Keep stolen card numbers out of your checkout
Attackers run stolen card numbers through your checkout to see which ones still work, then use the ones that clear.
Request a site audit10,000+ unique IPs a day
run headless Chrome for scraping and carding, and the traffic splits roughly half-and-half between headless and headful mode. A checkout page with no bot check in front of it is a free card-testing service.
Read the researchWhat the traffic looks like
Small charges, fast
Cards get charged the smallest amount your checkout allows, just to see which ones still clear.
One script, one card list
A list of stolen card numbers gets run through checkout automatically until the valid ones are found.
A browser that passes the obvious checks
Headless or patched Chromium clears the checks that only look for the CDP automation flag or a missing viewport.
What runs against this traffic
Proof of execution
Checks run inside an obfuscated virtual machine whose code paths change on every build.
To answer at all, an attacker has to drive a real, unpatched browser through the full check on every attempt, not just the first one.
Read moreClient validation
Everything the client reports is checked for tampering and for the contradictions automation leaves behind.
A script that submits a valid-looking card still fails the checks running around the form.
Read more
Traffic doesn't stop at one attack
Want to see what reaches your site?
A site audit shows the crawler families reaching your domain and the pages where you may need more control.