Trust was the product
Crypto had a trust problem. Not the blockchain-trustless kind but the human kind. How do you get someone comfortable with entering sensitive information, linking their bank account, and handing over money to software they've never heard of? That was the core of my work at Meso.
First, a couple bets.
The UI was never the final shape
When we started out we intended this to be an API first platform. But the further we got into it, the more we realized that the first iteration of the business needed to be B2B2C. However, some non negotiables were that it had to be fast, fluid, and fit seamlessly into a partner's app. Why? Because the hardest part was verifying a user without dragging the partner into compliance, regulatory, and PCI scope.
Invest early in compliance
A fine from regulators could tank the company. The US hadn't really passed a lot of regulation which put us into a tricky spot. We either risk it and hope regulators don't come down on us. Or we build to the European standard as much as we could. Europe was far stricter (and generally safer for users) so we baselined our programs on the EU.
The tension: to stay compliant without exposing partners to scope, we had to hold a relationship with the user. Specifically, an account which held their verified identity, saved payment methods. The payoff was that once any new partner integrated, the user just authenticates and they're transaction ready.

We designed all of this with the expectation that if we were successful no one would use it.
Building trust with no reputation
Meso was a crypto payments company. The pitch to developers: drop in our SDK and your users can buy crypto without leaving your app. The pitch to users: an onramp that's fast, has low fees, and is safe.
Most onramps in 2022 felt like filling out a tax form inside a slot machine.
Trust was tenuous at every layer because people were wary of new products, developers didn't trust the infrastructure, and the industry had given everyone plenty of reasons. Every decision came back to one question: does this build trust or erode it?
First off, UXR
We had no product, no users, and we were building for people who preferred anonymity over convenience. The only heckin way to get any sense of what would work was to just start talking to people.
First issue? Because of the anonymity thing, these folks are hard to find. So we got some help and hired a small team to help us recruit and run UXR (User Experience Research). Second issue? As mentioned we had no product, but we did have figma. So I whipped up some quick prototypes and we got that in front of about 30 people. Quite possibly some of the best money we spent.
We formed some core pillars that would help inform everything we built after, synthesized from this research.
Social proof
Has anyone I know used this?
Pricing
Am I getting ripped off?
Visual trust
Does this look like a real company?
Speed
How fast do I get my crypto?
Some early insights that guided a lot of iteration
“I don't know about the Meso logo with the fire - it doesn't look too welcoming.”
“I'm not sure what secure transfers would entail.”
“[sharing this information] is something I might be hesitant on if I've never heard of Meso before, but I don't know if it would actually stop me.”
“If they're based in the US it's pretty reasonable [to ask for these details].”
Here's some things that changed over time because of the research:
- Co-branding was important to build trust
- The icons and avatars were way too much - and confused people
- Kinda doing too much on a lot of fronts
- Over-explaining and over-justifying in text
- Smooth progress bar over stepped because we could dynamically inject a step without visually adding a step
- What was I thinking with that serif?

The front door
As mentioned earlier, the goal from the beginning was always to build a platform. To have a powerful API that allowed partners to integrate deep payments functionality. However, because regulations, PCI scope, and a few other complexities - building this first would have bankrupted us. So we took a slightly different approach and started with a B2B2C platform - we would provide UI to our partners but since we were competing on similar playing fields to our competitors our edge would be deep customizability and embeddability.
Everyone else redirected. Tap Buy, land on a provider's website, do the whole thing over there, then find your own way back to see whether it worked.
It works, technically. But trust breaks at the exact moment someone is deciding whether to spend money, and sending them to a domain they've never seen is a great way to break it.
Ours slid up inside the partner's app, wearing their theme or one of our defaults. From the user's side, they never left.
Compliance from day one
We took a very strong stance early on to build a compliance program alongside the product. Our combined experience had taught us that getting this wrong could be devastating for the company - and we just believed it was the right call. US had (has) very little regulation so we baselined everything on EU as it was sensible and had much stronger protections for users.
The bill for that landed primarily in onboarding. KYC and identity verification are invasive - if you've ever opened a new bank account, or tried investing through a regulated app, you know.
Picking the stricter standard costs you in exactly one place: how many people make it through. About 30% of people who started KYC came out verified and transacting. Compliance, risk, and fraud live in that flow and turn (bad) people away on purpose while not punishing the good users.
It bought us something four years later, though. Expanding into the EEA was licensing and operations rather than a redesign, which was a big part of doing it that way in a market that wasn't asking us to. It shipped as the acquisition closed, so the numbers are small.
The account
To keep partners out of scope we had to hold the relationship ourselves. Verified identity, saved payment methods, all on our side.
Definitely a funny design problem. The user ends up with an account at a company they've never heard of, inside an app that isn't ours, and the promise is that it never feels like they left. Authentication is the one moment we wanted our brand/logo visible. Everywhere else the goal was to be furniture.
The payoff was the network effect. Verify once, transact at any partner. Someone who bought through one wallet in March could open a completely different app in June, authenticate, and be done in seconds.
The integration

Developer experience was a huge priority and focus for us. We'd all worked on developer platforms (at Braintree together for most of us) so we knew what it takes to build good DX (Developer Experience).
Because of that, the quality bar for DX was always high. We often wrote docs as the specification and integrated to that (docs driven development?). This meant we were never scrambling to write documentation or guides and that everyone was contributing (yes even I wrote some of our documentation).
BuyCrypto.tsx
import { transfer, Asset, Environment, Network } from "@meso-network/meso-js"; const instance = transfer({ partnerId: "<PARTNER_ID>", environment: Environment.PRODUCTION, sourceAmount: "100", // what the user spends, in USD destinationAsset: Asset.ETH, // the token they receive network: Network.ETHEREUM_MAINNET, walletAddress: "<WALLET_ADDRESS>", // your user's wallet, at runtime onEvent({ kind, payload }) { // every state change in the lifecycle comes back through here }, async onSignMessageRequest(message) { // the user signs, proving the wallet is theirs }, });
Beyond that partners could customize our UI to match their brand. An obviously important part of making sure it feels right inside of their app.
Dogfooding
Before we felt confident enough to ship our SDKs we needed a way to test them in sandbox and developer conditions. So we built Meso Cash. A consumer app where people could buy crypto. If we couldn't convince real people to buy through our own frontend, we had no business asking partners to embed us in theirs.
It became our second-biggest partner by volume, which wasn't the plan. More useful was what it surfaced - edge cases in KYC, confusing error states, places trust broke that you only find when somebody is actually trying to spend $200. We went in the same front door everyone else did.
What it added up to
And now, some conversion numbers. ~30% of people who started KYC finished and transacted. ~87% of transactions succeeded once a user was verified.
The second is high because of the first. Strict onboarding and risk modeling means the people on the other side of it are good users. And the reason this was a good number for us is because this was one of the highest acceptance rates in the industry at the time where banks decline crypto as a matter of policy. We made the funnel narrower on purpose.
MoonPay acquired us in late 2025.
The other hats
There was no brand team. Ben and I always joked that we'd eventually hire an agency to do it for us. But we never did, so the logo stuck. But I was glad for it because I got to do a lot of weird brand experiments and push into fun and interesting visual territory.
The clouds got out of hand first.
The logo was representative of what product we were building. Two converging ramps to form an M. Everything else came out of that concept.
It kept coming back to ramps. On-ramp, off-ramp, the mark, the renders, the icons. I never got tired of drawing them or rendering them. And getting weird with them.
Looking back
Trust wasn't a feature we shipped. It was the product. Every screen, every interaction, every API response was either building it or eroding it, and we didn't always get it right.
The house behind the front door never got built at Meso. It's what the work turned into at MoonPay - the acquisition wasn't the end of the bet so much as the thing that funded it.
Meso was a really special time in my career. So much trust, and a bunch of people that just wanted to build good software.
I designed all of it expecting it to disappear, and it did (although not in the way I'd planned in the beginning). Meso was acquired, the product came down. But it kinda lives on here now, and that's cool.










