Professor
Professional
- Messages
- 1,749
- Reaction score
- 1,713
- Points
- 113
The Complete Carder's Guide to Infiltration, Analysis, and Manipulation of Fraud Engines
Bro, up to now we've covered the basics of AI anti-fraud systems — their weaknesses and how to bypass their detection methods from the outside. But let's be honest: sometimes you're just rolling the dice. Maybe you need the cardholder to have a flawless history of interactions with the fraud protection system. Maybe you're dealing with strict 3DS requirements or those pesky EU cards with SCA. Or maybe the fraud protection system is already too familiar with your device fingerprint after a few days and a few transactions.In those cases, the resources required to maintain a working method multiply faster than your profits. You're burning through proxies, constantly changing anti-detection browsers, and praying to the fraud gods that your next attempt doesn't trigger a security flag.
But what if I told you there's a better way? This is a two-part guide that will change your approach to carding forever. In Part 1, we'll go behind the scenes — accessing these anti-fraud systems to understand exactly why your cards are being declined, and how to evaluate your transactions. In Part 2, we'll go further and show you how to completely break their detection capabilities by poisoning their data.
Today, we're focused on accessing and using these systems to your advantage. It's not just about understanding how they work — it's about using their own tools to check your cards before you burn them.
Warning: This method primarily works against third-party anti-fraud systems like Riskified, Signifyd, Forter, and SEON. If you're going against built-in fraud processors like Stripe Radar or Adyen Risk Engine, the effectiveness drops significantly, since they have direct access to payment data and transaction patterns that third-party systems can't see.
PART 1: THE ANATOMY OF AI ANTI-FRAUD
1.1. How These Systems Work
AI anti-fraud systems aren't just fancy algorithms that check whether your IP address matches your billing address. They're huge, data-hungry beasts that watch and learn from billions of transactions across thousands of merchants.What they collect:
| Data Category | Examples | Weight in Scoring |
|---|---|---|
| Device fingerprint | OS, browser, resolution, fonts, Canvas | 20-30% |
| Behavioral patterns | Typing speed, mouse movements, scroll | 15-25% |
| Transaction amounts | Typical amounts, deviations | 10-15% |
| Time between purchases | Frequency patterns | 5-10% |
| Merchant categories | Typical purchases | 5-10% |
| IP addresses | Geolocation, network type | 10-15% |
| Age, domain, reputation | 5-10% | |
| Chargeback history | Lifetime trace | 10-20% |
The core question AI asks: "Does this transaction match the historical pattern we've seen with this card across our entire network?"
1.2. How AI Learns
1.3. Why Card Reuse is Suicide
Even if you change everything else, you create a profile in their database that screams "I'm fraud."What happens:
| Attempt | AI Action | Result |
|---|---|---|
| 1st | Profile creation: card + device + behavior | Neutral |
| 2nd (failed) | Red flag on profile | -10 trust |
| 3rd (failed) | Flag reinforcement | -25 trust |
| 4th | Profile marked as "fraud" | Card burned |
Conclusion: Every failed attempt is another red flag associated with the card number and your device fingerprint.
1.4. The Black Box Problem
These systems intentionally keep you in the dark, never telling you the real reason for a decline. They won't say: "Declined: this card has had 17 failed attempts on our network in the last week." They'll just hit you with generic nonsense.That's why access to these systems is so important:
| Without Access | With Access |
|---|---|
| You don't know the reason for decline | You see applied rules |
| You burn cards blindly | You check before using |
| You waste proxies | You optimize settings |
| You don't see patterns | You analyze data |
PART 2: GAINING ACCESS TO ANTI-FRAUD SYSTEMS
2.1. Access Difficulty Levels
| Provider | Dashboard URL | Difficulty | Requirements | Time |
|---|---|---|---|---|
| SEON | admin.seon.io | Low | Basic verification | 1-2 days |
| Signifyd | app.signifyd.com | Medium | Business front | 1-2 weeks |
| Riskified | app.riskified.com | Medium | Business front | 1-2 weeks |
| Ravelin | dashboard.ravelin.com | Medium | Business front | 1-2 weeks |
| Forter | portal.forter.com | High | Video calls, documents | 3-4 weeks |
2.2. SEON — The Entry Point
Why SEON:- Hungry for business
- Basic verification
- No video calls
- Easy to bypass
- Fast registration
Problem: Few large sites use SEON.
Step-by-step registration:
- Go to seon.io
- Click "Sign Up" or "Get Started"
- Fill in basic business information
- Confirm email
- Get API key
2.3. Signifyd and Riskified — Medium Level
What you need:- Legitimate business front
- Email verification
- Conversation with sales team
- Steel balls and a solid front
Step-by-step process:
- Create business front (see section 2.6)
- Fill out form on website
- Wait for sales call
- Pass verification
- Get access
2.4. Forter — The Final Boss
What you need:- Video calls
- Business record checks
- Evidence that would make law enforcement envious
- Don't waste time unless you're planning a large-scale attack
2.5. Ravelin — The Alternative
What you need:- Business front
- Basic verification
- Fewer requirements than Forter
2.6. Step-by-Step Business Front Creation
Step 1: Domain
Bash:
# Buy on Namecheap
# Price: $10-15
# TLD: .com, .co, .io
# Required: privacy protection
Step 2: Shopify Store
- Register on Shopify
- Choose a theme (electronics or fashion)
- Set up basic pages:
- About Us
- Contact Us
- Shipping Policy
- Return Policy
- Privacy Policy
Step 3: Content
Bash:
# Use AI to generate:
- Business name
- Product descriptions
- About page
- Policies
# Download images from:
- Legitimate stores
- Unsplash
- Pexels
Step 4: Professional Email
Code:
Format: firstname@domain.com
Example: john@techstore.com
Set up:
- Signature with title
- Autoresponder
- Professional tone
Step 5: LinkedIn Profile
Code:
- Create a boring corporate profile
- Add work experience
- Add education
- The more mundane, the better
2.7. Alternative: Buying Logs
Why it's easier:| Parameter | Own Registration | Buying Logs |
|---|---|---|
| Time | 1-4 weeks | Instant |
| Cost | $100-500 | $10-100 |
| Risk | Medium | Low |
| Paper trail | Yes | No |
| Access to vendors | 1 | Multiple |
What to look for:
- Sellers who don't sell burned accounts
- Verified sellers on forums
- Reviews from real buyers
- Replacement guarantee
PART 3: ASSESSING YOUR TRANSACTIONS
3.1. Three Possible Responses
| Response | Meaning | Merchant Action |
|---|---|---|
| APPROVED | Transaction looks clean | Process payment |
| VIEW | Suspicious, but not obvious scam | Manual review |
| REJECT | High-risk transaction | Block |
3.2. Risk Score
Merchants receive a risk score from 0 to 100:| Range | Risk Level | Merchant Action | Your Action |
|---|---|---|---|
| 0-30 | Very low | Auto-approve | Use |
| 31-50 | Low | Auto-approve | Use |
| 51-70 | Medium | Manual review | Fix issues |
| 71-85 | High | Manual review | Don't use |
| 86-100 | Very high | Auto-decline | Don't use |
3.3. Merchant Setting Flexibility
Key insight: Merchants control how strictly they follow recommendations.| Merchant Type | Setting | Example | Success Chance |
|---|---|---|---|
| Strict | Rejects > 50 | Best Buy | Low |
| Medium | Manual review up to 80 | Mid-size stores | Medium |
| Loose | Approves high risk | Small stores | High |
This explains why the same card works on one site but not another.
3.4. Data Sharing Between Systems
Important: These systems share data. A declined transaction at a random merchant registers in the network and can ruin future attempts at all merchants using that vendor.That's why we gain access to systems — to use their AI to evaluate our transactions before real attempts.
PART 4: PRACTICAL API USAGE
4.1. SEON API — Complete Guide
Step 1: Get API key
Bash:
# Register on seon.io
# Find API key in dashboard
# Format: your_api_key_here
Step 2: Basic CURL request
Bash:
curl https://api.seon.io/SeonRestService/fraud-api/v2/ \
-X POST \
-H "X-API-KEY: your_api_key" \
-H "Content-Type: application/json; charset=UTF-8" \
-d '{
"config": {
"ip": {"include": "flags,history,id", "version": "v1"},
"aml": {"version": "v1", "monitoring_required": true},
"email": {"include": "flags,history,id", "version": "v2"},
"phone": {"include": "flags,history,id", "version": "v1"},
"ip_api": true,
"email_api": true,
"phone_api": true,
"aml_api": true,
"device_fingerprinting": true
},
"ip": "192.168.1.1",
"action_type": "purchase",
"transaction_id": "txn_123456",
"email": "example@domain.com",
"user_fullname": "Jane Doe",
"user_firstname": "Jane",
"user_lastname": "Doe",
"user_dob": "1985-05-15",
"user_country": "US",
"user_city": "Los Angeles",
"user_region": "CA",
"user_zip": "90210",
"user_street": "456 Elm St",
"payment_mode": "credit_card",
"card_fullname": "Jane Doe",
"card_bin": "411111",
"card_last": "1234",
"card_expire": "12/2025",
"avs_result": "Y",
"cvv_result": "M",
"payment_provider": "Visa",
"phone_number": "+1234567890",
"transaction_type": "online",
"transaction_amount": "299.99",
"transaction_currency": "USD",
"items": [{
"item_id": "item_001",
"item_quantity": "1",
"item_name": "Gadget",
"item_price": "299.99",
"item_category": "Electronics"
}],
"shipping_country": "US",
"shipping_city": "Los Angeles",
"shipping_region": "CA",
"shipping_zip": "90210",
"billing_country": "US",
"billing_city": "Los Angeles",
"billing_region": "CA",
"billing_zip": "90210"
}'
Step 3: Advanced request with full data
Bash:
curl https://api.seon.io/SeonRestService/fraud-api/v2/ \
-X POST \
-H "X-API-KEY: your_api_key" \
-H "Content-Type: application/json; charset=UTF-8" \
-d '{
"config": {
"ip": {"include": "flags,history,id", "version": "v1"},
"aml": {"version": "v1", "monitoring_required": true},
"email": {"include": "flags,history,id", "version": "v2"},
"phone": {"include": "flags,history,id", "version": "v1"},
"ip_api": true,
"email_api": true,
"phone_api": true,
"aml_api": true,
"device_fingerprinting": true
},
"ip": "192.168.1.1",
"action_type": "purchase",
"transaction_id": "txn_123456",
"affiliate_id": "aff_78910",
"order_memo": "Test order",
"email": "example@domain.com",
"email_domain": "domain.com",
"password_hash": "5f4dcc3b5aa765d61d8327deb882cf99",
"user_fullname": "Jane Doe",
"user_firstname": "Jane",
"user_middlename": "A",
"user_lastname": "Doe",
"user_dob": "1985-05-15",
"user_pob": "New York",
"user_photoid_number": "98765",
"user_id": "654321",
"user_name": "janedoe",
"user_created": "2023-01-01",
"user_country": "US",
"user_city": "Los Angeles",
"user_region": "CA",
"user_zip": "90210",
"user_street": "456 Elm St",
"user_street2": "Apt 9C",
"session": "session_12345",
"payment_mode": "credit_card",
"card_fullname": "Jane Doe",
"card_bin": "411111",
"card_hash": "abcd1234efgh5678",
"card_last": "1234",
"card_expire": "12/2025",
"avs_result": "Y",
"cvv_result": "M",
"payment_provider": "Visa",
"phone_number": "+1234567890",
"transaction_type": "online",
"transaction_amount": "299.99",
"transaction_currency": "USD",
"brand_id": "brand_123",
"items": [{
"item_id": "item_001",
"item_quantity": "1",
"item_name": "Gadget",
"item_price": "299.99",
"item_store": "Gadget Store",
"item_store_country": "US",
"item_category": "Electronics",
"item_url": "https://example.com/gadget",
"item_custom_fields": {"Color": "Black", "RAM": "8GB"}
}],
"shipping_country": "US",
"shipping_city": "Los Angeles",
"shipping_region": "CA",
"shipping_zip": "90210",
"shipping_street": "456 Elm St",
"shipping_street2": "Apt 9C",
"shipping_phone": "+1234567890",
"shipping_fullname": "Jane Doe",
"shipping_method": "Standard",
"billing_country": "US",
"billing_city": "Los Angeles",
"billing_region": "CA",
"billing_zip": "90210",
"billing_street": "456 Elm St",
"billing_street2": "Apt 9C",
"billing_phone": "+1234567890",
"discount_code": "DISCOUNT10",
"gift": "false",
"gift_message": "",
"merchant_id": "shop_123",
"details_url": "https://example.com/orderdetails",
"custom_fields": {}
}'
4.2. Reading SEON Response
JSON:
{
"success": true,
"error": {},
"data": {
"id": "67c2810c2de1",
"state": "DECLINE",
"fraud_score": 95.75,
"blackbox_score": 93.25,
"bin_details": {
"card_bin": "411111",
"bin_bank": "VERMONT NATIONAL BANK",
"bin_card": "VISA",
"bin_type": "CREDIT",
"bin_level": "CLASSIC",
"bin_country": "UNITED STATES",
"bin_country_code": "US",
"bin_website": "www.vermontnationalbank.com",
"bin_phone": "+1 802 476 0030",
"bin_valid": true,
"card_issuer": "VISA"
},
"version": "v2",
"applied_rules": [
{
"id": "P106",
"name": "Customer is using a datacenter ISP",
"operation": "+",
"score": 10.0
},
{
"id": "P110",
"name": "IP address was found on 4 spam blacklists",
"operation": "+",
"score": 4.0
},
{
"id": "P112",
"name": "Customer is using public proxy",
"operation": "+",
"score": 10.0
},
{
"id": "E123",
"name": "Email is not similar to user full name",
"operation": "+",
"score": 1.0
}
],
"device_details": {
"os": "MacOS",
"type": "web",
"browser": "FIREFOX10",
"private": true,
"platform": "MacIntel",
"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:102.0) Gecko/20100101 Firefox/102.0",
"device_type": "desktop",
"screen_resolution": "1600x800"
},
"ip_details": {
"ip": "192.168.1.1",
"score": 24.0,
"country": "US",
"state_prov": "California",
"city": "Los Angeles",
"type": "DCH",
"tor": false,
"vpn": false,
"web_proxy": false,
"public_proxy": true,
"spam_number": 4
},
"email_details": {
"email": "example@domain.com",
"score": 2.11,
"deliverable": true,
"domain_details": {
"domain": "domain.com",
"registered": true,
"disposable": false,
"free": false,
"custom": true
}
},
"calculation_time": 2327
}
}
4.3. Analyzing the Response
Fraud Score:| Range | Meaning | Action |
|---|---|---|
| 0-50 | Low risk | Use |
| 51-80 | Medium risk | Fix |
| 81-100 | High risk | Don't use |
Applied Rules:
| Rule | Meaning | What to Do |
|---|---|---|
| P106 | Datacenter ISP | Use residential proxy |
| P110 | IP in spam blacklists | Change proxy |
| P112 | Public proxy | Use private proxy |
| E123 | Email doesn't match name | Create matching email |
| C101 | High-risk BIN | Use different BIN |
| V101 | Velocity exceeded | Wait |
Device Details:
- OS, browser, resolution — all analyzed
- Make sure everything is consistent with proxy
IP Details:
- Type: DCH (datacenter), RES (residential), MOB (mobile)
- Tor, VPN, proxy flags
- Spam number — number of blacklists
PART 5: OTHER PROVIDERS' APIs
5.1. Signifyd
Bash:
# Production
curl https://api.signifyd.com/v3/orders \
-X POST \
-H "X-SIGNIFYD-API-KEY: your_api_key" \
-H "Content-Type: application/json" \
-d '{
"orderId": "order_123",
"email": "example@domain.com",
"card": {
"bin": "411111",
"last4": "1234",
"expiryMonth": 12,
"expiryYear": 2025
},
"billing": {
"name": "Jane Doe",
"address": "456 Elm St",
"city": "Los Angeles",
"region": "CA",
"postalCode": "90210",
"country": "US"
},
"shipping": {
"name": "Jane Doe",
"address": "456 Elm St",
"city": "Los Angeles",
"region": "CA",
"postalCode": "90210",
"country": "US"
},
"amount": 299.99,
"currency": "USD"
}'
5.2. Riskified
Bash:
# Production
curl https://wh.riskified.com/api/v2/orders \
-X POST \
-H "X-RISKIFIED-SHOP-DOMAIN: your_shop_domain" \
-H "Content-Type: application/json" \
-H "HMAC-SHA256: calculated_hmac" \
-d '{
"order": {
"id": "order_123",
"email": "example@domain.com",
"created_at": "2026-01-01T00:00:00Z",
"currency": "USD",
"total_price": 299.99,
"customer": {
"email": "example@domain.com",
"first_name": "Jane",
"last_name": "Doe"
},
"payment_details": [{
"card_bin": "411111",
"card_last4": "1234"
}]
}
}'
5.3. Forter
Bash:
# Production
curl https://api.forter.com/v2/orders/validation \
-X POST \
-H "api-version: 2.36" \
-H "x-forter-siteid: your_site_id" \
-H "Authorization: Bearer your_api_key" \
-H "Content-Type: application/json" \
-d '{
"orderId": "order_123",
"orderType": "WEB",
"createdAt": "2026-01-01T00:00:00Z",
"customer": {
"email": "example@domain.com",
"firstName": "Jane",
"lastName": "Doe"
},
"payment": [{
"cardBin": "411111",
"cardLast4": "1234"
}],
"total": {
"amount": 299.99,
"currency": "USD"
}
}'
5.4. Provider Comparison
| Provider | Access Difficulty | API Complexity | Features | Best For |
|---|---|---|---|---|
| SEON | Low | Low | Best for start | Beginners |
| Signifyd | Medium | Medium | Email age matters | Mid-level |
| Riskified | Medium | Medium | HMAC required | Mid-level |
| Forter | High | High | Device fingerprint critical | Pros |
PART 6: SYSTEM SETUP
6.1. Technical Requirements
| Component | Requirement | Cost | Where to Buy |
|---|---|---|---|
| Proxy | Residential, IPQS > 80 | $15-30/GB | Bright Data, IPRoyal |
| Antidetect | Linken Sphere, Octo | $19-50/mo | Official sites |
| API Access | SEON/Signifyd/etc | $50-500/mo | Direct registration |
| VPS | For API requests | $10-20/mo | DigitalOcean, Vultr |
| Domain | For business front | $10-15 | Namecheap |
6.2. Step-by-Step Setup
Step 1: Proxy Setup
Bash:
# 1. Buy residential proxy
# 2. Check via IPQS:
curl "https://ipqualityscore.com/api/json/ip/YOUR_API_KEY/192.168.1.1"
# 3. Ensure:
# - IPQS score > 80
# - Type: RES or MOB
# - Not in blacklists
Step 2: Antidetect Setup
Code:
1. Create profile in Octo/Linken Sphere
2. Configure:
- Timezone = proxy timezone
- Language = en-US
- Resolution = 1920x1080
- WebRTC = disabled
- Canvas = noise
- WebGL = consistent
3. Check on browserleaks.com
Step 3: API Setup
Bash:
# 1. Get API key
# 2. Set up VPS:
ssh root@your_vps_ip
# 3. Install curl:
apt-get install curl
# 4. Test request:
curl https://api.seon.io/SeonRestService/fraud-api/v2/ \
-X POST \
-H "X-API-KEY: your_api_key" \
-H "Content-Type: application/json" \
-d '{"ip": "192.168.1.1", "action_type": "purchase"}'
Step 4: Business Front Creation (if needed)
Code:
1. Buy domain on Namecheap
2. Create Shopify store
3. Generate content via AI
4. Create email
5. Create LinkedIn
6. Prepare documents
6.3. Security
Rules:- □ Separate VPS for API
- □ Don't use main email
- □ Proxy rotation
- □ Log cleaning
- □ Don't store API keys in plain text
- □ Use environment variables
- □ Encrypt sensitive data
PART 7: MISTAKES AND HOW TO FIX THEM
7.1. Mistake: API Returns Error
Causes:- Wrong API key
- Wrong request format
- Rate limit exceeded
- Wrong endpoint
Fix:
Bash:
# Check key:
echo $API_KEY
# Check format:
curl -v https://api.seon.io/SeonRestService/fraud-api/v2/
# Check limit:
# In SEON dashboard
# Check endpoint:
# SEON documentation
7.2. Mistake: High Fraud Score
Causes:- Datacenter IP
- Public proxy
- Email doesn't match name
- Device fingerprint inconsistent
- High-risk BIN
Fix:
Bash:
# 1. Check proxy:
curl "https://ipqualityscore.com/api/json/ip/YOUR_API_KEY/YOUR_IP"
# 2. If DCH → buy residential
# 3. If public proxy → buy private
# 4. If email mismatch → create new
# 5. If device inconsistent → configure antidetect
# 6. If BIN high-risk → use different
7.3. Mistake: Access to System Denied
Causes:- Bad business front
- Suspicious activity
- Wrong documents
- Bad domain reputation
Fix:
Code:
1. Improve business front:
- Professional website
- Corporate email
- LinkedIn profile
2. Buy logs instead of registering:
- Verified sellers
- Reviews
3. Use different provider:
- SEON → easier
- Signifyd → medium
7.4. Mistake: Card Still Declined
Causes:- Card already burned in network
- Strict merchant
- Other factors
- Velocity exceeded
Fix:
Code:
1. Check card via API
2. Analyze applied rules
3. If card burned → use another
4. If strict merchant → use another
5. If velocity → wait
7.5. Mistake: Misinterpreting Response
Causes:- Not understanding applied rules
- Ignoring device details
- Ignoring IP details
Fix:
Code:
1. Study SEON documentation
2. Create rule table:
- P106: Datacenter → resident proxy
- P110: Spam → change proxy
- P112: Public proxy → private proxy
- E123: Email mismatch → new email
3. Analyze all details:
- Device
- IP
- Email
- BIN
PART 8: COMPLETE CHECKLIST
Before Starting:
- □ Proxy configured (residential, IPQS > 80)
- □ Antidetect ready
- □ API access obtained
- □ VPS configured
- □ Business front created (if needed)
- □ API keys secure
For Each Transaction:
- □ Check card via API
- □ Analyze fraud score
- □ Read applied rules
- □ Fix issues
- □ Repeat check
After Check:
- □ If score < 50 → can use
- □ If score 51-80 → fix issues
- □ If score > 80 → don't use card
- □ Log result
Daily:
- □ Check proxy
- □ Clean logs
- □ Update records
- □ Check API limits
Weekly:
- □ Rotate proxy
- □ Check relevance
- □ Update BINs
- □ Analyze results
PART 9: COMPARISON WITH OTHER METHODS
| Method | Complexity | Effectiveness | Cost | Risk | Time |
|---|---|---|---|---|---|
| Blind carding | Low | Low | Low | High | Instant |
| API check | Medium | High | Medium | Low | 5-10 min |
| Data poisoning | High | Very high | High | Medium | Weeks |
PART 10: KEY TAKEAWAYS
Bro, access to anti-fraud systems is a game-changer.10.1. Main Conclusions
- AI anti-fraud is a black box — they don't tell you why they declined
- Access to systems — key to understanding
- SEON is the entry point — easy to register
- API requests — check cards before using
- Applied rules — show what triggered the flag
- Data sharing — declined transaction burns card across network
- Business front — needed for Signifyd/Riskified access
- Logs — alternative to registration
10.2. Strategy
Step-by-step plan:- Start with SEON for practice
- Study API requests
- Check cards before use
- Analyze applied rules
- Fix issues
- Scale with other providers
10.3. What's Next
In Part 2, we'll cover how to poison their training data, create robust profiles, and make their AI work for you, not against you.With these guides, these systems are no longer black boxes — you've seen how they work from the inside. It's time to make them dance to your tune.
Good luck, bro. If anything — ask.