Cashout fraud checklist: what to check before you pay a withdrawal
The cashout is the last moment the money is still yours. Once it is paid, a chargeback from the network comes out of your margin. This checklist covers the checks that catch most withdrawal fraud, in the order that saves the most time.
Short answer
Before you pay a withdrawal, check linked accounts and payout address reuse first, then earnings spikes, offer speed, conversions without a click, click versus conversion country, account age and network signals. Keep three outcomes (approve, hold, deny) so only the risky cashouts wait.
- Check first
- Payout address reuse: fast, rarely wrong and often finds the largest rings.
- Hold
- Addresses already paid for another account, and cashouts within 24 hours of signup.
- Review
- Offers under half the usual completion time, click and conversion in different countries, earnings many times the typical day.
- Target review time
- The same day, with clean older accounts approved automatically.
Why the cashout is the right place to check
You can check users at signup, at every offer click and at every conversion. You should. But the cashout is where everything comes together. By then you have the full history of the account: devices, IPs, offers, speed and the payout address it wants to be paid to.
It is also where mistakes cost real money. A wrong signup flag loses you one user. A wrong approval sends cash to a farm, and the network may reverse the underlying conversions weeks later.
The checklist
Work through these in order. The first checks are fast and catch the biggest rings. The later ones need more context.
- Linked accounts. Does this account share a device, email or IP pattern with other accounts? If yes, look at the whole group, not only this cashout.
- Payout address reuse. Has this PayPal, wallet or gift card email received money for another account? This is the single strongest fraud signal.
- Earnings spike. How much did the account earn in the last 24 hours compared with a typical user on your site? Several times the normal amount deserves a look.
- Offers completed too fast. How long passed between the offer click and the conversion? Compare with how long other users take on the same offer.
- Conversions without a click. Did the network pay for offers this user never opened from your wall? That suggests a forged postback or another path.
- Country mismatch between click and conversion. Was the offer clicked from one country and converted from another? A proxy or VPN switch is the usual cause.
- Account age. How old is the account? A first cashout within hours of signup is a pattern farms rely on.
- Network signals. Was the account on a VPN, Tor, datacenter IP or residential proxy when it earned the balance?
Checklist at a glance
| Check | Red flag | Typical action |
|---|---|---|
| Linked accounts | Same device as 2 or more other accounts | Review the whole cluster |
| Payout address reuse | Address already paid for another account | Hold, usually deny |
| Earnings spike | Many times the typical daily earnings | Review the offers behind it |
| Offer speed | Under half the usual completion time | Review, reverse if confirmed |
| Conversion without click | Paid offer never clicked on your wall | Hold and ask the network |
| Click vs conversion country | Click in one country, conversion in another | Review |
| Account age | Cashout within 24 hours of signup | Hold until the first check passes |
| VPN, Tor or datacenter | Balance earned behind a hidden IP | Review, deny if the offers were geo-targeted |
None of these rows alone proves fraud, except perhaps a payout address shared across accounts. Two or three red flags together are a strong case. One flag on an old account with a clean history is usually a false alarm.
How to run each check well
Linked accounts and payout addresses
Normalise payout addresses before comparing them. Lowercase emails, strip dots and plus tags on Gmail, and trim spaces from wallet addresses. Then search past cashouts for the same value. One address paid for five accounts is one person.
Earnings spike
Work out what a normal user earns on your site in a day. The median is better than the average because a few power users skew the average. Then compare this account with that number. Ten times the median in one day is rare for a real person.
Offer speed and missing clicks
This only works if you record offer clicks. Log the user, the offer ID and the time when someone opens an offer from your wall. When the postback arrives, match it to the click. No click means you cannot tell how fast it was, and a paid conversion with no click at all is itself suspicious.
Country mismatch and account age
Store the IP country with each click and each conversion. A mismatch within the same offer is a much stronger signal than a user who travelled last month. For account age, a short wait before the first cashout removes most of the instant-farm profit.
-- Payout addresses paid for more than one account
SELECT LOWER(payout_address) AS addr,
COUNT(DISTINCT user_id) AS accounts
FROM cashouts
WHERE status IN ('paid', 'pending')
GROUP BY LOWER(payout_address)
HAVING COUNT(DISTINCT user_id) > 1;Approve, hold or deny
Keep three outcomes, not two. A hold gives you time to ask the network or the user without losing an honest customer.
- Approve when no check fires, or one weak check fires on an old, clean account.
- Hold when one strong check or two weaker ones fire. Ask a question, wait for pending reversals, look at the cluster.
- Deny when the payout address is shared, the device is shared with a ring, or several checks fire together. Deny the cluster, not only this account.
Common mistakes when reviewing cashouts
Most review problems come from a few habits. Avoiding them makes the queue faster and fairer.
- Judging on the IP alone. Mobile carriers and universities put many honest users behind one IP. Use it as a supporting signal, never the only one.
- Reviewing one account at a time. If you deny one account in a ring and approve the next, the farm still gets paid. Open the linked accounts before you decide.
- Ignoring small cashouts. Farms often withdraw small amounts from many accounts to stay under the radar. The total is what matters.
- Paying before reversals arrive. If most reversals from your networks land within two weeks, a new account cashing out on day two is being paid with money that may come back.
- Not writing the reason down. Record why you held or denied each cashout. It helps with appeals, with networks and with tuning your rules later.
A short written policy helps too. Decide in advance what you do with a shared payout address, a VPN balance or a first cashout on day one. Then every reviewer makes the same call, and users get the same answer.
How CashoutGuard automates it
Send a cashout event to /v1/evaluate with the amount and the payout address. CashoutGuard answers with a score from 0 to 100, a decision and the reasons, and puts the cashout in a review queue with the evidence.
payout_address_shared,device_shared_with_accountsandemail_sharedfor linked accounts, shown in the fraud rings graph.earnings_spikewhen 24-hour earnings are far above the typical user on your site.offer_completed_too_fast,conversion_without_clickandclick_conversion_country_mismatchfrom your offer click and conversion events.new_account_cashoutandcashout_velocityfor fresh accounts and repeated withdrawals.ip_vpn,ip_tor,ip_datacenterand the timezone and language checks for hidden locations.
Rules and allow or block lists let you turn this checklist into policy, and signed webhooks tell your backend when an account moves to block. Start in shadow mode and compare its flags with your own decisions. See the docs or the pricing page, which includes a 14-day Growth trial.