EN RU
List your company
Compliance

Card testing (carding)

Card testing is a fraud technique where an attacker uses a site's payment flow to check which stolen card numbers are still valid, by attempting many…

By Daniel Cohen · CMO Updated 6 September 2026
In brief

Card testing is a fraud technique where an attacker uses a site's payment flow to check which stolen card numbers are still valid, by attempting many small transactions in quick succession and seeing which are approved.

Definition

Card testing is a fraud technique where an attacker uses a site's payment flow to check which stolen card numbers are still valid, by attempting many small transactions in quick succession and seeing which are approved. Gambling deposit pages are a target because they accept card payments, often internationally, and a successful small deposit confirms a working card that can then be used elsewhere for larger fraud.

A card-testing attack shows up as a burst of low-value deposit attempts, a high decline rate, many different cards from few devices or IPs, and often failed 3-D Secure challenges.

Operators defend with velocity limits (capping attempts per card, device, IP and time window), CAPTCHA and bot detection on the payment form, minimum deposit amounts, 3-D Secure, device fingerprinting, and rules that block or challenge the pattern. Left unchecked it drives up the operator's decline rate and chargeback exposure and can threaten its card-processing relationships.

Compare KYC and compliance software

In context

For affiliates, card testing is background but it explains payment friction and is relevant to traffic-quality context. A spike in the payment-decline rate on a particular traffic source can be a card-testing attack riding on that source, and an operator will investigate — traffic associated with card testing is worthless and damaging, so affiliates should filter bot and suspicious sources that could carry it.

It also explains why operators impose minimum deposits, CAPTCHA on the cashier, and velocity limits that occasionally inconvenience genuine users.

Affiliate content covering payment security for players can accurately note that these controls exist to stop fraud like card testing, and that a licensed operator with proper payment-fraud defences is safer to use than a site with a loosely protected cashier. Affiliates must never publish content explaining how to test cards, bypass velocity limits or defeat 3-D Secure, and should treat any such request as out of scope.

For affiliate-facing content, the framing is that card testing is a fraud attack that targets gambling deposit pages, that the resulting controls (minimum deposits, CAPTCHA, velocity limits, 3-D Secure) are protective, and that affiliates should keep traffic sources clean of the bot activity that can carry these attacks.

Worked example

An operator sees a burst of tiny deposit attempts across hundreds of cards from a handful of devices and blocks the pattern with tighter velocity limits and cashier CAPTCHA. Its decline rate normalises.

An affiliate whose new source coincided with the spike investigates, finds bot contamination, and drops the source before it damages its traffic-quality standing.

Related terms

Frequently asked questions

How does Card testing (carding) work in practice?+
For affiliates, card testing is background but it explains payment friction and is relevant to traffic-quality context.
Can you give an example of Card testing (carding)?+
An operator sees a burst of tiny deposit attempts across hundreds of cards from a handful of devices and blocks the pattern with tighter velocity limits and cashier CAPTCHA. Its decline rate normalises.
What terms are closely related to Card testing (carding)?+
The closest related terms are 3-D Secure (3DS), Decline rate (payment), Anti-fraud, Bot traffic, Chargeback. Each is linked in the related-terms block below.
← Previous Card counting (online context) Next → Cascading reels (tumbling reels)

Browse the full iGaming & affiliate glossary — hundreds of EN/RU terms with examples.

← Back to glossary