What Is Carding?
Carding is a form of payment fraud in which stolen credit card data is tested against payment forms to determine which cards are still valid. Fraudsters obtain card numbers in bulk from data breaches and underground markets, then use automation to run small test transactions. Cards that pass are either used for larger fraudulent purchases or resold at a premium as "verified" cards.
How Carding Works
A carding operation typically starts with a list of thousands of card records of unknown quality. Bots then submit small authorization attempts — often donations, low-priced digital goods, or gift card purchases — through the checkout or payment forms of legitimate websites. The response tells the fraudster whether the card is live, dead, or blocked. A related variant, card cracking, targets cards where some fields are missing: automation iterates through possible expiry dates and CVV codes until the combination is accepted.
Because each test is a tiny transaction on someone else's site, the fraudster pays nothing for the validation infrastructure. The tested traffic is distributed through botnets and residential proxies to avoid IP-based blocking, and the checkout flow is automated end to end.
Why Carding Hurts Merchants
The merchant whose payment form is abused bears most of the cost. Every fraudulent authorization generates processing fees, and successful tests later come back as chargebacks with penalties attached. Payment providers monitor authorization decline rates, and a site used as a card-testing ground can see its merchant account throttled or terminated. Cleanup adds support workload, and legitimate conversion suffers when stricter payment rules are imposed in response.
Warning Signs
Typical indicators include bursts of small transactions in quick succession, unusually high authorization decline rates, many attempts sharing a device or session but cycling through different card numbers, mismatched billing data, and checkout traffic that skips normal browsing behavior and lands directly on the payment step.
How to Prevent Carding
Payment-side controls help: velocity limits on authorization attempts, address and CVV verification, and fraud scoring from the payment provider. The complementary layer is stopping the automation before it reaches the payment step, since carding only works at bot scale. Verifying at the checkout that a real customer in a real browser is submitting the form — the invisible check that bot protection services such as CaptchaFox perform — removes the free testing infrastructure carders depend on, while paying customers proceed without interruption.
About CaptchaFox
CaptchaFox is a GDPR-compliant solution based in Germany that protects websites and applications from automated abuse, such as bots and spam. Its distinctive, multi-layered approach utilises risk signals and cryptographic challenges to facilitate a robust verification process. CaptchaFox enables customers to be onboarded in a matter of minutes, requires no ongoing management and provides enterprises with long-lasting protection.
To learn more about CaptchaFox, talk to us or start integrating our solution with a free trial.