Skip to content
Use case

Keep stolen card numbers out of your checkout

Attackers run stolen card numbers through your checkout to see which ones still work, then use the ones that clear.

Request a site audit
Why it matters

10,000+ unique IPs a day

run headless Chrome for scraping and carding, and the traffic splits roughly half-and-half between headless and headful mode. A checkout page with no bot check in front of it is a free card-testing service.

Read the research
How it works against you

What the traffic looks like

  • Small charges, fast

    Cards get charged the smallest amount your checkout allows, just to see which ones still clear.

  • One script, one card list

    A list of stolen card numbers gets run through checkout automatically until the valid ones are found.

  • A browser that passes the obvious checks

    Headless or patched Chromium clears the checks that only look for the CDP automation flag or a missing viewport.

How Centinel closes it

What runs against this traffic

  • Proof of execution

    Checks run inside an obfuscated virtual machine whose code paths change on every build.

    To answer at all, an attacker has to drive a real, unpatched browser through the full check on every attempt, not just the first one.

    Read more
  • Client validation

    Everything the client reports is checked for tampering and for the contradictions automation leaves behind.

    A script that submits a valid-looking card still fails the checks running around the form.

    Read more
Start with your site

Want to see what reaches your site?

A site audit shows the crawler families reaching your domain and the pages where you may need more control.