How the fraud actually works.
Signal research, teardowns of real abuse patterns, and the engineering behind the API. Written for the operators running the traffic, not for a search engine.
FingerprintJS Pro and Kaidn, side by side in 24 privacy browser sessions
We ran both engines in the same page loads across Tor, Mullvad, Brave and Camoufox. Every number, including the two rounds where our own detector was the one that was wrong.
Read itBlocking disposable email domains is the easy half
A list of throwaway domains catches the lazy attempt. The one that costs you money uses a real Gmail address, six times, and every heuristic you would reach for first is wrong.
5 min readBuilding an MCP server for fraud investigation: why we expose evidence instead of risk scores
Most fraud APIs hand an AI agent a risk score and nothing else. We built one that hands over the evidence, and it changed how review queues actually get worked.
4 min readFraud playbooks
One page per abuse pattern: how the attack runs, what does not work, and the signals that do.
Account takeover
Why account takeover is caught by what changed rather than what is wrong, how credential stuffing is actually run, and where detection stops and authentication has to take over.
4 min readBonus abuse
How bonus abuse actually works, why per-account limits never hold it, and which signals separate a farmed signup from a real new user before the payout clears.
3 min readCard testing
Why card testing costs you more in processor standing than in stolen goods, how the attack is structured, and the signals that catch it in the first minutes.
3 min readFake signups
Why most fake registrations are not after your money, how bulk signup actually gets automated, and the signals that separate a script from a slow human.
3 min readComparisons
Honest head-to-heads, each one with the case for choosing them instead.
AbuseIPDB alternatives
Five alternatives to AbuseIPDB for IP abuse data, and why a community reporting database answers a different question from a fraud decision.
3 min readCastle alternatives
Five alternatives to Castle for account security, and where the line sits between protecting logins and scoring the whole funnel.
3 min readFingerprint alternatives
Five alternatives to Fingerprint for device identification, and an honest account of when you want a specialist identifier versus a scoring layer that uses one.
4 min readIPinfo alternatives
Five alternatives to IPinfo for IP data, and the difference between knowing what an address is and deciding what to do about the person behind it.
3 min readBuilt for
Where the money leaves your particular kind of business, and which events are worth scoring.
Marketplaces
Why marketplaces have two user populations and one fraud budget, where seller-side loss actually happens, and which events to score on each side.
3 min readRewards & offerwalls
Why reward platforms lose money at the payout rather than the signup, which events carry the loss, and how partner reversals turn fraud into a second bill weeks later.
3 min readSaaS
Why SaaS abuse is a cost-of-goods problem rather than a theft problem, which events are worth scoring when nothing is withdrawn, and when you should fix packaging instead.
3 min read