CashoutGuard: fraud prevention for rewards, GPT, faucet, PTC and offerwall sites.

Cashout fraud checklist: what to check before you pay a withdrawal

The cashout is the last moment the money is still yours. Once it is paid, a chargeback from the network comes out of your margin. This checklist covers the checks that catch most withdrawal fraud, in the order that saves the most time.

Short answer

Before you pay a withdrawal, check linked accounts and payout address reuse first, then earnings spikes, offer speed, conversions without a click, click versus conversion country, account age and network signals. Keep three outcomes (approve, hold, deny) so only the risky cashouts wait.

Check first
Payout address reuse: fast, rarely wrong and often finds the largest rings.
Hold
Addresses already paid for another account, and cashouts within 24 hours of signup.
Review
Offers under half the usual completion time, click and conversion in different countries, earnings many times the typical day.
Target review time
The same day, with clean older accounts approved automatically.

Why the cashout is the right place to check

You can check users at signup, at every offer click and at every conversion. You should. But the cashout is where everything comes together. By then you have the full history of the account: devices, IPs, offers, speed and the payout address it wants to be paid to.

It is also where mistakes cost real money. A wrong signup flag loses you one user. A wrong approval sends cash to a farm, and the network may reverse the underlying conversions weeks later.

The checklist

Work through these in order. The first checks are fast and catch the biggest rings. The later ones need more context.

  1. Linked accounts. Does this account share a device, email or IP pattern with other accounts? If yes, look at the whole group, not only this cashout.
  2. Payout address reuse. Has this PayPal, wallet or gift card email received money for another account? This is the single strongest fraud signal.
  3. Earnings spike. How much did the account earn in the last 24 hours compared with a typical user on your site? Several times the normal amount deserves a look.
  4. Offers completed too fast. How long passed between the offer click and the conversion? Compare with how long other users take on the same offer.
  5. Conversions without a click. Did the network pay for offers this user never opened from your wall? That suggests a forged postback or another path.
  6. Country mismatch between click and conversion. Was the offer clicked from one country and converted from another? A proxy or VPN switch is the usual cause.
  7. Account age. How old is the account? A first cashout within hours of signup is a pattern farms rely on.
  8. Network signals. Was the account on a VPN, Tor, datacenter IP or residential proxy when it earned the balance?

Checklist at a glance

CheckRed flagTypical action
Linked accountsSame device as 2 or more other accountsReview the whole cluster
Payout address reuseAddress already paid for another accountHold, usually deny
Earnings spikeMany times the typical daily earningsReview the offers behind it
Offer speedUnder half the usual completion timeReview, reverse if confirmed
Conversion without clickPaid offer never clicked on your wallHold and ask the network
Click vs conversion countryClick in one country, conversion in anotherReview
Account ageCashout within 24 hours of signupHold until the first check passes
VPN, Tor or datacenterBalance earned behind a hidden IPReview, deny if the offers were geo-targeted

None of these rows alone proves fraud, except perhaps a payout address shared across accounts. Two or three red flags together are a strong case. One flag on an old account with a clean history is usually a false alarm.

How to run each check well

Linked accounts and payout addresses

Normalise payout addresses before comparing them. Lowercase emails, strip dots and plus tags on Gmail, and trim spaces from wallet addresses. Then search past cashouts for the same value. One address paid for five accounts is one person.

Earnings spike

Work out what a normal user earns on your site in a day. The median is better than the average because a few power users skew the average. Then compare this account with that number. Ten times the median in one day is rare for a real person.

Offer speed and missing clicks

This only works if you record offer clicks. Log the user, the offer ID and the time when someone opens an offer from your wall. When the postback arrives, match it to the click. No click means you cannot tell how fast it was, and a paid conversion with no click at all is itself suspicious.

Country mismatch and account age

Store the IP country with each click and each conversion. A mismatch within the same offer is a much stronger signal than a user who travelled last month. For account age, a short wait before the first cashout removes most of the instant-farm profit.

-- Payout addresses paid for more than one account
SELECT LOWER(payout_address) AS addr,
       COUNT(DISTINCT user_id)  AS accounts
FROM cashouts
WHERE status IN ('paid', 'pending')
GROUP BY LOWER(payout_address)
HAVING COUNT(DISTINCT user_id) > 1;

Approve, hold or deny

Keep three outcomes, not two. A hold gives you time to ask the network or the user without losing an honest customer.

  • Approve when no check fires, or one weak check fires on an old, clean account.
  • Hold when one strong check or two weaker ones fire. Ask a question, wait for pending reversals, look at the cluster.
  • Deny when the payout address is shared, the device is shared with a ring, or several checks fire together. Deny the cluster, not only this account.

Common mistakes when reviewing cashouts

Most review problems come from a few habits. Avoiding them makes the queue faster and fairer.

  • Judging on the IP alone. Mobile carriers and universities put many honest users behind one IP. Use it as a supporting signal, never the only one.
  • Reviewing one account at a time. If you deny one account in a ring and approve the next, the farm still gets paid. Open the linked accounts before you decide.
  • Ignoring small cashouts. Farms often withdraw small amounts from many accounts to stay under the radar. The total is what matters.
  • Paying before reversals arrive. If most reversals from your networks land within two weeks, a new account cashing out on day two is being paid with money that may come back.
  • Not writing the reason down. Record why you held or denied each cashout. It helps with appeals, with networks and with tuning your rules later.

A short written policy helps too. Decide in advance what you do with a shared payout address, a VPN balance or a first cashout on day one. Then every reviewer makes the same call, and users get the same answer.

How CashoutGuard automates it

Send a cashout event to /v1/evaluate with the amount and the payout address. CashoutGuard answers with a score from 0 to 100, a decision and the reasons, and puts the cashout in a review queue with the evidence.

  • payout_address_shared, device_shared_with_accounts and email_shared for linked accounts, shown in the fraud rings graph.
  • earnings_spike when 24-hour earnings are far above the typical user on your site.
  • offer_completed_too_fast, conversion_without_click and click_conversion_country_mismatch from your offer click and conversion events.
  • new_account_cashout and cashout_velocity for fresh accounts and repeated withdrawals.
  • ip_vpn, ip_tor, ip_datacenter and the timezone and language checks for hidden locations.

Rules and allow or block lists let you turn this checklist into policy, and signed webhooks tell your backend when an account moves to block. Start in shadow mode and compare its flags with your own decisions. See the docs or the pricing page, which includes a 14-day Growth trial.

Frequently asked questions

How long should a cashout review take?

Most sites aim for the same day. Automatic approval for clean, older accounts keeps the queue short, so only the risky withdrawals wait.

Which check should I run first?

Payout address reuse. It is fast, rarely wrong and often finds the largest rings in one query.

Should I deny a cashout because of a VPN?

Not automatically. Look at whether the balance was earned on geo-targeted offers while the VPN was on. If it was, the network will likely reverse those conversions.

What if the user was paid for offers they never clicked?

Hold the cashout and ask the network about those conversions. It can mean a forged postback, a bug in your click logging or offers done outside your wall.

Keep reading