What is a carding attack, and why do bots love my checkout?

Short answer: Carding is the automated testing of stolen credit card numbers through real checkouts. Bots submit thousands of small transactions or authorization attempts; the cards that pass get sold or used elsewhere. Your store becomes the testing rig - and you pay the processing fees, the chargebacks, and eventually the fraud-score penalty from your payment processor.

Why small stores get hit hardest

Carders prefer checkouts with weak velocity controls because failed cards cost them nothing. A store doing modest volume is ideal: enough real transactions to blend into, few defenses, and an owner who notices the spike only when the processor calls. The attack traffic usually arrives in bursts at odd hours from rotating residential proxies.

The real cost is not the stolen goods

Most carded orders fail, so the direct theft is small. The damage is the chargeback ratio: cross your processor's threshold and you face reserves, higher fees, or termination. Stores have lost their payment processing over a carding weekend they never knew happened.

What actually stops it

Velocity rules alone fail because bots pace themselves. Effective defense scores the visitor before the checkout loads - automation fingerprints, impossible browsing sequences, headless-browser signals - and silently diverts bots away from payment endpoints while real shoppers never notice.

See your own numbers.

A free bot-traffic audit shows the human-automated split in your live traffic - no code changes, no commitment.

Get a free bot-traffic audit