CashoutGuard: fraud prevention for rewards, GPT, faucet, PTC and offerwall sites.

Case study: 1 in 5 accounts was a VPN, a phone farm or a multi-account

A US-traffic offerwall network connected CashoutGuard and ran it in shadow mode for its first 24 hours. Nothing was blocked. Every event was scored and logged. By the end of the day, 46 of 218 accounts were flagged for review or block. This is what the data showed.

Short answer

In its first 24 hours in shadow mode on a US-traffic offerwall network, CashoutGuard flagged 46 of 218 accounts (21 percent, roughly 1 in 5) for review or block, without blocking anyone.

Fraud rings
5 rings of several accounts on the same device.
Foreign browser languages
60 events with a browser language from another country than the IP.
Device signals
16 events with a spoofed phone model, 15 from China-only models outside China, 8 with default emulator profiles.
Offer speed
17 or more offers completed impossibly fast.
First three days
389 of 3,419 conversions, worth $251 in payouts, would have been blocked.

The setup

The operator runs an offerwall network with mostly US traffic. High-paying US offers make it a natural target for users outside the US, for multi-account farms and for emulator setups. The operator suspected fraud but had no clear picture of how much.

They added the CashoutGuard JavaScript collector to their pages and called /v1/evaluate from their server on user events such as offer clicks, conversions and cashouts. Then they left the site in shadow mode. The network is not named here, and all numbers below cover that first 24-hour window only.

What shadow mode is

Shadow mode means CashoutGuard scores every event but never tells your site to block anything. Each event still gets a risk score from 0 to 100 and a list of reasons. The operator can read everything in the dashboard, but users see no difference.

It exists for a simple reason. Before you let any system block real people, you should see what it would do on your own traffic. Shadow mode answers three questions without risk:

  • How much fraud is there? A real number instead of a guess.
  • What kind? VPNs, farms, emulators, fast offers or a mix.
  • Would the rules hurt honest users? You can check flagged accounts by hand before anything is enforced.

When the operator is comfortable, they switch to enforce mode, and decisions start to apply.

How a score is built

Each signal carries a weight. A single weak signal, such as a timezone that is slightly off, moves the score a little. Several signals on the same event add up, so an account with a foreign browser language, a spoofed phone model and a shared device lands much higher than an account with only one of them. The reasons are listed with every score, so a reviewer can see why an account was flagged instead of trusting a number.

The headline: 46 of 218 accounts

In 24 hours CashoutGuard analysed 218 accounts. It flagged 46 of them for review or block. That is 21 percent, or roughly 1 in 5 accounts.

FindingCount
Accounts analysed218
Accounts flagged for review or block46 (21%)
Fraud rings (multiple accounts on the same device)5
Events with a browser language from another country60
Events with a spoofed phone model16
Events from China-only phone models outside China15
Events with default emulator profiles8
Offers completed impossibly fast17+

After three days: the money

The operator kept shadow mode on. In the first three days CashoutGuard scored 3,419 conversions from 5,687 accounts. It would have blocked 389 of them and sent 457 more to review.

First three daysResult
Conversions scored3,419
Would have been blocked389 (11.4%)
Sent to review457 (13.4%)
Payout on the blocked conversions$251 of $2,867 (8.8%)
Accounts behind them443 of 5,687

Almost all of the blocked conversions (384 of 389) came from a device shared by several accounts, the signature of a phone or emulator farm. Other reasons on the same conversions were a browser clock or language from another country than the IP, default emulator profiles, devices that wiped their storage and came back as a new user, and tampered browsers.

That is about $80 a day of payouts the network would have held, more than $2,000 a month, before counting the chargebacks advertisers send weeks later for the same traffic.

Five fraud rings on shared devices

The linked accounts graph found 5 fraud rings. In each one, several accounts were used from the same device. To the operator they had looked like separate users with separate histories. On the graph they were one cluster each.

Rings matter more than single accounts. Removing one account from a ring leaves the others earning. Seeing the cluster lets the operator decide on all of them at once.

Browser languages from another country

The largest single signal was language. 60 events came from browsers whose language settings named another country than the IP. Examples included ar-IQ and ar-EG on US IP addresses.

A US IP with a browser set to Iraqi or Egyptian Arabic does not prove fraud. Some users are expats or bilingual. But on a network whose value comes from US offers, it is a strong hint that the user is outside the US and connecting through a VPN or proxy. An IP check on its own cannot see that. The browser can.

Spoofed phones, China-only models and emulators

Three device signals pointed to farms and emulators:

  • 16 events with a spoofed phone model. The device claimed to be one model, but its graphics chip belonged to different hardware. Real phones do not do that. Anti-detect tools and farms that rotate model names do.
  • 15 events from China-only phone models outside China. These models are sold only in mainland China. Seen on US traffic, they suggest cheap bulk devices bought for a phone farm.
  • 8 events with default emulator profiles. Android emulators on a PC report well-known default models and builds. These are not real phones.

Each of these alone could have an innocent explanation in rare cases. Together, and combined with the rings and language mismatches, they described organised activity rather than ordinary users.

Device signals are also the hardest for a fraudster to clean up. Changing the IP takes one click on a proxy dashboard. Changing the graphics chip a browser reports, or the market a phone was sold in, is much harder. That makes them useful even when the network signals look ordinary.

Offers completed impossibly fast

More than 17 offer conversions arrived far faster than the offer could be completed by a real user. CashoutGuard compares each conversion with the time since the matching offer click and with what is normal for that offer.

Fast conversions are exactly what advertisers look for when they reverse payouts. Catching them in shadow mode showed the operator which offers were being abused, before the network raised it.

What the operator did next

Shadow mode does not decide anything for you. It gives you the list. In general terms, the operator did two things:

  1. Reviewed the queue. They went through the flagged accounts and cashouts in the review queue, with the reasons for each one in front of them.
  2. Tightened the rules. They adjusted their rules and lists for the signals that matched their own judgement of the flagged accounts.

We are not reporting outcomes beyond the first 24 hours here. The point of the case is the picture that one day of shadow data can give.

Lessons for other operators

  • Measure before you block. One day of shadow data showed a fraud share that the operator had only guessed at.
  • Look past the IP. Language, timezone and device checks found traffic that clean IPs hid.
  • Think in clusters. Five rings meant many accounts but only five decisions.
  • Speed tells you which offers are targeted, so you can protect them first.
  • Read the reasons, not only the score. The reasons are what let a reviewer agree or disagree with a flag.

Run the same test on your traffic

Every new CashoutGuard site starts in shadow mode, so you can run the same 24-hour test. Add the collector, call /v1/evaluate from your server and read the results in the dashboard. The free plan covers up to 1,000 monthly active users, and you can try the Growth plan free for 14 days. See the docs to integrate or the pricing page for plans.

Frequently asked questions

Does shadow mode affect my users?

No. Events are scored and logged, but your site gets no block decision, so users see nothing different.

Is 21 percent a typical fraud rate?

It is what this one network saw in its first 24 hours. Rates vary a lot by traffic source, country mix and offers. Running shadow mode on your own traffic is the only way to know yours.

Were all 46 flagged accounts fraudulent?

Flagged means sent for review or block, not proven fraud. The operator reviewed the queue by hand before tightening any rule.

How long should I stay in shadow mode?

Long enough to review a representative sample of flagged accounts and cashouts. For many sites a few days is enough; some start enforcing on the clearest signals after the first day.

Keep reading