmart OnePay become a gateway drug to real crypto (users start here, eventually graduate to self-custody and DeFi)? Or is it a permanent walled garden (users stay within Walmart’s ecosystem forever, never experience actual Web3)?

The Business Model Reality Check

I get why this happened. Self-custody has real UX and security problems:

  • Lose your seed phrase = funds gone forever
  • Phishing and malware risks
  • No customer support
  • Complex fee markets and gas estimation

Most retail users want the benefits of crypto (fast, cheap payments) without the responsibility of being their own bank. That’s a legitimate market need.

But if we normalize custodial-only as “good enough,” are we just rebuilding banking with extra steps?

My Take (Subject to Change)

I want to be excited about 3M users getting access to SOL. Visibility matters. Legitimacy matters. But I can’t shake the feeling that we’re optimizing for adoption at the expense of the sovereignty that made crypto interesting in the first place.

Maybe the answer is both/and instead of either/or:

  • Custodial onboarding for ease of use
  • Self-custody as an unlock feature for power users
  • Measure success by “conversion rate” (what % of OnePay users eventually withdraw to their own wallets?)

Question for the community: Should we celebrate this milestone or demand better? Are custodial crypto offerings helping or hurting long-term Web3 adoption?

I’m genuinely torn on this one. Would love to hear from folks working on wallets, building DeFi protocols, or thinking about mainstream adoption.


Sources:

Steve, this hits close to home since I work on wallet infrastructure daily. The custody debate isn’t black and white—there are legitimate UX and security tradeoffs that make custodial solutions necessary for most users.

The Self-Custody Reality Check

Here’s what I see when we user-test self-custody wallets with regular people (not crypto natives):

  • Seed phrase anxiety: 70%+ of test users write their seed phrase on paper, then either lose it or store it insecurely (desk drawer, photo on phone). One user literally lost $2K because their dog chewed the paper.
  • Gas estimation confusion: “Why do I need ETH to send USDC?” breaks people’s mental models. Even on Solana where fees are low, users don’t understand why transactions fail due to insufficient SOL for rent.
  • No recovery path: TradFi trained users that “forgot password” always works. When they lose seed phrases and we say “your funds are gone forever,” they assume we’re lying or incompetent.
  • Phishing success rates: Sophisticated phishing (fake WalletConnect modals, malicious dApp frontends) still catches even crypto-savvy users. Retail users are sitting ducks.

These aren’t problems we can UX-design away. They’re fundamental to how self-custody works.

Custodial Isn’t Inherently Evil

Custodial solutions solve real problems:

  • Institutional requirements: Goldman Sachs legally cannot hold private keys directly. They need qualified custodians with insurance, audits, and compliance frameworks.
  • Retail safety: For users with <$1K in crypto, custodial risk (Walmart/Coinbase/Binance goes bankrupt) is probably lower than self-custody risk (lose seed phrase, get phished, send to wrong address).
  • Regulatory clarity: Custodians operate within existing legal frameworks. Self-custody still has grey areas around AML compliance, tax reporting, and estate planning.

The Real Problem With OnePay

My issue with OnePay isn’t that it’s custodial—it’s that it doesn’t offer a graduation path to self-custody.

Compare to how Coinbase does it (imperfectly, but better):

  1. Start custodial for ease of use
  2. Offer withdrawals to external wallets once users are comfortable
  3. Eventually support Coinbase Wallet (self-custody option) for power users

OnePay, based on what I’ve seen, is a permanent walled garden. Users can’t withdraw SOL to a Phantom or Solflare wallet. They can’t use it in DeFi. It’s not even real SOL—it’s just a tracking number in Walmart’s database that represents SOL held by Zero Hash.

What Should Exist (But Doesn’t Yet)

The ideal model:

  1. Custodial onboarding (easy, familiar, safe for beginners)
  2. Progressive decentralization (as users gain comfort, unlock self-custody features)
  3. Assisted self-custody (social recovery, multi-device backup, optional insurance)
  4. Full sovereignty (graduate to pure self-custody when ready)

Think of it like training wheels on a bike. You don’t keep them forever, but you also don’t start without them.

Should We Celebrate OnePay?

I’m cautiously optimistic with caveats:

:white_check_mark: Good: 3M users exposed to SOL, institutional validation, rural access
:warning: Concern: If users never experience real crypto (DeFi composability, self-custody sovereignty), are we just creating Venmo 2.0?

The metric Steve proposed is perfect: measure the self-custody conversion rate. If OnePay becomes a feeder system that graduates users to real wallets (even 5-10% conversion would be huge), it’s a win. If it’s a permanent enclosure, we’ve failed.


To builders reading this: The market opportunity is building better self-custody UX. Custodial dominates because self-custody is too hard, not because users prefer centralization. If we make self-custody as easy as custodial, users will choose sovereignty.

We’re not there yet, but account abstraction (ERC-4337), social recovery, and biometric wallets are getting us closer.

Will makes great points about UX tradeoffs, but as someone building DeFi protocols, I have to push back on the “custodial is good enough” framing.

If You Can’t Use It in DeFi, Is It Really Crypto?

Here’s my concern: OnePay SOL isn’t composable. Users can’t:

  • Trade on Jupiter or Orca DEXs
  • Provide liquidity to AMMs
  • Use it as collateral in lending protocols (Solend, MarginFi)
  • Participate in liquid staking (Marinade, Jito)
  • Interact with any Solana dApp or smart contract

It’s literally just a speculative asset sitting in a custodial account. The number goes up or down, and that’s it.

The Composability Value Prop

What makes crypto interesting (to me, at least) isn’t “fast cheap payments”—Venmo already does that. It’s programmable money and permissionless composability.

A user with 1 SOL in a self-custody wallet can:

  1. Swap 0.5 SOL for USDC on Jupiter
  2. Provide USDC-SOL liquidity on Orca
  3. Stake LP tokens in a yield optimizer
  4. Use the yield to buy an NFT
  5. All in one transaction via a DEX aggregator

That’s not possible with OnePay SOL. It’s a closed loop. You can only buy, hold, sell, and maybe eventually spend at Walmart. That’s not Web3—that’s a tracking number in Walmart’s database that happens to represent blockchain assets held by Zero Hash.

The Two-Tier System Risk

If custodial offerings like OnePay become the dominant adoption path, we risk creating a two-tier crypto system:

Tier 1 (normies): Buy/sell/hold via custodial platforms. Never touch private keys. Never use DeFi. Crypto is just another asset class, like buying stocks on Robinhood.

Tier 2 (power users): Self-custody, DeFi, smart contracts, actual blockchain interactions. Tiny minority of users.

If 99% of users stay in Tier 1, what happens to DeFi protocols? We’re building for a niche market while the mainstream adoption happens in walled gardens that exclude us.

The Institutional Bridge Argument

Will mentioned Goldman Sachs and institutional requirements. I get it—institutions need custodial solutions for compliance reasons. Fine. But retail users don’t have fiduciary duties or regulatory constraints. They’re capable of self-custody if we make the UX tolerable.

The Goldman/BlackRock activity on Solana that Steve mentioned ($108M + $550M) is happening on-chain. They’re using actual Solana infrastructure, not custodial IOUs. That’s the model that scales the network and ecosystem, not OnePay’s off-chain tracking.

What I Want to See

Custodial onboarding is fine as a starting point, but it needs to connect to the actual crypto ecosystem:

  1. Withdrawals enabled: Let users move SOL to external wallets (Phantom, Solflare, Backpack)
  2. DeFi bridge: Partner with a DeFi aggregator (Jupiter?) so OnePay users can interact with Solana protocols
  3. Educational pathways: Teach users about DeFi, self-custody, and why sovereignty matters
  4. Incentivize graduation: Offer lower fees or rewards for users who move to self-custody

If OnePay did even one of these, I’d be way more optimistic.

The Venmo Comparison

Will called it “Venmo 2.0” and that’s exactly right. Venmo lets you “buy Bitcoin,” but you can’t withdraw it to a wallet. It’s Bitcoin exposure, not Bitcoin ownership. OnePay is following the same playbook.

That’s not Web3 adoption. That’s TradFi incumbents using blockchain as backend infrastructure while maintaining full control over user access.


Steve’s question was “should we celebrate or demand better?” I vote demand better.

Celebrate when OnePay enables withdrawals and DeFi access. Until then, this is just crypto-adjacent fintech, not actual Web3.

As someone who helps crypto companies navigate compliance, I need to add the regulatory perspective that’s missing from this discussion. Diana’s DeFi-maximalism is idealistic, but ignores the legal realities that make custodial solutions necessary—at least for now.

Legal Clarity Enables Institutional Participation

The Goldman Sachs ($108M SOL) and BlackRock ($550M BUIDL) activity Steve mentioned didn’t happen in a vacuum. It happened because:

  1. Custodial frameworks exist: Qualified custodians (like Coinbase Custody, BitGo, Anchorage) have regulatory approval, insurance, and auditing requirements. Institutions legally cannot hold private keys directly.

  2. ETF structures require custody: Solana ETFs (which saw $900M+ inflows in Q1 2026) wouldn’t exist without SEC-approved custodial arrangements. Self-custody isn’t compatible with 40 Act requirements.

  3. Fiduciary duty standards: Asset managers have fiduciary obligations to protect client assets. “User holds private keys” doesn’t meet institutional risk management standards (key loss, insider theft, operational errors).

This isn’t about institutions preferring centralization—it’s about legal compliance making custodial solutions mandatory.

Retail Users Have Compliance Needs Too

Diana argues “retail users don’t have fiduciary duties.” True, but they do have:

  • Tax reporting requirements: Custodial platforms issue 1099s, track cost basis, report to IRS. Self-custody users need to track this manually (most don’t, creating audit risk).
  • AML/KYC compliance: Regulators increasingly scrutinize crypto transactions. Custodial platforms handle this; self-custody users may face scrutiny when interacting with regulated on/off-ramps.
  • Estate planning: What happens to self-custody funds when the user dies? Legal frameworks for custodial assets are clear; self-custody inheritance is messy (lost keys, lack of probate guidance).

For many retail users, custodial solutions are safer from a legal/tax perspective, not just UX.

The Gradual Decentralization Path

I agree with Will that OnePay should offer a “graduation path” to self-custody. But I understand why Walmart started custodial-only:

  • Regulatory approval is easier: Launching a custodial crypto product requires FinCEN registration, state money transmitter licenses, and compliance frameworks. Enabling withdrawals to self-custody wallets adds complexity (how do you ensure AML compliance for external wallets?).
  • Liability protection: If users lose private keys with OnePay’s custodial model, that’s Walmart/Zero Hash’s insurance problem. If OnePay enables self-custody and users lose keys, who’s liable? (Legally unclear, PR nightmare either way).
  • Iterative rollout makes sense: Launch custodial first, prove demand, then expand features (withdrawals, DeFi access) once you’ve built trust and compliance frameworks.

The Both/And Solution

Here’s my pragmatic take: Custodial and self-custody models will coexist, serving different use cases.

Custodial for:

  • Institutional investors (legally required)
  • Retail investors prioritizing safety/convenience over sovereignty
  • Tax/compliance automation
  • Users with <$5K in crypto (where custody risk < self-custody risk)

Self-custody for:

  • DeFi power users
  • Privacy advocates
  • Sovereignty maximalists
  • Users with significant holdings (where custody risk > self-custody risk)

The market will decide the split. Current data (59% prefer self-custody in 2025) suggests both models have product-market fit.

What Regulators Want to See

From my conversations with SEC/CFTC/FinCEN folks, they’re watching:

  1. Fraud prevention: Custodial platforms have better tools for detecting scams, wash trading, and market manipulation.
  2. Consumer protection: When exchanges fail (FTX, Celsius), custodial assets have legal recourse; self-custody has “tough luck.”
  3. Tax compliance: Custodial platforms report transactions; self-custody creates enforcement challenges.

If crypto wants institutional capital and regulatory clarity, custodial infrastructure is necessary. Full stop.

My Take on OnePay

I’m more optimistic than Diana. OnePay isn’t perfect, but it’s a pragmatic first step:

:white_check_mark: Brings 3M retail users into crypto with legal/compliance frameworks
:white_check_mark: Enables institutional participation (Goldman, BlackRock on-chain activity follows similar custody models)
:white_check_mark: Reduces fraud/scam risk for retail users (custodial platforms can block suspicious transactions)

:warning: Should add withdrawal functionality eventually
:warning: Should educate users about self-custody option

But “demand better” implies OnePay is failing. I think it’s succeeding at what it’s designed to do: provide legally compliant, safe, accessible crypto exposure to mainstream users.

If you want permissionless DeFi, use Phantom. If you want safe, simple SOL exposure, use OnePay. Both can coexist.


Steve’s “conversion rate” metric is interesting, but I’d add: what % of OnePay users would lose funds if forced to use self-custody? My guess: 30%+. That’s not a UX failure—that’s a fundamental tradeoff.