How do loyalty point bots drain rewards programs?
Why points are worth stealing
Points feel free to the brand and spendable to the thief, which is the worst combination. A point balance converts to gift cards, merchandise, or travel, and there are brokers who buy points at a discount with no questions asked. Unlike credit card fraud, loyalty theft often goes unnoticed for months: customers do not check point balances the way they check bank statements, and brands write off breakage without investigating. That detection gap is what makes farming profitable. The bot operator's only real cost is the infrastructure, and the margins beat most other fraud verticals.
Farming: manufacturing points from nothing
Farming bots create thousands of accounts and run them through the earning actions: sign-up bonuses, referral loops, review incentives, gamified engagement. Referral programs are the classic target: bot A refers bot B refers bot C, and each hop earns. Some operations target coalition programs where one account's activity earns across partner brands. The tell is velocity and pattern: accounts that earn at superhuman speed, referral chains that never touch a real purchase, engagement completed in seconds that should take minutes. Earning rules written for humans are trivially gameable by scripts.
Stealing: draining real members' balances
Account takeover is the other half. Loyalty logins are stuffed with credentials from unrelated breaches, because members reuse passwords everywhere. Once inside, the bot checks the balance, and if it is worth taking, transfers or redeems immediately. High-value redemptions get converted fast: gift cards emailed out, merchandise shipped to reshippers, points transferred to mule accounts. Members discover the theft weeks later when they try to use points that are gone. The brand's customer service then faces an impossible conversation with no logs to explain what happened.
Controls that protect the program
Start by making redemption harder than earning. Require step-up verification for redemptions above a threshold and for any transfer between accounts. Rate-limit earning actions per account and per device, not just per IP. Flag earning velocity anomalies: no human completes fifty product reviews in an hour. Add cooling periods on new accounts before points become redeemable, and on changed contact details before redemptions go through. Monitor the resale channels too; when your points show up on broker sites at scale, you have a measurement of the leak. None of this kills a good loyalty program. It just prices the bots out.
Should we require two-factor for all loyalty logins?
For redemption and account changes, yes. For simple balance checks, risk-based authentication is enough. The goal is to put the strong control at the money moment, which is redemption, without annoying members who just want to see their balance.
Do points expiry help against fraud?
Expiry limits the window but does not stop farming or fast cash-outs. Treat expiry as a liability management tool, not a security control. The security controls are authentication, velocity checks, and transfer rules.
How do we handle members whose points were stolen?
Reimburse promptly and investigate visibly. Stolen points are a trust event: the member did nothing wrong and the brand's security failed. Fast reimbursement plus a clear explanation of the new protections retains the customer; arguing about it loses them forever.
Won't strict queue verification hurt conversion?
It changes who converts, not how many units sell. Limited inventory sells out either way; verification just decides whether the buyers are real customers or resellers. For open-catalog products the calculus differs, but for constrained drops, verification protects the customers who drive lifetime value.
Can bots beat raffle or lottery systems?
Only by multiplying identities, which is exactly what identity-bound entry prevents. A lottery where each verified customer gets one entry is the fairest system available and the hardest to game. The attack surface moves from queue speed to identity verification, which is a fight you can win with standard KYC-style checks.
Should we cancel orders we suspect are botted?
Cancel carefully and communicate clearly. Mass cancellations after the fact punish the real customers mixed in with the bots and generate the support nightmare you were trying to avoid. It is better to prevent bot entries upfront than to unwind them later; reserve cancellations for clear-cut cases like ten units to one address.