Card testing is a fraud technique where an attacker uses a site's payment flow to check which stolen card numbers are still valid, by attempting many small transactions in quick succession and seeing which are approved.
Definition
Card testing is a fraud technique where an attacker uses a site's payment flow to check which stolen card numbers are still valid, by attempting many small transactions in quick succession and seeing which are approved. Gambling deposit pages are a target because they accept card payments, often internationally, and a successful small deposit confirms a working card that can then be used elsewhere for larger fraud.
A card-testing attack shows up as a burst of low-value deposit attempts, a high decline rate, many different cards from few devices or IPs, and often failed 3-D Secure challenges.
Operators defend with velocity limits (capping attempts per card, device, IP and time window), CAPTCHA and bot detection on the payment form, minimum deposit amounts, 3-D Secure, device fingerprinting, and rules that block or challenge the pattern. Left unchecked it drives up the operator's decline rate and chargeback exposure and can threaten its card-processing relationships.
In context
For affiliates, card testing is background but it explains payment friction and is relevant to traffic-quality context. A spike in the payment-decline rate on a particular traffic source can be a card-testing attack riding on that source, and an operator will investigate — traffic associated with card testing is worthless and damaging, so affiliates should filter bot and suspicious sources that could carry it.
It also explains why operators impose minimum deposits, CAPTCHA on the cashier, and velocity limits that occasionally inconvenience genuine users.
Affiliate content covering payment security for players can accurately note that these controls exist to stop fraud like card testing, and that a licensed operator with proper payment-fraud defences is safer to use than a site with a loosely protected cashier. Affiliates must never publish content explaining how to test cards, bypass velocity limits or defeat 3-D Secure, and should treat any such request as out of scope.
For affiliate-facing content, the framing is that card testing is a fraud attack that targets gambling deposit pages, that the resulting controls (minimum deposits, CAPTCHA, velocity limits, 3-D Secure) are protective, and that affiliates should keep traffic sources clean of the bot activity that can carry these attacks.
Worked example
An operator sees a burst of tiny deposit attempts across hundreds of cards from a handful of devices and blocks the pattern with tighter velocity limits and cashier CAPTCHA. Its decline rate normalises.
An affiliate whose new source coincided with the spike investigates, finds bot contamination, and drops the source before it damages its traffic-quality standing.
Related terms
Frequently asked questions
Browse the full iGaming & affiliate glossary — hundreds of EN/RU terms with examples.
← Back to glossary