Fraud scoring for marketplaces
Also called: two-sided marketplace · peer-to-peer marketplace · gig platform · seller payouts
How the money moves
Buyers pay in, you hold the money briefly, sellers get paid out, and you take a cut in the middle. The gap between money arriving and money leaving is your entire exposure, and how long you hold it decides how much fraud you can still catch.
Where it leaves
- arrow_outwardSeller payouts. This is the leg you cannot undo. Once the money reaches a seller's bank or wallet, getting it back is a legal process, not a technical one.
- arrow_outwardRefunds and chargebacks on orders you already paid the seller for, so you cover both sides.
- arrow_outwardDeals where the buyer and the seller are the same person, using stolen cards and turning them into clean payouts through your platform.
- arrow_outwardPromo credit and first-order discounts, farmed on the buyer side with fresh accounts.
- arrow_outwardFees you never collected, on deals that moved off-platform after the two parties met on it.
What to score, and why these
Scoring everything is expensive and scoring the signup alone misses most of it. These are the events that carry the loss in marketplaces.
The seller payout
The leg you cannot reverse, so score it hardest. A payout destination shared by supposedly unrelated seller accounts is the clearest sign of a ring, and you never see it if you only score listings and logins.
Seller onboarding
A fraudulent seller account gets set up before it is used, often long before. Scoring at onboarding, while the account has no history to hide behind, is cheap and catches the operators who register in batches.
The transaction
Where buyer risk and seller risk meet. What matters is not the order on its own but the relationship. A buyer and a seller sharing a device, a network or a payout destination are not two parties.
A change of payout destination
The marketplace version of a recovery-email change in account takeover. A seller account with real history whose bank details change days before a big payout deserves a hold, and this is what a compromised seller account normally looks like.
The patterns you will see
Account takeover
Established seller accounts are valuable precisely because they have history and reviews. Stealing one is faster than building one.
Card testing
Marketplaces with fast, low-value checkout make attractive places to test stolen cards, and the damage to your decline rate lands on you.
Multi-accounting
Sellers dodging a suspension, and buyers farming first-order promos, both show up as duplicate accounts.
Fake signups
Seller accounts registered in bulk ahead of time, left to age, then used later or sold on.
When we are not the answer
- blockIf you are single-sided and pay nobody out, most of the value here does not apply. Your risk is payments fraud and belongs with a payments-focused tool.
- blockIf your main problem is counterfeit or banned goods, that is content moderation and classification, not behavioural fraud scoring, and we do not do it.
- blockIf you need identity verification on sellers for regulatory reasons, buy a KYC provider. We are not one and cannot be turned into one.
- blockIf disputes and chargeback representment are most of your loss, a payments platform will serve you better than we will.
Marketplaces are harder than single-sided businesses for a reason that is easy to say and awkward to build around. You have two populations with opposite incentives, and abuse often involves both at once, sometimes run by the same person.
Most fraud tooling assumes one user doing one suspicious thing. Here the suspicious thing is usually a perfectly ordinary transaction between two accounts that should not know each other.
The gap is the exposure#
Money arrives from a buyer and leaves to a seller. Everything you can do sits in that window.
Pay out instantly and you have chosen to have almost no fraud window, so you will absorb the losses. Hold for a week and you catch far more, but you have made your sellers' cash flow worse, which is a real product cost in a competitive market.
That trade-off is a business decision, not a technical one, and it is worth making on purpose rather than inheriting whatever your payments integration did by default.
Risk-based holds are usually the better answer than one blanket delay: most sellers get paid fast, and a scored minority waits.
Collusion is a relationship problem#
The pattern that costs marketplaces most is not a lone bad actor. It is a buyer and a seller who are the same person.
A stolen card buys a nonexistent item from a seller account they control, and your platform quietly turns card fraud into a clean bank transfer.
Nothing about either account looks alarming on its own. The buyer bought something. The seller sold something. The fraud is entirely in the relationship, and you only see the relationship if you link across accounts instead of scoring each one alone.
What surfaces it: shared devices, shared networks, shared payout destinations, and order histories where the money goes round in a very short circle.
Seller accounts are an asset, so they get stolen#
A seller account with two years of history and four hundred reviews is worth far more than a new one, and it takes minutes to steal versus years to build.
The tell is almost never the login. It is the payout destination changing shortly before a withdrawal, or a listing pattern that breaks with everything the account did before.
Score those as their own events, with the login attached, and hold payouts on a destination change until the real owner confirms. That one control catches a whole category of loss that login monitoring alone will miss.
Scoring the payout and the destination change#
Two events carry most of a marketplace's exposure, and neither of them is the signup:
const r = await kaidn.score({ event: "seller_payout", user_id: seller.id, ip: req.ip, email: seller.email, device_id: body.kaidn_device_id, }); if (r.verdict === "block") return holdPayout(seller.id, r.reason_text); if (r.verdict === "review") return queueForReview(seller.id, r.event_id); return releasePayout(seller.id);
// the highest-value control on this page, and most of it is not the score const r = await kaidn.score({ event: "payout_destination_change", user_id: seller.id, ip: req.ip, email: seller.email, device_id: body.kaidn_device_id, }); const newDevice = !(await db.accountDevices.exists({ user_id: seller.id, device_id: body.kaidn_device_id, })); if (newDevice || r.verdict !== "allow") { await holdDestinationChange(seller.id, "24h"); await notifyPreviousContact(seller, r.event_id); // the details from BEFORE the change return { status: "pending" }; }
Finding collusion in your own order table#
Kaidn scores identities, not orders. The circular-money half is a query you own, and it is short:
SELECT buyer_id, seller_id, count(*) AS orders, sum(total) AS value FROM orders WHERE created_at > now() - interval '90 days' GROUP BY buyer_id, seller_id HAVING count(*) > 4 AND count(*) = (SELECT count(*) FROM orders o2 WHERE o2.buyer_id = orders.buyer_id) ORDER BY value DESC;
A buyer whose entire history is with one seller proves nothing on its own. A buyer whose entire history is with one seller, who also shares a device with them, is a different matter.
Where we sit#
We score events on both sides with the same engine, and the value is in linking them: device, network, email identity, and how fast the same patterns repeat across accounts. Verdicts carry the checks that fired and what each one counted for.
We are not a payments processor and we do not handle disputes. We do not do KYC and we do not classify listings. If your problem is counterfeit goods or regulatory identity checks, those are different products and you should buy them.
Frequently asked questions
Where is a marketplace actually exposed?
In the gap between taking the buyer's money and releasing the seller's payout. That window is the product, because it is what makes the marketplace trustworthy, and it is also the whole attack surface, because everything a fraudster does is aimed at getting value out of it before the truth catches up. Score the payout and you are scoring the exposure. Score only the signup and you are scoring the cheapest moment.
Why is collusion hard to catch per account?
Because both sides are behaving perfectly normally. A buyer buys, a seller sells, and no individual account does anything a rule can object to. What is wrong is the relationship: the same device or network on both sides, orders that only ever involve each other, and money moving in a circle. That is a question about connections, not about accounts.
Do seller accounts get stolen?
Constantly. An established seller account is one of the most valuable things on a marketplace, because it carries reputation, reviews, and a payout channel that already exists. The pattern is a login from an unfamiliar device followed quickly by a change of payout destination, which is why that change deserves to be its own scored event rather than a settings update.
What is the single highest-value control?
A hold on a change of payout destination. Twenty-four hours plus a notification to the contact details that were on file before the change gives the real owner the one thing an attacker needs them not to have, which is time. It costs almost nothing and catches takeovers no scoring layer would have refused outright.
Can Kaidn see who trades with whom?
It sees the identity evidence on each event: the device, the real mailbox, the network, how fast things repeat. It does not hold your order table, so money moving in a circle between a buyer and a seller is a query you run on your own data. Kaidn tells you these two accounts look related. Your order history tells you they only ever trade with each other.
Run it on your own traffic
10,000 events a month free, no card. Every verdict returns the checks that fired and their weights, so you can see which signal caught it.