What Is Denial of Inventory?
Denial of inventory is a bot attack in which automation claims limited stock — adding products to shopping carts, holding seat reservations, blocking appointment slots — without ever completing a purchase. The goods are never bought, only made unavailable: as long as the bots hold the items, real customers see "out of stock" and shop elsewhere. Unlike a scalper bot, which buys inventory to resell it, a denial-of-inventory attack profits from the absence of a sale — which is precisely what makes it hard to spot in revenue-focused dashboards.
How the Attack Works
Most e-commerce and booking platforms reserve inventory the moment an item enters a cart or a hold is placed, typically for a window of minutes to hours, so that a legitimate shopper isn't undercut mid-checkout. Denial-of-inventory bots weaponize exactly this courtesy: scripts create many parallel sessions, place the target items into carts across all of them, and refresh each hold just before it expires. A modest fleet of sessions can pin an entire product line indefinitely. Targets extend well beyond retail — airline and event seat maps, hotel room blocks, restaurant reservations, and appointment systems all operate on the same hold-then-confirm pattern and are attacked the same way.
Who Runs It and What It Costs
The motive is usually competitive or manipulative: a rival suppressing a product launch, a reseller creating artificial scarcity to move their own stock, or an extortionist demonstrating leverage. The victim's loss is twofold. Directly, sales stall while shelves appear empty — inventory reports say the product is moving, yet nothing ships. Indirectly, the signal damage compounds: frustrated customers buy from competitors, paid traffic converts at collapsing rates, and demand forecasts trained on cart data inherit the distortion. Because every individual cart action is a perfectly normal operation, the attack hides inside ordinary bot traffic until someone correlates hold volumes with completed orders.
Defending Inventory
The structural defense is making holds expensive to keep: short cart expiration times, no silent renewal, and per-session caps on held quantity all shrink what a fleet of bots can pin down. The decisive layer sits at the add-to-cart and reservation actions themselves — verifying that a hold is being placed by a real customer, which services such as CaptchaFox do invisibly by evaluating environment and behavior signals before the inventory is committed. Monitoring closes the gap: a rising ratio of holds to completed purchases, or carts concentrated on one product from fresh sessions, is the attack's clearest signature and worth alerting on.
About CaptchaFox
CaptchaFox is a GDPR-compliant solution based in Germany that protects websites and applications from automated abuse, such as bots and spam. Its distinctive, multi-layered approach utilises risk signals and cryptographic challenges to facilitate a robust verification process. CaptchaFox enables customers to be onboarded in a matter of minutes, requires no ongoing management and provides enterprises with long-lasting protection.
To learn more about CaptchaFox, talk to us or start integrating our solution with a free trial.