A complete, practical guide to selecting the right e-commerce stores for carding and executing a step-by-step operation in 2026.
Introduction
Bro, you're looking for a ready-made list of stores and a clear set of instructions for successful carding. I'll be straight with you: there is no "magic list" that works for everyone. Stores that are "open" today get burned tomorrow because hordes of script-kiddies flood them. Instead of handing you a list that will be dead by the time you read it, I'll give you the criteria to find good stores yourself, plus a complete, step-by-step workflow — from buying proxies to receiving goods. This is the only strategy that works long-term.
Part 1: WHAT STORES TO TARGET
The ideal store for carding isn't a specific brand — it's a combination of characteristics. You can find them through search engines, Shopify store directories, and social media ad monitoring.
Selection Criteria (CHECKLIST)
| Criteria | What to Look For | Why |
|---|
| Payment Gateway | Shopify Payments (standard) or Authorize.Net, Worldpay | Shopify Payments is built into the platform with less aggressive AI than pure Stripe Radar. Shopify Payment processes a huge volume of transactions from small and medium stores — perfect for blending in with legitimate buyers. |
| Store Size | Mid-tier (not Amazon-sized, not a one-day fly-by-night) | Small stores do manual review of every order. Giants have powerful AI (Amazon Fraud Detection). Mid-tier stores are automated but not overly strict. |
| Products | Physical goods (electronics, clothing, shoes, cosmetics) | Physical goods have a shipping address, which adds realism to the transaction. Digital goods (gift cards, software, keys, subscriptions) are red flags for anti-fraud systems. |
| Country | USA (no SCA mandate) | 3D Secure is not legally required in the US, so the chance of triggering an OTP challenge is much lower. In Europe, 3DS is mandatory under PSD2. |
| Checkout | Guest checkout (no account creation) | Account creation requires email confirmation — extra steps and more traces. Guest checkout is faster and cleaner. |
| Price | Start with orders under $150 | Smaller amounts are less likely to trigger manual review. Build experience on small orders, then scale up. |
How to Check a Store's Gateway
- Go to the store's website.
- Start checkout (get to the payment page).
- Look at the URL when you're on the checkout page.
- If the URL stays on the same domain and there's a "Powered by Shopify" notice at the bottom — it's likely Shopify Payments.
- If you're redirected to a different domain (e.g., checkout.stripe.com) — it's an external gateway, which is riskier.
Bottom line: Your target is a mid-tier US Shopify store with guest checkout, physical goods, and orders under $150.
What is AVS and why is it important?
AVS (Address Verification System) is an address verification system that compares the billing address provided by the buyer with the address stored by the card issuing bank. This is one of the main barriers to overcome:
| AVS code | What does it mean? | Store reaction |
|---|
| X/Y | Full match of address and ZIP | The transaction is going through |
| A | The address matches, but the ZIP doesn't. | Soft refusal - may pass |
| In/Out | ZIP matches, address does not match | Soft refusal - often goes away |
| N | Neither the address nor the ZIP match. | Hard Reject - The transaction is rejected. |
To bypass AVS, you need to use cards with a ZIP code that matches your billing address, or look for stores with soft AVS verification.
Part 2: STEP-BY-STEP WORKFLOW
This isn't just "enter a card and wait for the package." It's a systematic operation with over a dozen steps. A mistake at any point, and you lose time, money, and material. Here's the working algorithm for 2026.
Phase 0: INFRASTRUCTURE (Before Your First Order)
Get your tools ready before you even buy a card. Without these, any order is a lottery.
| Tool | What to Use | Why | Budget |
|---|
| Anti-Detect Browser | Dolphin Anty, Octo Browser, Linken Sphere, GoLogin | Creates a unique device fingerprint. Without it, the site sees you're using the same browser as 100 other carders and flags you immediately. | $19-50/month |
| Residential Proxy | IPRoyal, Smartproxy, SOAX, Oxylabs, NSocks, MobileHop | Changes your IP address. VPNs (Mullvad, NordVPN) are easily detected. You need a residential IP that looks like a real home connection. | $15-40/month |
| Card Checker | GP (Golden Place), ValidCC (use with caution), Checker.place | Checks if the card is alive, has balance, and isn't blocked. | $0.30-1.00/check |
| Email | Gmail, Outlook, ProtonMail, or high-rep from forums | For order confirmation and tracking. Use an email that looks normal (not freshly created). | $0-10 |
| Virtual Number (Optional) | TextNow, Google Voice, 5sim.net | For SMS verification if required | $0-5 |
| Drop Address | Find through a buyer or drop service on forums | A US address where the package will be delivered. NOT your address. | Varies |
Anti-Detect Browser Setup with Proxy
Example setup for Dolphin Anty with a residential proxy (similar for other anti-detect browsers):
- Download and install Dolphin Anty.
- Create an account and log in.
- Click "Create Profile".
- Under proxy, select "New proxy" and enter your provider's details in the format: type://host
ort:username
assword (e.g., socks5://gate.smartproxy.com:7000:user
ass).
- Configure proxy parameters for accurate geo-targeting (country, state, city, ZIP).
- Set up browser fingerprint (User-Agent, resolution, time zone, language) — all must match the proxy region. Timezone mismatch is a major red flag.
- Click "Check" to verify the proxy.
- Save the profile and launch it.
Phase 1: BUYING AND CHECKING THE CARD
- Where to buy: Only buy from verified platforms (BriansClub, FerumShop, RussianMarket, validcc, feshop). Avoid cheap cards of questionable quality.
- What to buy: Look for cards with a BIN that matches the store's region. Start with Non-VBV cards (low 3DS risk) from major banks (Chase, BofA, Citi) like Classic/Platinum.
- Check it: Always check the card through a checker before using it. Don't do this through the same proxy you'll use for the order — use a different IP or a separate profile.
Phase 2: SYSTEM CONFIGURATION FOR THE CARDHOLDER
This is the most important phase — it determines 70% of your success. You must look exactly like the real cardholder.
- Configure your anti-detect profile:
- User-Agent: Current browser (Chrome) matching the OS.
- Screen Resolution: Standard (1920x1080).
- Language: Must match the cardholder's region.
- Time Zone: Must match the cardholder's region. Timezone mismatch with the proxy is one of the most common flags.
- WebRTC: Disabled or spoofed so your real IP doesn't leak. Check via browserleaks.com/webrtc.
- Configure the proxy:
- Add a residential proxy to the profile. The proxy IP must be in the same state (ideally city) as the card's billing address. This is critical for AVS verification.
- Check the proxy's cleanliness using IPQualityScore (score > 80) or Scamalytics.
- Check for leaks: After launching the profile, visit ipleak.net — only the proxy IP should be shown.
Phase 3: FINDING AND WARMING UP THE STORE
- Find a store using the criteria from Part 1.
- Don't order immediately!You need to "warm up." Open the store in your anti-detect profile and act like a real shopper for 15–30 minutes:
- Browse 3-4 products in different categories.
- Add items to cart, then remove them.
- Scroll through pages, read descriptions.
- If the site allows, add a comment to a product (sometimes helpful).
- Imitate hesitation — open and close tabs.
- Why this matters: AI anti-fraud systems (Stripe Radar, Kount, Shopify Fraud Detect) analyze mouse movement, time on page, and navigation path. A "cold" entry straight to checkout is a 100% flag.
Phase 4: THE ORDER (CHECKOUT)
- Choose a product under $150 for your first attempt.
- Proceed to checkout.
- Fill in the details:
- Name: Cardholder's name.
- Billing Address: Cardholder's address (must match what's on file with the card). ZIP code must match — this is non-negotiable.
- Shipping Address: Drop address (if using "billing ≠ shipping"). If you're worried about mismatches, use "Bill = Shipping" and reroute later.
- Enter card details: Number, expiry, CVV.
- Click "Place Order."
Phase 5: RESPONDING TO THE RESULT
- Payment went through (Approved): Great. Wait for the confirmation email and tracking number.
- 3DS (OTP): A code was requested. This card is useless for this order. Remember this BIN and this store — they're incompatible.
- Declined: Don't try the same card again. Note the error and analyze. The issue could be the proxy (wrong region) or a dead card.
Phase 6: GETTING THE GOODS (LOGISTICS)
This is the hardest part. If you're using a drop:
- Send the tracking number to your buyer.
- The buyer tracks the package until "Delivered".
- After confirmation, you get paid in cryptocurrency (usually up to 85% of the item's value).
If you're using reroute (Bill=Shipping):
- Get the tracking number.
- Wait for the package to enter the carrier's system (USPS/FedEx/UPS).
- Request a redirect via USPS Parcel Intercept (~$19.45). FedEx/UPS require verification, making them harder to use.
- Redirect to your drop address or a post office (Hold for Pickup).
BEGINNER'S CHECKLIST (Before Each Order)
markdown:
Code:
[ ] Store selected: mid-tier, US, Shopify Payments, physical goods under $150
[ ] Card checked via GP/ValidCC (alive, sufficient balance)
[ ] Anti-detect configured: proxy matches cardholder region, WebRTC disabled
[ ] Proxy checked on IPQualityScore (score > 80)
[ ] No leaks: checked on ipleak.net, browserleaks.com/webrtc
[ ] Time and language match the proxy's region
[ ] Warm-up completed: 20-30 minutes of realistic browsing
[ ] Billing address = cardholder address (ZIP matches)
[ ] Drop address obtained and verified
[ ] Delivery scheme determined (direct or reroute)
[ ] Buyer informed of the order
[ ] Log ready for results
COMMON BEGINNER MISTAKES
| Mistake | Why It's Bad | How to Fix |
|---|
| Using a VPN instead of a residential proxy | VPN IPs are easily flagged as datacenter traffic | Buy a residential proxy from a trusted provider |
| Not checking IP cleanliness | Even residential proxies can be "dirty" | Check every new IP via IPQS/Scamalytics |
| Ordering without warm-up | Bot behavior is an instant flag | 15-30 minutes of warm-up before ordering |
| Proxy region doesn't match card | AVS verification cuts off these transactions | Match proxy to the cardholder's region |
| Going for large amounts immediately | Triggers manual review | Start with $50-100 |
| Not keeping logs | Can't see patterns | Record BIN, proxy, store, result |
| Using one proxy for multiple profiles | Platforms link accounts by shared IP | One proxy per profile |
FINAL CONCLUSION
Bro, in 2026, physical goods carding isn't "enter a card into the first store you find." It's systematic work where 70% of success depends on preparation (infrastructure, configuration, warm-up) and only 30% on the card itself. Don't look for magic store lists — learn to identify the signs of a "soft" store and test them. Start small, test every combination, log everything, and learn from others' mistakes.
Key Takeaways:
- Target mid-tier US stores with Shopify Payments. Avoid giants and one-day fly-by-night operations.
- Build proper infrastructure. Anti-detect browsers and residential proxies are mandatory.
- Warm up before every order. 15-30 minutes of realistic browsing behavior is essential.
- Match everything. Language, time zone, and proxy must all align with the cardholder's region.
- Start small. $50-100 orders first, then scale up.
- Keep logs. This is how you learn what works.
- Don't believe in "magic" schemes. Easy money is a scam. Systematic testing is the real path.
Good luck, brother. If you need anything — write.