Fraud scoring for rewards sites and offerwalls
Also called: GPT sites · get-paid-to · offerwall · rewards platform · incentive platform
How the money moves
Advertisers and networks pay you for completed actions, and you pay a share of that to the user who completed them. Your margin is the gap between the two. So anything that produces a payout without a real conversion costs you twice: the payout you sent, and the advertiser revenue that was funding it.
Where it leaves
- arrow_outwardCashouts to PayPal, gift cards, crypto or bank transfer, which are effectively gone once sent.
- arrow_outwardPoints credited on conversions the network later reverses, leaving you paid out against revenue you no longer have.
- arrow_outwardReferral bonuses, which pay immediately and are self-referred far more often than most operators measure.
- arrow_outwardSignup and welcome bonuses, the cheapest thing on the site to farm at volume.
- arrow_outwardPartner clawbacks weeks later. This is the loss that arrives twice: once as the payout, once as the reversal.
What to score, and why these
Scoring everything is expensive and scoring the signup alone misses most of it. These are the events that carry the loss in rewards and offerwalls.
The cashout, not just the signup
The event that matters most here, and the one most operators score last. At registration a farmed account has told you almost nothing. At withdrawal it has told you everything: which accounts head for the same destination, in the same window, through the same networks. If you score one event, score this one.
The offer completion
Where value is created, and where it gets faked. Completions that look identical across accounts, or that finish faster than the offer allows, show up weeks before the reversal does. Catching it here is the difference between refusing a payout and trying to claw one back.
The referral
Self-referral is the single most common abuse on reward platforms, because the bonus pays immediately and the setup is easy. Score the referral when it is claimed and you catch pairs referring each other before either side gets paid.
The signup
Worth scoring, but for coverage rather than as your main line. It filters the obvious automated wave and builds the history that later events get compared against.
The patterns you will see
Bonus abuse
The core pattern here. Farmed accounts doing the bare minimum that qualifies, all converging on a handful of payout destinations.
Multi-accounting
One person, many accounts, usually to claim a per-user offer over and over or to refer themselves.
Fake signups
The automated wave. Cheaper to run here than almost anywhere, because accounts are free and useful the second they exist.
When we are not the answer
- blockIf your losses are chargebacks on card payments rather than payouts, this is the wrong shelf. That is payments fraud and a payments platform will serve you better.
- blockIf you have no payout at all and make money purely on ad impressions, most of what we score does not apply to you.
- blockIf what you need is identity verification (KYC) rather than abuse detection, we do not do that and you should not buy us for it.
- blockIf you are pre-launch with no traffic, wait. Our signals get better with volume, and a graph with nothing in it cannot link anything.
Rewards platforms have a structural problem most fraud tooling was never designed around.
The fraud is not a theft. It is a payout you agreed to make, to a user who did the thing you asked, who happens to be the same person as thirty other users.
Nobody used a stolen card. Nothing was broken into. Each account, looked at on its own, did exactly what the offer required.
Score the withdrawal#
The most useful change most reward operators can make is to move detection from the signup to the cashout.
At registration you have an email, an IP and a device, and a farmed account looks like a new user because it is a new user.
At withdrawal you have weeks of behaviour, a completion history, and above all a destination. Many accounts sending money to a small number of places is the single strongest signal in this vertical, and it does not exist at signup.
It is also where blocking is cheap and reversible. Refusing a suspicious cashout costs you a support ticket. Sending it costs you the money permanently.
The loss that arrives twice#
What makes reward fraud more expensive than it first looks is the reversal cycle.
A fake conversion pays you. You credit the user. The user cashes out. Weeks later the network reverses the conversion because the advertiser rejected it.
You have now lost the payout you already sent and the revenue that was funding it. And your reversal rate looks worse in the partner's dashboard for the next negotiation.
That second effect is the one to protect. A bad invalid-traffic rate is a commercial problem with your networks long after the individual money is gone, and it decides which offers you get access to next.
Fraud you can afford, and fraud you cannot#
Not all of this is worth chasing. The honest position is that some abuse is a cost of doing business.
Somebody gaming one offer for a few dollars is annoying and not worth an engineer's afternoon. A ring running forty accounts into one wallet is worth stopping today.
The difference is concentration, and concentration is only visible if you score the payout and link on shared entities rather than checking accounts one at a time. Set your threshold where the loss actually is, not where the volume is.
Manual review is not a failure#
In this vertical specifically, review is often the right default rather than block.
Your users include genuinely ambiguous cases: two people in one household sharing a laptop, students on a university network, whole markets where a mobile carrier puts thousands of people behind one address. Blocking those outright generates support load and public complaints, and reward audiences are vocal.
A queue where a human looks at the twenty highest-risk cashouts a day, with the reasons attached, is usually a better fit than an automatic block. It is the setup we would suggest starting with.
Scoring both ends#
Two calls with the same identity fields, on the two events that matter. The signup call is cheap and mostly exists to build the history the second one reads:
import { Kaidn } from "@kaidn/sdk"; const kaidn = new Kaidn({ apiKey: process.env.KAIDN_API_KEY }); const r = await kaidn.score({ event: "signup", user_id: user.id, ip: req.ip, email: user.email, device_id: body.kaidn_device_id, event_country: offer.country, // where the offer expects the user to be ip_country: req.headers["cf-ipcountry"], }); // let them in; hold what the account is WORTH if (r.verdict !== "allow") await markBonusHold(user.id, r.event_id);
const r = await kaidn.score({ event: "cashout", user_id: user.id, ip: req.ip, email: user.email, device_id: body.kaidn_device_id, }); if (r.verdict === "block") return holdPayout(user.id, r.reason_text); if (r.verdict === "review") return queueForReview(user.id, r.event_id); return payout(user.id);
The query Kaidn cannot run for you#
Payout convergence is the strongest signal in this vertical and it is not a Kaidn check, because the API never takes a payout destination. It is a short query on your own side and it is worth writing:
SELECT payout_destination, count(DISTINCT user_id) AS accounts, sum(amount) AS total FROM payouts WHERE created_at > now() - interval '30 days' GROUP BY payout_destination HAVING count(DISTINCT user_id) > 3 ORDER BY total DESC;
Put that next to the cashout verdict and you have both halves. Kaidn says this account looks like other accounts. Your own data says here is where they all send the money.
Where we sit#
This is the vertical Kaidn was built around first, so the signals are tuned for it: what the email resolves to, whether the device has been here before, network reputation, how fast things repeat across the funnel, and a cross-operator graph that links entities seen at other operators. Verdicts come back with the checks that fired and what each one counted for.
We do not do KYC, we are not a payments processor, and we do not replace your relationship with your networks. We score events and explain the answer.
Frequently asked questions
Where should a rewards site score first, if it can only score one event?
The cashout. At signup the farmer has told you almost nothing: a working email, a plausible name, a real device, an address that belongs to somebody's house. By the time money moves they have told you which accounts qualified in the same odd way, in the same window, through the same networks, and whether the same device came back. Registration is the cheapest event to score and the least informative.
Why does reward fraud cost twice?
You pay the reward, then you lose the campaign. The payout is the visible loss. The second one is your standing with the network: a partner that sees farmed conversions will claw them back or drop the offer, and the ad budget behind it converted at nothing rather than at the number on your dashboard.
Is manual review a failure?
No. It is the right outcome for the ambiguous middle, and the whole reason there are three verdicts instead of a yes/no. What does not scale is reviewing the entire funnel by hand. Let allow and block run automatically, and spend your analyst hours on the review band, where the evidence genuinely is mixed.
Does Kaidn detect payout convergence?
Not directly. Kaidn scores the cashout and returns the device, mailbox, network and velocity evidence about the account making it. Counting how many accounts withdraw to the same destination is a query on your own side, because Kaidn never takes a payout destination field. It is worth writing: convergence is the moment forty independent-looking accounts stop looking independent.
We are pre-launch. Should we integrate now?
Probably not. These signals get better with volume, because most of them are statements about other accounts, and a store with nothing in it cannot link anything. Come back when you have traffic and a loss you can measure.
Run it on your own traffic
10,000 events a month free, no card. Every verdict returns the checks that fired and their weights, so you can see which signal caught it.