What is a carding attack, and why do bots love my checkout?
Why small stores get hit hardest
Carders prefer checkouts with weak velocity controls because failed cards cost them nothing. A store doing modest volume is ideal: enough real transactions to blend into, few defenses, and an owner who notices the spike only when the processor calls. The attack traffic usually arrives in bursts at odd hours from rotating residential proxies.
The real cost is not the stolen goods
Most carded orders fail, so the direct theft is small. The damage is the chargeback ratio: cross your processor's threshold and you face reserves, higher fees, or termination. Stores have lost their payment processing over a carding weekend they never knew happened.
What actually stops it
Velocity rules alone fail because bots pace themselves. Effective defense scores the visitor before the checkout loads - automation fingerprints, impossible browsing sequences, headless-browser signals - and silently diverts bots away from payment endpoints while real shoppers never notice.